Privacy Policy

Last updated: October 5, 2026

LeanZero SRL (“we”, “us”, “our”) is a limited liability company (societate cu răspundere limitată) registered in Romania.

  • Company name: LeanZero SRL
  • Registered office: Str. Toamnei 23 G, CAM. 1, Loc. Bragadiru, Jud. Ilfov, Cod 077025, Romania
  • Trade register number: J2025012835002
  • CUI (Cod Unic de Înregistrare): 51336260
  • EUID: ROONRC.J2025012835002
  • Contact: office@leanzero.net

This Privacy Policy explains what personal data we collect, why, who receives it, how long we keep it, and what rights you have. It covers:

  • Our Atlassian Marketplace apps: CogniRunner (Jira), Sentinel Vault (Confluence) and LeanZero Management (Jira).
  • Our website, leanzero.net, and everything on it: contact and quote forms, the AI advisors, the newsletter, certification practice exams, MCP demo keys, demo site access, comments, guest submissions and the benchmark leaderboard.
  • Goose Swarm (our desktop app) and the LeanZero Link sign-in service.
  • Our MCP demo servers (MCP Doc Processor and MCP Web Search).
  • Consulting services: Jira and Confluence migrations, AI training and custom Forge app development.

1. Who Is Responsible for Your Data

For our website, Goose Swarm, LeanZero Link, the MCP demo servers (when you use a demo key yourself) and consulting, LeanZero SRL is the data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”).

For our Marketplace apps, the customer that installs the app (through its Atlassian site administrator) is the data controller, and LeanZero acts as a data processor on the customer’s behalf. This includes content a CogniRunner rule or agent sends to our MCP demo servers, if the customer’s administrator connects them. Our Data Processing Addendum sets out the terms of that processing and applies automatically to every customer. If you are a user of a Jira or Confluence site, contact your site administrator first; we will help them with any request.

We have assessed that we are not required to appoint a Data Protection Officer under Article 37 GDPR, because our core activities do not involve large-scale regular and systematic monitoring of individuals or large-scale processing of special categories of data. For any privacy question, write to office@leanzero.net.


2. Our Website (leanzero.net)

2.1 Hosting and server logs

The website runs on Amazon Web Services (AWS Amplify and CloudFront), with its servers in London (eu-west-2). Every request passes your IP address, browser details and the requested URL to our hosting. Our server logs are kept in AWS CloudWatch for 90 days. When our spam filter rejects a form submission, the log line records the IP address, the email address given and the browser details, so that we can find a wrongly rejected message. We use IP addresses and email addresses in memory to limit abuse (for example, how many forms one address can send per hour); these counters are not stored.

2.2 Analytics

We use PostHog to understand how the website is used. PostHog is hosted in the EU (Frankfurt), and our site sends its data through our own address (leanzero.net/ingest). PostHog does not store your IP address with the events it records.

  • Before you choose, or after you choose “Decline”: our site’s script reads page and browser details and sends cookieless, pseudonymous analytics. That means page views (including the full page address), clicks on page elements and the text on them, page performance, and device and browser details. No cookie is set, and the identifier is a hash that changes daily, so you cannot be recognised from one day to the next. Our legal basis is our legitimate interest in knowing which pages work.
  • “No analytics”: the banner’s “No analytics” button, the same size as the others, stops all analytics, including the cookieless kind, on this page and every later visit from this browser.
  • If you accept analytics cookies: PostHog sets a cookie (up to 365 days) so it can recognise your browser across visits, and records session replays (a reconstruction of the pages you view and how you move through them) and heatmaps. In replays, text you type into form fields, the AI advisor conversations and email addresses shown on screen are masked. Our legal basis is your consent, which you can withdraw at any time through Cookie settings.
  • Retention: analytics events are kept for 1 year and session replays for 30 days.

2.3 Contacting us

When you use the contact form or email us, we receive your name, email address, company (if given) and message. The form sends your message to our mailbox and a receipt to you through Resend, our email provider. We do not store form messages in a database. Our mailbox is hosted by Microsoft 365. We keep correspondence for up to 3 years after our last exchange (the general limitation period for civil claims), unless it led to a contract, in which case we keep it with the contract records; we delete it earlier on request unless the law requires us to keep it.

Problem reports from Goose Swarm use the same route. They contain your description, your email, the app version and, only if you tick that option, system details shown to you before sending (engine version, operating system and processor architecture, AI provider, model file name and extension names). They never include your chats, logs or keys.

2.4 AI advisors and quote requests

The chat advisors on our AI, Forge and migration service pages are AI systems. When you chat with one, your messages and the conversation so far are sent to Anthropic (the Claude models) to generate the replies. To answer questions about current facts, the advisor may write a few web search queries from your conversation (the migration advisor can run several per turn, to look up the apps you name). They go to our own search server and from there, on our Serper account, to Serper, a web search service. The queries are written to look up public facts, not about you. Our search server keeps them in its logs for 30 days. We do not store your conversation in a database; if you accepted analytics cookies, session replays include the chat only as masked text.

