Privacy Policy
Effective: 8 October 2026
This policy explains how the LeadKnight browser extension and the LeadKnight service (“LeadKnight”, “we”, “us”) handle information. LeadKnight is operated by LeadKnight. The short version: the extension only handles the data strictly needed to perform the posts you ask it to make — nothing else — and every post is initiated by you.
How we protect sensitive data
We protect sensitive data with technical safeguards. Our public web service uses HTTPS/TLS and HSTS, and the browser console applies a Content Security Policy and other security headers to limit untrusted content and connections.
Google OAuth tokens are encrypted at rest and held only on our servers; they are never sent to your browser. We use authorization checks and database row-level security to keep workspace data separated from other workspaces.
What the extension does
LeadKnight lets you publish content (text, photos, video) to Facebook on your own behalf, using your own Facebook account that is already logged in to your browser. You create and approve each post in the LeadKnight console (the backend); the extension is only the executor that carries out the posting jobs you have created and approved.
Data the extension handles — strictly limited to its function
- A pairing token & session state. When you pair the extension to your LeadKnight account, a per-installation token and minimal session/heartbeat state are stored locally in your browser (via the extension’s own storage) so the extension can authenticate to your account and run the jobs you create.
- The content you choose to post. The text, images, video, and destination you select are sent to the LeadKnight backend (which you control) and then to Facebook, solely to perform the specific post you requested.
- Your Facebook account identity. The identifier of the Facebook account you are logged in as is read so the extension can link your installation to your own account and post under it. This proves to the backend that the post is being made by you, with your live session.
Cloud phones and optional saved Facebook sign-in
A cloud phone keeps its own Facebook session, separate from the extension’s on-device session. Manual sign-in input and live screen frames transit our short-lived relay. You may optionally save your Facebook email or phone and password per cloud profile, encrypted in our backend, for automatic sign-in. Only the live member who connected the profile can save, replace or delete these details. In a sponsored workspace, admins and owners may additionally delete them, but cannot save or replace them. Nobody can retrieve or view the saved password through LeadKnight. Deleting it removes automatic sign-in, not the current Facebook session.
Saved credentials are typed into the phone using DuoPlus’s HTTPS command API. DuoPlus, our phone provider, receives the plaintext command; whether it logs these commands is unknown. The live phone screen remains visible during automatic entry. This is not end-to-end encryption to the phone and does not protect against a compromised phone or provider or the phone’s control channel being compromised. An already-issued command cannot be recalled by deleting the saved password.
We purge the encrypted email/phone and password from live storage 180 days after saving, or on authorized deletion. Expired credentials cannot be used; a healthy expiry worker purges them within 60 seconds. Encrypted historical backups age out under backup retention, not immediate cryptographic erasure. CAPTCHA challenge images or site keys may be sent to 2Captcha when solving is enabled; passwords, cookies and whole login screens are not sent to the solver. Two-factor authentication and identity checkpoints always require you; we do not store TOTP codes or seeds.
Data we do NOT collect, store, or transmit
The extension does not collect, store, or transmit any data that is not related to its function. Specifically, it does not:
- read, record, or transmit your general browsing history, your other tabs, or pages unrelated to the posting you requested;
- collect personal data, contacts, messages, or content you did not choose to post;
- track you across websites or build an advertising/behavioural profile;
- contain third-party advertising or analytics SDKs that profile you;
- sell, rent, or share your data with third parties for their own purposes.
You initiate all posting
Every post is created and approved by you in the LeadKnight backend. The extension never posts on its own and never acts without a job you have explicitly created and approved. The browser’s debugging/automation capability is used only to carry out your posting actions inside your own authenticated Facebook session — it is not used to read or extract unrelated data.
One exception is your own choice: if you bring over your Nadlanite account and leave “Resume posting automatically” selected, that choice is your approval for LeadKnight to continue posting your active Nadlanite properties to the matched Facebook groups, as Nadlanite did. You can pause or stop any campaign at any time.
Moving your account from Nadlanite
If you choose “Bring over my Nadlanite account”, on your instruction we fetch your data from Nadlanite, the real-estate app you used before: your properties with their photos and videos, your contacts with their notes and WhatsApp conversation summaries, your tasks, your Facebook group list and posting settings, and your business name and logo. We copy the photos and videos into our storage and create the matching properties, campaigns, contacts and tasks for you. WhatsApp settings and messages are not imported.
We keep an encrypted copy of the full Nadlanite export for 12 months so we can help if something did not transfer. It also contains your landing pages, mini-sites, templates and short links, which we do not import. The copy is deleted after 12 months, or earlier if your account is deleted. As part of the move we ask Nadlanite to stop posting for you, so your properties are not posted twice.
