Skip to content
leae
How it worksPricingPrivacyTerms
Join the waitlist
SECURITY · TRUST

Only you can read what's private.

This page explains how Leave protects athletes' data, in plain words. Every claim is labeled with where it stands today, because Leave hasn't launched yet and we'd rather show you the plan than pretend it's all running. The full design is public, down to the architecture.

STATUS AS OF SEPTEMBER 23, 2026LEAVE INC.
CONTENTS
Where we are The promise, and its limits How your key works Who can see what AI Vendors Your controls Infrastructure Athletes under 18 This website, today Check it yourself Report a vulnerability Changelog
HOW TO READ THIS PAGE
LIVETrue today, and you can check it.
IN TESTINGBuilt, but not yet protecting real athletes.
BEFORE LAUNCHDesigned, and required before the app goes on sale.
LATERPlanned, with what triggers it.

1. Where we are

Leave hasn't launched. Right now:

  • LIVE No athlete data is on Leave's servers. The production backend hasn't been built yet, so there's nothing private to protect or to lose.
  • LIVE The only personal data we hold is the waitlist: email addresses, plus the details listed in the Privacy Policy.
  • IN TESTING The iOS demo on TestFlight runs on fictional data that stays on your phone. It doesn't create a real account.

Already built into the app and in testing on that fictional data:

  • IN TESTING Sign-in with a six-digit emailed code. There's no password anywhere.
  • IN TESTING The age gate: no one under 13, and athletes aged 13 to 17 only through a parent or guardian.
  • IN TESTING Delete my account, in the app, with a typed confirmation.
  • IN TESTING No analytics SDK, no advertising SDK, no advertising identifier, and no access to your location or contacts. The only permission prompts are camera, photos, microphone, and speech recognition, each with a plain reason.

Everything below marked BEFORE LAUNCH has to be in place before Leave goes on sale. As each item goes live, we'll change its label and log it in the changelog.

2. The promise, and its limits

Your private details, your contracts, and your files are encrypted so that nobody at Leave, at Google, at our AI provider, or at any vendor can read them. Only you can, and you hold a key you can revoke.

Here's what that promise doesn't cover, stated up front:

  • While you're using Leave, the records you're working with are readable in our server's memory and in the AI model for the moment it takes to answer you. There's no way to explain a contract without reading it. Nothing from that moment is written to logs.
  • Leave can see account metadata: that you have an account, how many contracts and strands you have, file sizes, dates, and payment dates. Support works from that alone.
  • Lose every device and your recovery code, and your private data is gone. Nobody can recover it, including us. That's the point.
  • Support can't "take a look" at a contract or anything you told Leave privately. They can see that a contract exists and its size.
  • Your public record is public. Stats, rosters, and announced deals aren't encrypted, because they aren't secret.

3. How your key works BEFORE LAUNCH

Every private item, whether a strand you told Leave, a contract's text, or a file, is encrypted with its own key. That key is locked twice, and both locks are needed to open it:

Lock 1A hardware key in Google Cloud (an HSM). Only Leave's two server programs can use it. No person at Leave can, by policy, and any attempt to change that policy is logged and alerts the founder's phone.
Lock 2Your key share: 32 random bytes that live on your phone, in the Keychain, and in your iCloud Keychain if you use it. It never leaves your devices.
Recovery codeA 28-character code shown once when you sign up. It can rebuild your key share if you lose every device.

When you open the app, it unlocks only the items your session needs and hands our server those item keys for at most 15 minutes. The server can read what you're using now, never your whole account. Someone holding a full copy of our database, our backups, and our cloud key still can't read a single strand, because your share isn't there.

  • New phone? It gets no private data until a phone you already use approves it, or you enter your recovery code. Every new sign-in notifies your devices and your Talent Teammate.
  • Revoke your key and, after a 24-hour undo window, every private item on our servers becomes permanently unreadable, including in backups.
  • Destructive actions (revoke, rotate, delete, export, changing your Teammate) need Face ID on a device that already holds your share.