If you ask for a quote, we receive your name, email, message, your answers and, if you came from a chat, the conversation. We use Anthropic to write a short summary of the request for us and for you, and Resend sends both. Anthropic processes this data under its commercial terms, does not use it to train its models, and deletes API inputs and outputs within 30 days, except where its terms provide otherwise.

While you fill in a quote form, your browser keeps a draft (including your name, email and message) in its local storage so you do not lose your work. The draft stays in your browser until you clear it; it is never sent to us until you submit.

2.5 Newsletter

The newsletter uses double opt-in: when you sign up, we email you a confirmation link and add you to the list only after you confirm. Your email address is kept in our email provider (Resend). Every newsletter contains an unsubscribe link. When you unsubscribe, we keep your address marked as unsubscribed so that we never email you again; ask us if you want it deleted completely. Our legal basis is your consent.

2.6 Certification practice exams

To take a practice exam, you request an access key by email. When you first use the key, we store your email address and a record of the key in Sanity, and your address joins our newsletter list. Using the practice exams requires a subscription to our newsletter: the form where you type your email says so, and if you unsubscribe, your key stops working. Your key record stays in Sanity until you ask us to delete it. Your answers and scores are not stored on our servers. Your browser remembers your email and key for 180 days so you do not have to sign in again; “Forget this browser” removes them.

2.7 MCP demo keys

To get a demo key for MCP Doc Processor or MCP Web Search, you request a single-use link by email (valid for 24 hours). When you claim the key, your address joins our newsletter list, as the claim page says; if you unsubscribe, we may stop issuing you keys. The key record stays until you ask us to delete it. We store your email address with the key record in Sanity, and the demo server operated by LeanZero records the key under a label that contains your email address. Demo keys do not expire; you can have up to three active keys per product. See section 5 for what the demo servers keep.

2.8 Comments and guest submissions

When you comment on an article, we store your name and your comment in Sanity, our content platform, and publish both. The form asks for your email address so we can check that it is a real address and block spam; we do not store or publish it. When you submit a guest article or tutorial, we store your name, email address and submission privately in Sanity for review, and publish only what we accept, under the name you chose.

2.9 Booking a call

Booking buttons open Calendly. Calendly’s scripts load only when you open the booking window. If you open it from our contact page, the name and email you typed into the contact form are filled into Calendly for you. Calendly processes your booking for us as our processor, and applies its own privacy policy to your use of calendly.com.

2.10 Videos

On our product pages, videos are click-to-load: nothing is requested from YouTube until you press play, and the player then loads from youtube-nocookie.com. Videos embedded in articles show a thumbnail that our own server fetches from YouTube, so your browser contacts YouTube only when you press play; the player then loads from youtube-nocookie.com. YouTube (Google) processes your data under its own privacy policy.

2.11 Donations

Our Buy Me a Coffee link takes you to buymeacoffee.com, which handles the payment. We receive your name or alias, any message, and the amount. We never receive your card details.

2.12 Benchmark leaderboard

Goose Swarm can publish a benchmark run to the public leaderboard on leanzero.net when you press “Publish”. A published run is public by design: the title, model and provider, scores and per-check details, run times, the names of the machines you ran it on and their speed figures, screenshots, a screen recording of the generated app (required for some benchmark tiers), a random pseudonym, and a random installation ID. Choose machine names with that in mind. Runs are stored in Sanity until removed; email us to remove one.

2.13 Demo site access

To try our apps on our demo site, leanzero-demo.atlassian.net, you request a single-use link by email (valid for 72 hours). When you press the button on the page the link opens:

  • Atlassian account. We create an Atlassian account for your address, or use the one you already have, and give it access to the demo site as a Jira and Confluence administrator. Atlassian holds the account under its own terms and privacy policy; the account also appears in the Atlassian organisation that owns the demo site, which LeanZero administers.
  • Our record. We store your email address, your Atlassian account ID, when your access started and ends, how many times you extended it, and a short history of those changes, privately in Sanity. We also keep one work item for you in a private project on the demo site, holding your Atlassian account (not your email address) and those dates, so our automation (CogniRunner) can end your access on time.
  • Other people on the site. The demo site is shared. Other evaluators, who are administrators too, can see your name (and your email address, depending on your Atlassian profile settings) and what you create or change there, and could open that private project.
  • Emails and the newsletter. We email you about your access (welcome, a reminder before it ends, extensions, the end). Your address also joins our newsletter list, as the page and the email say; every newsletter has an unsubscribe link, and unsubscribing does not end your access.
  • This browser. Confirming sets the lz_demo cookie (section 11).

Access lasts five days and you can extend it up to three times. When it ends, we take your account out of the demo site’s groups; the account stays, and what you made on the site stays until other evaluators or we change or clean it up. Email us to have your record deleted and your account removed from our organisation.


