Lever Today · Legal
Privacy Policy
Last updated: July 30, 2026
Lever Today ("the Service") is operated by Manne IT Solutions Private Limited, Hyderabad, Telangana, India ("we", "us"). We build calm software whose business model is subscriptions — we do not sell your personal data, and we do not show advertising. This policy explains what we collect, why, and the controls you have.
1. Information we collect
- Account information. Name, email address and authentication identifiers provided when you sign up (we use Logto for secure authentication).
- Content you create. Contacts, notes, journals, goals, habits, time entries, financial records, health entries and routine configurations you enter into the Service.
- Connected-service data. Only when you explicitly connect an integration (see Section 2), data from that service such as calendar events, contact details, fitness metrics, files or email metadata.
- Usage & device data. Basic logs (IP address, browser type, timestamps, error traces) used for security, debugging and capacity planning.
2. Google user data & the Limited Use disclosure
When you connect Google Calendar, Google Fit, Google Drive, Gmail, Google Keep or Google Contacts, the Service accesses only the scopes you grant on the Google consent screen, and uses that data solely to provide the features you asked for (for example, showing your events, syncing health metrics, or importing notes).
Lever Today's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use Google user data to provide user-facing features, we do not transfer it except as necessary to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, or to comply with law.
You can disconnect any integration at any time from Settings → Integrations, which stops further access and lets you delete previously synced data. You can also revoke access from your Google Account permissions page.
3. AI processing
Our assistant and routine features send the minimum necessary context to AI model providers acting as our processors (currently DeepSeek for language models and Groq for voice transcription) to generate a response. This content is used only to produce your result; we contractually require processors not to use your content to train their models. You may use the Service fully without enabling AI features.
Health & financial data are never sent to the AI without your explicit consent. Because health data is a special category under GDPR Article 9 and financial records are sensitive, AI processing of them is off by default. The assistant and routines are blocked from using your health or financial data until you separately turn each one on under Settings → Privacy. Granting that consent is also what authorises the international transfer described in Section 6 (GDPR Art 9(2)(a) and Art 49(1)(a)). You can withdraw either consent at any time, which immediately re-blocks that category.
4. How we use information
- To provide, maintain and improve the Service's features you use.
- To run the routines and notifications you configure.
- To secure accounts, prevent abuse and debug failures.
- To send essential service communications (you control marketing emails separately).
Where the GDPR applies, we must tell you the legal basis for each purpose. Ours are:
| What we do | Legal basis |
|---|---|
| Run your account and the features you use | Contract — Art 6(1)(b) |
| Take payment for a subscription | Contract — Art 6(1)(b) |
| Send essential service, security and billing emails | Contract — Art 6(1)(b) |
| Keep the Service secure, prevent abuse, debug failures | Legitimate interests — Art 6(1)(f), in running a safe service |
| Keep records we are legally required to keep (e.g. tax) | Legal obligation — Art 6(1)(c) |
| Connect a third-party integration you choose | Consent — Art 6(1)(a); withdraw by disconnecting it |
| Analytics cookies and product analytics | Consent — Art 6(1)(a); off until you accept |
| Marketing emails | Consent — Art 6(1)(a); unsubscribe any time |
| AI processing of your health data | Explicit consent — Art 9(2)(a) (health data is a special category, so consent is the only basis we rely on) and Art 49(1)(a) for the transfer |
| AI processing of your financial data | Explicit consent — Art 6(1)(a), separately controlled |
Where we rely on consent you can withdraw it at any time without affecting anything we did beforehand. Where we rely on legitimate interests you can object — see Section 9.
5. Sharing
We share personal data only with:
- Processors that host and power the Service (cloud hosting, authentication, AI providers listed above) under data-processing agreements. Every one of them is named on our sub-processors page, with its purpose and country.
- Integrations you connect, at your direction (e.g., sending a Telegram message you requested).
- Analytics providers — Google Analytics, PostHog and Plausible — but only if you allow analytics. They are off by default: nothing loads and no analytics cookie is set until you accept in the consent banner, and turning analytics off under Settings → Privacy stops them again.