If you also tick the consent box to move your subscription, we ask our payment processor (HYP), which also processed your Nadlanite payments, for a token of the card on your Nadlanite payment agreement. We never see or store your full card number. Nothing is charged until the first charge date shown to you, and we record your consent and the exact wording you agreed to.
Google Calendar data
If you connect a Google Calendar, the permission you grant covers viewing and editing events on your calendars. That is the access Google asks you to approve, so we state it plainly.
On your instruction, the assistant can create, change and cancel events on the calendars you selected and add guests. When it adds a guest, Google sends the invitation email on your behalf. By default, cancelling an event and inviting anyone outside your workspace require your explicit approval in the chat before anything is sent. A workspace member with permission to publish content can choose to pre-approve these actions. A workspace administrator can choose to pre-approve these actions because that role includes this permission; actions covered by either choice run without an approval card. Pre-approval removes only the approval card: the assistant still needs your instruction for that specific cancellation or invitation. Nothing is written without your instruction.
LeadKnight reads the list of calendars on your Google account, so that you can choose which ones to use. It then reads events from only the calendars you select; events on the calendars you do not select are never read.
Events from the calendars you select are copied into our database and kept in sync, so the app can use your schedule without calling Google every time. The copy includes each event’s title, description, location, start and end times, whether it is all-day, its status, the organiser’s email address, and the names, email addresses and responses of its attendees — which may be information about other people, not just you.
The calendar event data you ask about, together with a short window of upcoming events, is sent to OpenAI (our primary AI provider) or, as a fallback, Google (Gemini), to answer your questions and carry out your instructions.
The access tokens Google issues are encrypted and held only on our servers, and are never sent to your browser.
When you disconnect your Google Calendar connection, we delete the events we copied from it immediately. We delete the stored Google token too unless another connected LeadKnight feature or connection on the same Google account still uses the shared grant. If one does, we keep the token until the last such connection is disconnected. At that point, we ask Google to revoke the grant and delete the token as soon as revocation succeeds. If Google cannot be reached, we retain the encrypted token solely to retry revocation and delete it as soon as revocation succeeds. Deselecting a single calendar deletes the events copied from that calendar in the same way.
If you instead revoke access from your Google account page, Google does not notify us, so we find out the next time we contact it on your behalf and delete the copied events and tokens then. While a calendar is syncing that is normally within about an hour. If you have deselected every calendar first, nothing of yours is being copied any more, but the stored token may not be discovered as revoked until you next open LeadKnight — so use Disconnect if you want the Calendar connection and its copied events gone at once.
We do not sell your Google Calendar data, do not use it for advertising or to build advertising profiles, and do not use it to develop, improve or train generalised AI models. No LeadKnight human reads it, except where you explicitly ask us to (for example to help with a support request), where it is necessary for security — such as investigating abuse — or where the law requires it.
LeadKnight’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect at any time from Settings, or from your Google account permissions page.
Gmail data
Gmail
What we access. If you connect Gmail, LeadKnight asks for the https://www.googleapis.com/auth/gmail.send permission, and no Gmail read permission, so it can send mail as your connected address. We also receive your basic Google identity: Google account ID, email address, and display name. This permission cannot read, list, search, or download any of your mail. LeadKnight also cannot see delivery status or bounces; Gmail reports a send as accepted, not delivered.
How we use it. We use this access only to send email you or your workspace composed, from your own connected address. Sending through your Gmail account puts the message in your Sent folder and uses your own domain reputation.
How we store it. OAuth tokens are envelope-encrypted at rest on our servers. We store the Google account ID, email address, display name, and granted scopes. For each outbound message, we store the recipient address, subject, and body text as the audit record of what was sent.
How we share and limit its use. To send the message, its recipient address, subject, and body text are transmitted to Google’s Gmail API. We do not sell this Gmail data, use it for advertising, or use it to train AI models. If you use the AI assistant to draft an email, the separate “AI assistant & conversation processing” section below explains how your drafting prompt and generated content are processed before sending.
How to disconnect and erase it. On Channels, disconnect Gmail to immediately remove LeadKnight’s ability to start new sends from that address. A job that has not been dispatched is refused rather than sent.