3. Our Marketplace Apps

3.1 What applies to all three apps

  • They run on Atlassian Forge. Each app runs inside Atlassian’s infrastructure and stores its data in Forge storage on your Atlassian site. Apart from the optional MCP demo servers a CogniRunner administrator can connect (section 5), we run no servers that receive app data.
  • AI runs on Atlassian-hosted models by default. Each app’s AI features use Forge LLM, which runs Anthropic Claude models on Atlassian’s platform; prompts and answers do not leave Atlassian.
  • Logs. Atlassian lets us see the apps’ operational logs in the Forge developer console, unless your site administrator has turned log sharing off for the app. Log lines can contain Atlassian account IDs, work item and page keys, attachment file names and short excerpts of prompts, AI answers and AI-written text. We use them only to fix problems.
  • Licence data. See section 6.1 for what Atlassian gives us about your licence.
  • Backups that survive uninstalling. Each app keeps a backup of its configuration and records (which include personal data, as listed below) on your own Atlassian site, so you can restore your setup after a reinstall. Because the backup lives on your site, uninstalling the app does not delete it. Section 3.2 to 3.4 say where it is and how to delete it. Data in Forge storage itself is handled by Atlassian’s retention rules after an uninstall. Data residency: data in persistent Forge storage follows your site’s data residency where Atlassian supports it; Atlassian gives no residency commitment for app logs or Forge LLM requests.
  • Keys you give an app (AI provider keys, git tokens and similar) are stored in Forge storage on Atlassian’s platform (CogniRunner keeps them in Forge’s encrypted secret storage since version 1.28.0), never in our source code.
  • No cookies, no analytics. The apps set no cookies, send no analytics or telemetry to us (the logs above are Atlassian’s, shown to us in the developer console), and keep only interface preferences and form drafts in your browser’s local storage.

3.2 CogniRunner (Jira)

CogniRunner automates Jira workflows: AI validators and post-functions, conditions (which never call AI), listeners, scheduled jobs and agents, including service desk agents and the Coder.

  • Which AI provider. By default, CogniRunner uses Forge LLM inside Atlassian. Your administrator can instead choose another provider and add its key: OpenAI, Azure OpenAI, AWS Bedrock, Anthropic, Google Gemini, OpenRouter, Ollama, LM Studio, a self-hosted OpenAI-compatible server or Goose Swarm. In that case the content a rule sends (field values, attachments, comments and, for agents, the work items they handle) goes to that provider under your organisation’s own agreement with it. These providers are chosen and contracted by you, not by us.
  • Other services your administrator connects. MCP servers, web search and GitHub or Bitbucket (for the Coder) receive the data a rule or agent sends them, again under your own agreements. Keys your administrator adds for MCP servers or web search are sent to that server with each call. If your administrator connects the optional LeanZero-hosted MCP demo servers, the content sent to them, and those keys, are processed by us as your processor (see section 5).
  • Deploy pipeline. If your administrator sets up a CogniRunner deploy pipeline, it deploys with the FORGE_EMAIL and FORGE_API_TOKEN secrets your administrator adds to your own GitHub or Bitbucket repository. Since version 1.28.0 CogniRunner stores no Atlassian email or API token for this, and identities saved by earlier versions are deleted.
  • What agents can do. Only when a CogniRunner administrator or editor enables them, agents can act in Jira (comment, edit, transition, assign, create and link work items, log work, add watchers and send notification emails), reply to service desk customers, create and update Confluence pages, and in a connected repository create repositories, commit, open, review and merge pull requests and trigger deployments. The service desk agents can also be given Atlassian REST operations chosen by an administrator, including deleting work items or changing configuration; those need a person’s approval each time. CogniRunner’s guard can create incident work items, send email and switch off Automation rules.
  • What it stores in Forge storage: rule configuration; an execution log (work item key, field, up to 300 characters of the checked value, up to 200 characters of the prompt, the result and up to 500 characters of the AI’s reason, and for post-functions the value written), kept for 30 days; an audit log of who changed what (Atlassian account IDs, no field values), kept for 60 days; the guard’s incident records (actor name, summary and reporter of a deleted work item), kept for 60 days; the service desk agents’ work items and journal (30 to 90 days) and their memories, notes about people they work with and voice samples taken from people’s comments (until deleted); memories, kept until deleted; Coder conversations and staged code, kept for 90 days after the last turn; redacted samples of listener events (7 days); per-user preferences; cached display names; and the keys your administrator adds.
  • Backup: a Jira project that CogniRunner creates (key CRBAK, or CRBAK2 to CRBAK5 if that key is taken; or, if your administrator chooses, properties on one work item) holds the backup. It contains configuration, memories, agent notes and voice samples, Coder conversations and code, documents and the app’s role list, but no keys or tokens. While the app is installed it recreates the backup daily, so to remove it, uninstall the app and then delete the project (or the work item properties).
  • Personal data reporting: since release 1.29.0 (version 7.0.0 in Manage apps), CogniRunner reports the Atlassian account IDs it stores in the places it keeps them for people to Atlassian’s personal data reporting API, as Atlassian requires of apps that store personal data (an ID that appears only inside text, such as a log line, is not reported). It sends account IDs and dates only, and reports each account once per reporting cycle (7 days by default; when Atlassian sets another period, CogniRunner follows it within 1 to 30 days). When Atlassian reports an account as closed, CogniRunner deletes the records that belong to that person alone (such as their Coder preferences and their list of Coder conversations), removes them from the app’s administrator list, and wherever else it keeps their account ID (rules, audit entries, Coder conversations and its other records) replaces it with an anonymous placeholder and removes any name, email address or avatar stored with it. Post-function code and staged Coder files are stored under a hash of their content and are not rewritten. The backup project gets the erased data with the next backup; the two older backups it keeps, and a backup set aside with Start fresh, keep the earlier copy until they are replaced or deleted. A name written in free text without the account ID beside it is not found this way and stays until that record expires or is deleted (memories, agent notes and voice samples are kept until someone deletes them). When Atlassian reports that an account changed, CogniRunner drops the display name it caches for that person in its list of rules.
  • Debug trace: if a rule’s internal debug flag is set, CogniRunner writes the checked value, prompt and reason to a property on the work item, which anyone who can see the work item can read. It stays there until the property or work item is deleted.