- Legal authorities when required by applicable law.
We never sell personal data and never share it for cross-context behavioural advertising.
6. International data transfers
We are based in India and some of our processors are located outside your country, so providing the Service can involve transferring your personal data internationally. Where that happens we rely on an appropriate safeguard under Chapter V of the GDPR (for EU/EEA users) and equivalent protections under India's DPDP Act. Our current cross-border processors are:
- DeepSeek — China. Language-model processing for the AI assistant and routines. China has not received an EU adequacy decision, so we do notsend special-category (health) or financial context to this provider unless you have given the explicit consent described in Section 3; that consent is the transfer safeguard for such data (GDPR Art 49(1)(a)). Non-sensitive assistant content is covered by a data-processing agreement with standard contractual clauses. You can avoid this transfer entirely by leaving AI features off.
- Groq — United States. Voice-to-text transcription when you use voice input. Transfers are covered by a data-processing agreement with standard contractual clauses.
- Hosting & authentication providers. Cloud infrastructure and Logto authentication, engaged under data-processing agreements with standard contractual clauses where the provider is outside your region.
- Analytics — United States / EU. Google Analytics and PostHog (US) and Plausible (EU), covered by standard contractual clauses where applicable. These run only with your consent, so you can avoid these transfers entirely by declining analytics.
- Connected apps — United States. Composio, which brokers the third-party app integrations you choose to link, under standard contractual clauses.
The full, versioned list is on our sub-processors page. You can request a copy of the relevant safeguards by contacting us at the address in Section 12.
7. Retention & deletion
Your content is retained while your account is active. You may delete individual records at any time in-app. Deleting your account removes your personal data from production systems within 30 days; if backup copies exist, they expire on a rolling schedule within 90 days of deletion. See our Data Deletion page for step-by-step instructions.
8. Security
Data is encrypted in transit (TLS 1.2+), and stored credentials for connected services (such as Google OAuth tokens) are encrypted at rest. Access to production systems is restricted and logged. No method of storage is 100% secure, but we treat your life's data with the seriousness it deserves and will notify you of any breach affecting you without undue delay.
9. Your rights
Subject to applicable law (including India's DPDP Act 2023 and, where applicable, the GDPR), you have the following rights. Use the in-app controls or contact us — we respond within 30 days, free of charge.
- Access (Art 15) — get a copy of your data. Settings → Account → Export.
- Rectification (Art 16) — correct anything inaccurate, in-app.
- Erasure (Art 17) — delete your account and data. Settings → Account.
- Restriction (Art 18) — ask us to pause processing while a dispute is resolved.
- Portability (Art 20) — your export is machine-readable.
- Object (Art 21) — object to processing based on legitimate interests.
- Withdraw consent (Art 7(3)) — any time, under Settings → Privacy, without affecting processing already carried out.
- Automated decision-making (Art 22) — we do not make decisions with legal or similarly significant effects about you by automated means. The AI assistant only responds to you; it does not decide anything about you.
Complaining to a supervisory authority
If you are in the EU/EEA and think we have handled your data wrongly, you may lodge a complaint with your local data protection authority (Art 77) — the list is at edpb.europa.eu. In India you may complain to the Data Protection Board under the DPDP Act 2023. We would rather hear from you first, but you are not required to contact us before going to a regulator.
Data protection contact
We have not appointed a statutory Data Protection Officer — our processing does not meet the Art 37 thresholds requiring one. Privacy matters are handled directly by our team at privacy@lever.today, which is the contact point for any request or complaint under this policy.
We are established in India and do not currently have an Art 27 EU representative. If our EU-facing activity grows to the point where Art 3(2) applies, we will appoint one and name them here.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We will notify you of material changes to this policy by email or in-app notice at least 14 days before they take effect.
12. Contact
Manne IT Solutions Private Limited · Hyderabad, Telangana, India
Privacy questions: privacy@lever.today
General support: support@lever.today