4. Who can see what

Who can see each kind of Leave data
WhoPublic recordPrivate strandsContract textAccount metadata
YouYesYesYesYes
Your Talent TeammateYesNoYesYes
Leave staffYesNoNoYes
Google (hosting)Encrypted at restNoNoEncrypted at rest
Anthropic (AI model)During a requestDuring a requestDuring a requestNo
An AI chat you connectYesOnly if you unlock itOnly if you unlock itNo
Someone with a court orderYesNoNoYes

"No" means the design makes it cryptographically impossible, not just against the rules. If we're ever legally compelled to hand over data, we can only hand over what we can read, and we'll report the request in our transparency report. Athletes aged 13 to 17 can't unlock private data for any AI chat.

5. AI

  • BEFORE LAUNCH Model: Claude Opus 5.5 by Anthropic, running inside Google Cloud (Vertex AI). There's no separate Anthropic account holding your data.
  • BEFORE LAUNCH Zero data retention: we have applied for Google's zero-data-retention option, so prompts and answers aren't stored after your request. It's pending Google's approval. Until it's approved, Google may keep prompts for up to 30 days solely for abuse monitoring, as the Privacy Policy says. We'll update this label when it's approved.
  • BEFORE LAUNCH No training: your data is never used to train or fine-tune any AI model, by us or by our providers.
  • BEFORE LAUNCH Speech and documents stay on your phone first. Voice is transcribed on the device. Contracts are read on the device where possible, and a scan goes to Google's text recognition only after the app asks you.

6. Vendors

Every company that touches Leave data, and exactly what it gets:

Google CloudHosting, encrypted storage, the AI model, and, only when you agree on screen, document text recognition and server speech. US region (Iowa). BEFORE LAUNCH
AnthropicThe Claude model, run inside Google Cloud. Sees the request you're making, during that request. BEFORE LAUNCH
WorkOSSends your sign-in code and handles AI chat sign-in. Gets your email address. BEFORE LAUNCH
StripePayments. Gets your email and card; Leave never sees your full card number. BEFORE LAUNCH
ResendSends Leave's email, including waitlist emails today. Gets your email address. LIVE
BrandfetchBrand logos and colors for your contracts. Gets a brand name, never who you are. BEFORE LAUNCH
Apple and GoogleApp stores, push notifications, and crash reports (Firebase Crashlytics, with any email, strand, or contract text removed before upload). BEFORE LAUNCH
CloudflareRuns this website, stores the waitlist, and runs the bot check on the waitlist form (Turnstile). Cookieless visit counts. LIVE

No advertising companies, no data brokers, no Google Analytics. We'll update this list before any vendor changes, and log it below.

7. Your controls

ExportProfile → Export my data. Your profile, Web, and contracts, encrypted so only you can open them. BEFORE LAUNCH
DeleteProfile → Delete my account, with a typed confirmation. Built in the app today IN TESTING; deleting real data within 30 days, including backups, starts with the backend BEFORE LAUNCH.
Revoke your keyProfile → Your key. Makes everything private permanently unreadable after a 24-hour undo. Not built in the app yet; it lands with the encryption work. BEFORE LAUNCH
AI chatsProfile → Connections. See every connected AI chat, unlock private data for 15 minutes or an hour, lock or disconnect. BEFORE LAUNCH
WaitlistUnsubscribe from any email, or email chris@leaveyouragent.com to be removed. LIVE

8. Infrastructure

How the servers are locked down, all BEFORE LAUNCH unless marked:

  • Data stays in the US. An organization-wide policy blocks creating anything outside US locations.
  • No keys to leak. Service-account keys are banned by policy; deploys authenticate without stored secrets.
  • Only reviewed code runs. Every server image is signed by the build pipeline, and Google refuses to run anything unsigned. The build workflow is public, so anyone can check what runs is what was reviewed.
  • Logs even the founder can't erase. Audit logs go to a storage bucket with a locked 400-day retention; nobody, including the account owner, can shorten it or delete them.
  • Google access is logged and needs our approval (Access Transparency and Access Approval).
  • Private database, private network. The database has no public address. The knowledge graph runs on a confidential VM inside the private network.
  • Web application firewall and rate limits on every public endpoint, plus per-account limits and app attestation, so scripted clients can't reach the API.
  • Nothing private in logs. Request bodies, transcripts, and strand text are excluded from logging, and no personal data goes in URLs.