3.3 Sentinel Vault (Confluence)

Sentinel Vault seals Confluence attachments and page sections, runs approval workflows and classifies pages. It sends no data outside Atlassian, and its AI review uses Forge LLM only.

  • What it stores in Forge storage: seals (who sealed, by account ID and name, a note and a snapshot of a sealed section; since version 6.7.0 no email address is stored with a seal, and since 6.9.0 none in approver lists; the weekly check removes older addresses, and backups taken before it did keep them until newer backups replace them, or, for the last backup an earlier installation took, until the backup is deleted); edit and steward requests (the requester’s name and reason); approvals, workflow history and read confirmations (who, when, decisions and reasons, and signature evidence); an activity log (who did what, on which page); notification watches and inbox indexes of account IDs; API token hashes with who created them; for users who turn on code signing, their authenticator secret; for AI review, the findings history (90 days) and the latest findings per page, which can quote page text.
  • Retention: the activity log, workflow history and read confirmations are compliance records, kept while the app is installed. A site administrator can turn on Delete old history and set a keep period of 30 to 3,650 days under Site settings, Privacy and retention; a weekly check then deletes older records. Copies in older backups stay until newer backups replace them, or, for the last backup an earlier installation took, until the backup is deleted. Workflow history is also removed when its page is purged from Confluence, and each approver’s pending approval record is removed once the approval is decided.
  • Personal data reporting: since version 7.0.0, Sentinel Vault’s weekly check reports the Atlassian account IDs it stores to Atlassian’s personal data reporting API, as Atlassian requires of apps that store personal data. It sends account IDs and dates only, and reports each account at most once per reporting cycle (7 days by default; when Atlassian sets another period, Sentinel Vault follows it within 1 to 30 days). When Atlassian reports an account as closed, Sentinel Vault deletes that person’s own records (such as their signatures, read confirmations and edit requests) and their authenticator, removes them from steward lists and read-confirmation audiences, and replaces every other mention of them, including on the markers it writes on pages, with “Former user”. A name written in free text (a seal note, a request or decision reason) without the account ID beside it is not found this way and stays with that record. The exception is sealed content: it is the record of what was sealed and is never rewritten, so a closed person mentioned inside sealed content stays mentioned there, as in Confluence’s own page history. Where a backup exists, the app then takes a fresh backup without that person and deletes every older backup that still names them outside sealed content. When Atlassian reports that an account changed, the stored display name is refreshed.
  • AI review sends the page title, up to 40,000 characters of page text and the administrator’s own rules to Forge LLM. It is off until an administrator, or a space steward for their space, turns it on.
  • Backup: a Confluence page that only the app can read holds the backup (it excludes authenticator secrets and API token hashes). The Backup tab’s Delete the backup deletes every backup file for good and moves the emptied page to the space trash. After that, a new backup is written only after the next change made in the app or over its REST API (or a page view that puts back sealed text), or when an administrator presses Back up now, so delete it right before uninstalling, or contact us and we will help.
  • Support: if the app was uninstalled without a backup, it shows your site ID and installation IDs to send us, so we can ask Atlassian to restore the old data within 21 days.

3.4 LeanZero Management (Jira)

LeanZero Management is a project planner on your Jira work items. It sends no data outside Atlassian, and its AI features use Forge LLM only.