For each email you or your workspace asked LeadKnight to send, we retain the recipient address, subject, and body as the audit record of that send, together with its outcome and timestamp. The timestamps also enforce Gmail’s rolling sending limit. Disconnecting Gmail does not by itself delete those stored message fields today. You can request erasure of those stored message fields through the contact address below. Approval and audit records are retained as described in Retention below. Disconnecting Gmail does not revoke a Google authorization still used by another connected Google feature or workspace; we revoke the shared Google grant when its final live Gmail or Calendar binding is disconnected.
To request erasure of any other retained records, contact us at [email protected], subject to applicable law.
LeadKnight’s use of Gmail information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. This commitment covers Gmail as well as Google Calendar.
The AI assistant & conversation processing
LeadKnight includes an AI assistant you can chat with to manage your campaigns and content. When you use it:
- Your messages are processed by AI providers. The content of your assistant conversations (and content it generates for you) is sent to OpenAI (our primary AI provider, including for semantic search over your own conversation history) and, as a fallback, Google (Gemini). Under OpenAI’s API policy, request data may be retained by OpenAI for up to approximately 30 days for abuse monitoring; where conversation-state features are enabled, OpenAI also stores recent conversation state server-side for a similar period so follow-up turns do not need to resend history. OpenAI does not use API data to train its models; fallback requests to Google (Gemini) are processed under Google’s applicable API terms.
- This includes content briefs, media, and voice notes. Beyond chat messages, AI processing covers the content-generation briefs you submit, the images, videos, and documents (such as PDFs) you upload for the assistant or for your posts (used to describe and understand the media — video understanding is performed by Google), and voice notes you send (used for speech-to-text). Depending on the task, this material is processed by OpenAI and/or Google as above.
- We keep your conversation history and a searchable archive. To give the assistant long-term memory, your conversations are stored in our database, and past conversations are summarised and indexed so the assistant can recall earlier discussions (for example, a budget you agreed weeks ago). This archive is private to your workspace and user, and is deleted when your data is erased (see “Your choices & rights”).
Website inquiries
If you leave your details in a contact form on our website, we email your name and phone number — and your email address and message, if you add them — to the LeadKnight team, together with the page and language you sent them from. The email is delivered through Resend, our transactional email provider. We use these details only to get back to you about your inquiry. Website inquiries are not stored in our database; they stay in the team’s mailbox until deleted. To prevent abuse, the form may run a Cloudflare Turnstile check, and our servers use your IP address briefly to limit repeated submissions. You can ask us to delete an inquiry at any time (see “Contact”).
Analytics & diagnostics
To operate, debug, and improve the service we use PostHog (product analytics, including analytics of AI assistant conversations — which may include the content of prompts and responses) and Sentry (error monitoring). Assistant search queries and retrieved conversation excerpts are also recorded in an internal tuning log so we can improve the assistant’s recall quality. Automatic redaction removes credential- and secret-shaped strings (such as API keys, tokens, and password fields) before any content reaches these tools, and the tuning log is automatically deleted after 180 days.
Where data is processed
To provide the service and keep an audit trail of the posts you make, the backend processes the data above using standard infrastructure and processing providers: Supabase (database & file storage), Railway (hosting), OpenAI and Google (AI processing, as described above), PostHog (analytics), Sentry (error monitoring), and — for workspaces publishing via official platform APIs or using the WhatsApp assistant — Zernio (a unified social platform API that holds connected-account credentials and transits the content you publish and your WhatsApp assistant messages, the latter riding Meta’s WhatsApp Cloud API). For cloud phones, DuoPlus (the cloud phone provider) hosts the phone’s Facebook session and, when you save a Facebook password for automatic sign-in, receives your Facebook email or phone and password in plaintext to type them into the phone; when CAPTCHA solving is enabled, 2Captcha receives the CAPTCHA image or site key only. Facebook and the other platforms you publish to are the destinations, under their own terms. These providers process data only to operate LeadKnight, not for their own purposes.
Retention
Operational data (your account, paired installations, and an audit log of the posts you make) is retained for as long as your account is active and as needed to provide the service, keep security/audit records, and meet legal obligations. Assistant conversations and the conversation archive are retained while your account is active so the assistant keeps its memory; the internal retrieval tuning log is deleted after 180 days. You can request deletion at any time (see below).
Your choices & rights
- Disconnect / uninstall at any time. Removing the extension, or unpairing it, stops all access immediately and revokes the installation token.
- Access, export, or deletion. You may request a copy or the deletion of your data, subject to applicable law, by contacting us.
Children
LeadKnight is intended for business/professional use and is not directed to individuals under 18. We do not knowingly collect data from children.
Changes
We may update this policy; we will revise the effective date above and, for material changes, take reasonable steps to notify you.
Contact
Questions or requests: [email protected] (LeadKnight).