9. Athletes under 18

  • IN TESTING Nobody under 13. The app refuses a birth date under 13.
  • IN TESTING Athletes aged 13 to 17 use Leave through an account a parent or legal guardian creates, and that adult is their required Talent Teammate.
  • BEFORE LAUNCH Minors can't share private data with any AI chat. The server refuses it.
  • LIVE No profiles of people who haven't signed up. Leave looks up your public record when you create an account, never before.

10. This website, today LIVE

  • HTTPS only, with HSTS, a strict Content Security Policy, and no framing by other sites.
  • No cookies. Visits are counted with Cloudflare Web Analytics, which sets no cookies and doesn't follow you around the web. Fonts are served from this site.
  • The waitlist record never stores your IP address. It's used for a few minutes to limit sign-ups from one connection, then dropped.
  • DNSSEC signs the domain's DNS records, so nobody can forge them.
  • CAA records allow only named certificate authorities to issue certificates for the domain.
  • Email from leaveyouragent.com is signed (DKIM), and DMARC tells mail providers to quarantine anything forged in our name.

Known gaps we're closing

  • DNSSEC is on and the domain is signed; the link that lets resolvers verify it (a DS record at the .com registry) is being published, which can take up to a day.
  • DMARC is set to quarantine forged mail. After a week of clean reports it moves to reject it outright.
  • The domain is submitted to the browsers' HSTS preload list and waiting to be included in a browser release.

You can check the headers yourself with securityheaders.com or SSL Labs.

11. Check it yourself

  • LIVE The design documents are public: the architecture and security plan, the API contract, the AI chat (MCP) design, and the iOS app's security plan, at github.com/…/leave-security. Every change has a public history.
  • LIVE Transparency report: as of September 23, 2026, Leave has received zero government or third-party requests for user data. We'll publish a report twice a year.
  • BEFORE LAUNCH The encryption code on your phone will be open source, so you can check that your key share never leaves the device.
  • LATER Independent penetration test once Leave is funded, then yearly, with the findings and fixes published here. There hasn't been one yet.
  • LATER Bug bounty after the first penetration test. SOC 2 when a league or partner asks for it.

12. Report a vulnerability

If you find a security problem in Leave, email chris@leaveyouragent.com with what you found and how to reproduce it. We'll confirm we got it within 2 business days, keep you updated, and credit you when it's fixed, if you'd like.

Safe harbor

If you act in good faith, we won't pursue legal action against you for security research on leaveyouragent.com or the Leave app. Good faith means: only use accounts you own or fictional data; don't access, change, or keep other people's data; don't disrupt the service (no denial-of-service, spam, or social engineering of staff or vendors); and give us reasonable time to fix a problem before you disclose it publicly. There's no paid bounty yet.

Machine-readable contact details are at /.well-known/security.txt.

13. Changelog

Sep 23, 2026Waitlist hardened: a bot check (Cloudflare Turnstile), stricter address checks, one welcome per inbox, opt-outs that can only be undone from the person's own inbox, and a response that never reveals who is on the list. www and http now redirect in one hop.
Sep 23, 2026DNSSEC turned on, CAA records added, DMARC moved from monitoring to quarantine, and the domain submitted to the HSTS preload list.
Sep 23, 2026Page published. Design documents released publicly. Transparency report: zero requests.

Questions about anything on this page: chris@leaveyouragent.com. Leave organizes publicly available information and explains terms. It is not a licensed agent and does not provide legal or financial advice.

leae
  • Press
  • Privacy
  • Terms
  • Security
  • Talent Teammates
  • Instagram
  • TikTok
  • X
  • Threads
  • LinkedIn
LEAVE ORGANIZES PUBLICLY AVAILABLE INFORMATION AND EXPLAINS TERMS. IT IS NOT A LICENSED AGENT AND DOES NOT PROVIDE LEGAL OR FINANCIAL ADVICE. ALL FIGURES ILLUSTRATIVE.