  • What it stores in Forge storage: plan indexes with work item keys, summaries, statuses, dates, estimates, assignee names and account IDs, and reporter names; plan members and roles; capacity per person; drafts (24 hours); who is viewing a plan, with their name and avatar (shown for 90 seconds after their last activity, and removed when they leave the plan or the next viewer arrives) and who holds the editing lock; snapshots, scenarios, baselines and portfolios; report notes and sponsor reports you capture; AI results, kept per person; the account IDs it reports to Atlassian, with dates (and, while a reporting cycle runs, the new names of changed accounts); an audit log of actions with account IDs, kept for 60 days; and REST API tokens, stored as hashes and expiring after 90 days by default.
  • AI features are on by default; a Jira administrator can turn them off. They send Forge LLM the plan data they need: work item keys, summaries, statuses, dates, dependencies, plan and target names and, for some features, the text of recent comments (with mentions removed and authors left out). Portfolio suggestions also send project names, descriptions and categories and epic summaries, and the AI helpers send any text you type into them. The REST “explain” call can include assignee names and account IDs.
  • Reports you publish are written to your Confluence site as the person who publishes them.
  • Backup: the backup (plan index rows with summaries and names, members, drafts, reports, AI notes, snapshots, scenarios, portfolios and capacity) is kept as Jira user properties on the app’s own account, so it survives an uninstall. Only Jira administrators can read it. It stays until a Jira administrator deletes it in the app’s Settings, Maintenance, Backup and restore, Delete backup (since release 4.17.0, version 5.20.0 in Manage apps), or through Jira’s REST API; contact us and we will help.
  • Personal data reporting: since release 4.18.0 (version 6.0.0 in Manage apps), LeanZero Management reports the Atlassian account IDs it stores to Atlassian’s personal data reporting API, as Atlassian requires of apps that store personal data. It sends account IDs and dates only, and reports each account about once per reporting cycle (7 days by default; when Atlassian sets another period, the app follows it within 1 to 30 days). When Atlassian reports an account as closed, the app deletes that person’s capacity settings, last-viewed marks, AI answer caches and their own drafts of unsaved edits, removes them from plan members, and writes “Former user” in place of their name as plan owner and last writer; names on plan rows follow Jira at the next re-index. Snapshots, scenarios and captured sponsor reports are sealed records and keep the names they were captured with; notes written on a sponsor report keep the writer’s name; and capacity rosters, portfolios, other people’s capacity settings and an AI structure not rebuilt since keep the name too. The account ID itself stays where the app records who did something, such as plan ownership and the audit log (60 days). The backup takes these changes on its next run; earlier copies stay in the backup generations it keeps until they age out. When Atlassian reports that an account changed, the app reads the person’s name from Jira again and updates it where they are plan owner, member or last writer.

Goose Swarm runs on your own computers. Your prompts, files and model outputs stay on your machines unless you send them somewhere yourself. The desktop app contacts:

  • GitHub to check for and download updates, which install when you quit the app (your IP address and app version).
  • leanzero.net to load the benchmark catalogue when the app starts, and when you send a problem report or publish a benchmark (sections 2.3 and 2.12).
  • Hugging Face when you browse or download models, and the npm and PyPI registries and OSV (a vulnerability database, sent the package name and version) when an extension is installed or started.
  • The LeanZero Link sign-in and coordination servers, once you sign in to LeanZero Link (below).
  • Any web address that appears as an image in chat content, when the chat shows it.
  • Usage statistics of the upstream goose project. Goose Swarm is built on the open-source goose project. Its usage statistics are switched on during setup unless you untick the box on the last setup screen. They contain a random installation ID, operating system and version, processor architecture, app version and install method, session counts and days since install, token counts, provider and model names, settings such as mode and maximum turns, and extension names and count. They go to that project’s PostHog account in the United States, which also sees your IP address, not to LeanZero. Turn them off in Settings → App → Privacy → “Anonymous usage data”, or by setting the environment variable GOOSE_TELEMETRY_OFF=1.

LeanZero Link connects your own Macs running Goose Swarm into one private network. When you sign in to the LeanZero-run sign-in service:

  • Email address: your email is your account identity. There is no password. Every Mac you sign in with the same email joins the same private network.
  • Sign-in code: a 6-digit code is emailed to you through Resend. We store only a hash of the code with your email; it is valid for 10 minutes and can be used once, and an expired record is removed within about an hour.
  • Sign-in token: after sign-in, your Mac keeps a token that is valid for 180 days. We do not store it on the server.
  • Rate limits: counters keyed by your email address and by your IP address limit code requests, and a counter keyed by your email limits code checks. They are deleted automatically two to three hours after your last request.
  • Operations log: the service logs code requests (with your email and IP address), sign-ins and account setup events. The log is rotated daily and archived logs are deleted after 30 days.
  • Account secret: a random secret per account, kept with your email address until your account is deleted.
  • Network records: our network coordination server names your account with a hash of your email. For each Mac you connect it keeps the device name, its network addresses (including public and local IP addresses and ports), operating system details and when it was last seen. Records of devices that go offline are removed after 30 minutes. The coordination server also keeps your account and a record of each device join (its time) until your account is deleted. The account name is derived from your email without a secret, so someone who knows your email could recognise it. The coordination server’s own log (device names and the hashed account names) is deleted after 30 days.
  • Tailscale: the sign-in service is reached through Tailscale, which sees your IP address. When your Macs cannot connect directly, Tailscale relays their traffic; that traffic is end-to-end encrypted, so Tailscale cannot read it. Traffic between your Macs never passes through our servers.
  • No mailing list: signing in does not subscribe you to anything.
  • Deleting your account: email us from the address you signed in with and we will delete your account and its records by hand; there is no self-service deletion yet.

5. Our MCP Demo Servers

MCP Doc Processor and MCP Web Search demo keys (section 2.7) are served from servers that LeanZero operates, reached through Tailscale. When you use a demo key yourself, we are the controller. When a CogniRunner administrator connects them, we process what CogniRunner sends as the customer’s processor under the DPA. In both cases:

  • Logs: the servers log the email address a key was issued to, each call (key, tool, timing) and, for web search, the queries, web addresses and file names requested; the Doc Processor logs document titles and file paths. Logs are deleted after 30 days.
  • Documents: documents you generate with MCP Doc Processor are stored on the server. Download links expire after 24 hours; the files stay until deleted. Email us to delete them.
  • Third parties: web search uses Serper, and page fetches reach the sites you ask for; optional image text recognition in the Doc Processor uses Z.AI. If you send your own Serper or Z.AI key, the call runs on your account; otherwise it runs on ours. Z.AI is outside the EEA with no adequacy decision and no data processing agreement with us, so send images for recognition only if that is acceptable to you.

6. Consulting Clients

When you engage us for consulting (migrations, training, custom development):

  • Contact and billing information: name, email, company name and the details needed for invoicing.
  • Project data: access to your Atlassian site or other systems as needed to deliver the agreed services. The scope of access, and any processing terms, are set in each engagement.

6.1 Data we receive from others

  • From Atlassian, for our Marketplace apps: licence and installation details (your site address and cloud ID, licence status, edition and dates) and the technical and billing contacts on the licence (name, email address and organisation). We use them to administer licences and to contact you about the apps, such as security notices and changes to our sub-processors (legitimate interest in managing the customer relationship, Art. 6(1)(f), and performance of the licence, Art. 6(1)(b)). We keep them while the licence is active and for as long as our accounting records require afterwards.
  • From Calendly: the booking details you enter (section 2.9).
  • From Buy Me a Coffee: your name or alias, any message and the amount (section 2.11).
  • From Atlassian Forge: the apps’ operational logs (section 3.1).

PurposeLegal Basis (GDPR Art. 6)
Running our Marketplace apps for customersWe process on the customer’s instructions as its processor (Art. 28); the customer determines its own legal basis
Answering enquiries, quotes, problem reports and support requestsSteps before a contract and performance of a contract (Art. 6(1)(b)), or our legitimate interest in answering you (Art. 6(1)(f))
AI advisors on our service pagesSteps you ask us to take before a contract (Art. 6(1)(b))
Newsletter, and exam and demo keys tied to itConsent (Art. 6(1)(a)); using the exams and demo keys requires the subscription, as section 2.6 explains
Demo site access (account, record, access emails)Steps you ask us to take (Art. 6(1)(b)); the newsletter that comes with it on consent (Art. 6(1)(a))
Cookieless website analyticsLegitimate interest in understanding how the site is used (Art. 6(1)(f)); object with “No analytics” (see below)
Marketplace licence and contact details from AtlassianPerformance of the licence (Art. 6(1)(b)) and legitimate interest in managing the customer relationship (Art. 6(1)(f))
Analytics cookies, session replay and heatmapsConsent (Art. 6(1)(a))
Comments, guest submissions, published benchmark runsYour request to publish (Art. 6(1)(b))
LeanZero Link accounts and Goose Swarm problem reportsPerformance of the service you asked for (Art. 6(1)(b))
Security, abuse prevention and server logsLegitimate interest in keeping our services safe (Art. 6(1)(f))
Consulting services and invoicingPerformance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))

We do not sell your data, use it for advertising, or make decisions about you that have legal or similarly significant effects based solely on automated processing.

Do you have to give us data? No law requires you to, except the invoicing details Romanian law requires if you buy consulting from us. Some services need it to work: we need an email address to send exam keys, demo keys and sign-in codes, to reply to you, and (only to filter spam) to accept a comment. Without it we cannot provide that service.


8. Sub-Processors and Other Recipients

These providers process personal data on our behalf. The “Used for” column shows which of our services each one serves.

Sub-ProcessorPurposeData ProcessedLocationTransfer safeguardUsed for
Atlassian (Forge platform, including Forge LLM)Hosts and runs our Marketplace apps, stores their data, and runs their AI features on Atlassian-hosted modelsThe Jira and Confluence content the apps work on, app configuration and logs, AI prompts and answersAtlassian's cloud infrastructure. Data in persistent Forge storage follows your site's data residency where Atlassian supports it; Atlassian gives no residency commitment for app logs or Forge LLM requestsAtlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationMarketplace apps
Microsoft (Microsoft 365)Our business mailbox, office@leanzero.net: enquiries, quotes, support, security reports and privacy requestsName, email address, message content and attachmentsMicrosoft's cloud infrastructureMicrosoft's data protection addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationSupport; Website; LeanZero Link and MCP demo servers
Atlassian (Jira Service Management)Our support portal at leanzero.atlassian.netName, email address and the content of your requestAtlassian's cloud infrastructureAtlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationSupport
Atlassian (our demo site)Hosts leanzero-demo.atlassian.net, where we create evaluator accounts and keep one private work item per evaluatorEmail address, name you set on the Atlassian account, Atlassian account ID, access datesAtlassian's cloud infrastructureAtlassian's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationWebsite
Amazon Web Services (Amplify, CloudFront, CloudWatch)Hosts leanzero.net and its server logsIP address, browser details, requested URLs, server log linesLondon (eu-west-2), plus CloudFront edge locations worldwideUnited Kingdom adequacy decision; AWS's data processing addendum (Standard Contractual Clauses) for edge locationsWebsite
PostHogWebsite analytics, and session replay if you accept analytics cookiesPseudonymous usage events, device and browser details, replays of pages viewedEU (Frankfurt)No transfer outside the EEAWebsite
ResendSends our emails (form receipts, keys, sign-in codes, newsletter) and holds the newsletter listEmail address, name if given, the content of the emailUnited StatesResend's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationWebsite; LeanZero Link and MCP demo servers
SanityContent platform for leanzero.net: comments, guest submissions, exam and demo key records, demo site access records, benchmark runsName and comment text, submission details, email addresses on key and demo access records, benchmark entriesEU (Belgium), with a worldwide content delivery network for published contentSanity's data processing addendum (Standard Contractual Clauses) where data leaves the EEAWebsite
AnthropicRuns the AI advisors on our service pages and drafts a summary of quote requestsYour chat messages and, for a quote request, your name, email, message, answers and the chatUnited StatesAnthropic's data processing addendum (Standard Contractual Clauses)Website
SerperWeb search: for the AI advisors, and for MCP Web Search demo keys used without your own Serper keySearch queries (the advisor writes them from your conversation to look up public facts)Not stated by SerperSerper publishes no data processing agreement; we have none in place with it. Queries are written to look up public facts, not about youWebsite; CogniRunner, only with our MCP demo servers
Z.AIOptional image text recognition in the MCP Doc Processor demo, when you use it without your own Z.AI keyThe images you send for text recognitionOutside the EEA (Z.AI does not state where)No adequacy decision and no data processing agreement in place; used only if you send images for recognitionCogniRunner, only with our MCP demo servers; LeanZero Link and MCP demo servers
CalendlyBooking a call with usName, email and the booking details you enterUnited StatesCalendly's data processing addendum (Standard Contractual Clauses) and its EU-U.S. Data Privacy Framework certificationWebsite
TailscaleNetwork access to our LeanZero Link sign-in service and our MCP demo serversIP address and connection metadata; Link device traffic is end-to-end encryptedTailscale's cloud infrastructureTailscale's data processing addendum (Standard Contractual Clauses)LeanZero Link and MCP demo servers; CogniRunner, only with our MCP demo servers

These services receive data when you use them, under their own privacy policies: YouTube (Google) for embedded videos, Buy Me a Coffee for donations, Discord if you join our community server (messages there are visible to its members and handled under Discord’s privacy policy; we moderate the server), the AI providers, MCP servers and git hosts a CogniRunner administrator chooses, and Serper and Z.AI when you use them with your own key through our MCP demo servers. We may also disclose data where the law requires it.

International transfers

Some providers above process data outside the European Economic Area, mainly in the United States. The “Transfer safeguard” column says what covers each one: an adequacy decision (the United Kingdom, or the EU-U.S. Data Privacy Framework for certified providers) or the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in that provider’s data processing terms. Serper and Z.AI are the exceptions: we have no data processing agreement with either, and the table says when they are used. Contact us for a copy of the safeguard for a specific provider.


9. How Long We Keep Data

DataRetention
Marketplace app dataAs described in section 3 for each app, controlled by your administrator; backups stay on your site until deleted
Website server logs (AWS CloudWatch)90 days
Analytics events / session replays (PostHog)1 year / 30 days
Enquiries, quotes and problem reportsUp to 3 years after our last exchange, or with the contract records if they led to a contract; deleted earlier on request unless the law requires us to keep them
AI advisor conversationsNot stored in a database by us; the advisor’s web search queries stay in our search server’s logs for 30 days; Anthropic deletes API inputs and outputs within 30 days, except where its terms provide otherwise
Newsletter subscriptionUntil you unsubscribe; then kept, marked unsubscribed, only to respect your opt-out, or deleted on request
Exam and demo key recordsUntil you ask us to delete them (unsubscribing ends access but does not delete them)
Demo site access recordsUntil you ask us to delete them; the Atlassian account stays yours and outside our control, except its membership of our organisation
Marketplace licence and contact details from AtlassianWhile the licence is active, then as long as our accounting records require
Comments, guest submissions, benchmark runsUntil removed by us or at your request
LeanZero LinkAs described in section 4; account records until you ask us to delete your account
MCP demo server logs / generated documents30 days / until deleted
Consulting project dataThe engagement plus any period agreed in it
Invoices and accounting records5 years from 1 July of the year after the financial year they relate to (Law 82/1991 on accounting, art. 25); annual financial statements for the longer period that law sets

10. Your Rights Under GDPR

You have the right to:

  • Access (Art. 15): get a copy of the personal data we hold about you.
  • Rectification (Art. 16): have inaccurate data corrected.
  • Erasure (Art. 17): have your data deleted, subject to legal retention duties.
  • Restriction (Art. 18): have us limit how we use your data.
  • Portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): object to processing based on our legitimate interest, including cookieless analytics.
  • Withdraw consent at any time, without affecting processing before the withdrawal.

Your right to object

Where we rely on our legitimate interest (cookieless analytics, server logs and abuse prevention, answering you, licence administration), you can object at any time on grounds relating to your situation. For analytics, choose Cookie settings at the bottom of any page and then No analytics: it takes effect at once. For anything else, email office@leanzero.net.

To exercise any of these rights, email office@leanzero.net. We reply within one calendar month. If a request is complex or we receive many requests, we may extend this by up to two further months and will tell you within the first month. For data in a Marketplace app, we pass your request to the customer that controls it and help them answer it.

You also have the right to lodge a complaint with the Romanian supervisory authority, or with the authority in the EU country where you live or work:

ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, Bucharest, Romania
Website: https://www.dataprotection.ro


11. Cookies and Local Storage

  • Our own cookies: one, lz_demo (60 days), set only after you confirm demo site access from our email (section 2.13). It holds your email address, signed, so the demo site page can show your access. “Sign out on this browser” on that page removes it. It is strictly necessary for the service you asked for, so it needs no consent.
  • PostHog analytics cookie (up to 365 days): only if you accept analytics cookies. Change your choice at any time through Cookie settings at the bottom of every page.
  • Third-party cookies: Calendly and YouTube may set their own cookies once you open the booking window or play a video.
  • Local storage in your browser: your cookie choice, your theme, quote form drafts, the practice-exam key and email (180 days), your exam results history and the exam you are taking (until you clear them or choose “Forget this browser”), and PostHog’s record of your analytics choice. This data stays on your device; clear it in your browser at any time.

Our Marketplace apps set no cookies (see section 3.1).


12. Security

  • Our Marketplace apps run on Atlassian Forge and keep their data in Atlassian’s infrastructure. Sentinel Vault and LeanZero Management send no data outside Atlassian; CogniRunner sends data only where its administrator connects a service (section 3.2).
  • All our services use HTTPS. Keys are never kept in source code.
  • Access to our production systems is limited to LeanZero staff who need it.
  • Public forms check every submission for abuse. Newsletter sign-ups are confirmed by email before we add the address; exam and demo keys add it once you use or claim a key sent to that address.
  • We welcome security reports. See our Vulnerability Disclosure Policy.

No method of electronic storage or transmission is 100% secure. For data we control, if a personal data breach affects you, we tell you without undue delay where the law requires it and notify the supervisory authority within 72 hours where Article 33 GDPR applies. For data in our Marketplace apps, we notify the customer, who is the controller, as the DPA sets out.


13. Children

Our products and services are not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact office@leanzero.net and we will delete it.


14. Open-Source Products

Sentinel Vault (Apache License 2.0), MCP Doc Processor (MIT) and Goose Swarm (Apache License 2.0) are published under open-source licences. If you run your own copy or a fork, this Privacy Policy does not apply to your instance; you are responsible for your own processing. It applies to the versions we provide: our Marketplace apps, our website, LeanZero Link, our MCP demo servers and our services.


15. AI Transparency

In line with the EU AI Act (Regulation (EU) 2024/1689), we tell you where AI is involved:

  • The advisors on our service pages are AI systems (Anthropic Claude models). Their answers and estimates are generated and can be wrong; estimates are indicative, and we confirm every quote ourselves before any engagement starts.
  • Our Marketplace apps use AI through Forge LLM by default, or through the provider a CogniRunner administrator chooses. AI outputs are probabilistic and can contain errors. Customers decide which rules and agents run and should review what matters.
  • For the advisors on our website and the AI features of our apps, LeanZero is the provider of the AI system (Article 3(3) of the AI Act). The underlying general-purpose models come from Anthropic (directly, or through Atlassian Forge LLM) or from the provider a CogniRunner administrator chooses. Customers who configure and run our apps are deployers.

16. Changes to This Policy

We may update this Privacy Policy. Changes are posted on this page with a new “Last updated” date. For changes that materially affect your rights or how we process your data, we will give notice on our website or in our products, and by email where we have your address for that service. This policy is information about how we process data; it is not part of any contract with you.


17. Contact

For any question about this Privacy Policy or our data practices:

LeanZero SRL
Email: office@leanzero.net
Website: https://leanzero.net


See also: Terms of Service | Data Processing Addendum | Trust Center | Vulnerability Disclosure Policy