LEAKVIC
Privacy Policy
Leakvic — leakvic.tilda.ws and the @leakvicbot Telegram bot

1. IntroductionThis Privacy Policy explains how [LEGAL ENTITY NAME] LLC ("Leakvic", "we", "us") collects, uses, stores, shares and protects personal data when you use the website leakvic.tilda.ws, the Telegram bot @leakvicbot and related services (the "Service").
We know that people come to Leakvic at a difficult moment and share material that is deeply private. This Policy is written to be read, not only to be filed. If anything in it is unclear, write to us at [PRIVACY E-MAIL] and we will explain.
This Policy applies together with our Terms of Use. Terms defined there have the same meaning here.
2. Who is responsible for your data
The operator of your personal data under Federal Law No. 152-FZ "On Personal Data" of the Russian Federation, and the controller under the EU/UK General Data Protection Regulation where it applies, is:
Name: [FULL LEGAL NAME] ([LEGAL ENTITY NAME] LLC)
OGRN: [OGRN]; INN: [INN]
Registered address: [REGISTERED ADDRESS]
Privacy contact: [PRIVACY E-MAIL]
Data protection officer / responsible person: [NAME, POSITION]
[EU / UK representative, if appointed: NAME AND ADDRESS]
3. What data we collect
Contact and account data: your Telegram user ID, username, display name and language setting; an e-mail address or other contact detail if you give us one.
Case data: the links (URLs), screenshots, photographs, videos, file names, account names, dates and descriptions you send us; the names or handles of people or sites involved, to the extent you choose to provide them; your statements about how the material was published.
Special-category data: the content you submit will often reveal intimate or sexual images of you, and may reveal your appearance, health, religion, ethnicity, political views or sex life. We treat all of it as data requiring heightened protection.
Identity and authority data: where we need to verify that you are the person depicted or are authorised to act for them, a document or other evidence you choose to send. We ask for the minimum necessary and ask you to redact anything we do not need.
Correspondence: your messages to us and our replies, including chat history with the bot and support e-mail.
Case-handling data: the Removal Requests we prepare and send, the responses we receive from Platforms, and the status and outcome of your case.
Technical data: IP address, approximate region derived from it, device and browser type, language, pages viewed, referring page, timestamps, and error and security logs.
Cookie and analytics data: see clause 12.
We do not ask for and do not want your government ID numbers, payment-card or bank-account numbers, or any data about third parties beyond what is strictly necessary to identify the Reported Material.
4. Why we process your data and on what legal basis
To provide the Service — locate Reported Material, verify your submission, prepare, send and follow up Removal Requests, monitor for re-uploads and report results to you. Legal basis: performance of the agreement between us (GDPR Art. 6(1)(b)); your consent under Art. 9 of 152-FZ.
To process special-category data, including intimate images. Legal basis: your explicit consent (GDPR Art. 9(2)(a)); your consent in writing under Art. 10 of 152-FZ. You give this consent knowingly when you submit such material to us, and you may withdraw it at any time.
To communicate with you — answer questions, give status updates, and provide support. Legal basis: performance of the agreement; our legitimate interest in responding to enquiries (GDPR Art. 6(1)(f)).
To keep the Service secure and prevent abuse — detect fraud, false requests, automated attacks and misuse of the Service against other people. Legal basis: our legitimate interest in the security and integrity of the Service; compliance with legal obligations.
To improve the Service and our AI models — see clause 5. Legal basis: your consent, or our legitimate interest where the data has been de-identified and the balancing test allows it.
To comply with law and to establish, exercise or defend legal claims — including responding to lawful requests from competent authorities and keeping records of requests we have sent. Legal basis: legal obligation (GDPR Art. 6(1)(c)); GDPR Art. 9(2)(f) for special-category data; the corresponding grounds in Arts. 6 and 10 of 152-FZ.
5. AI processing, human review and model improvement
The Service uses automated and machine-learning tools to search for Reported Material, classify what you send, and draft Removal Requests and chat replies. This means your submissions are processed by software automatically as a normal part of providing the Service.
Authorised personnel bound by confidentiality may read chats and view submissions where it is necessary to handle your case, to check quality, to investigate abuse or a security incident, or to comply with law. Access is limited to those who need it and is logged.
Chats and submissions may be used to improve our AI models. Before any such use we remove or mask direct identifiers, and we do not use intimate images or other special-category content to train models without your separate, explicit, freely given consent, which you may refuse without any effect on how we handle your case.
You can object to the use of your data for model improvement, and withdraw any consent you gave for it, at any time by writing to [PRIVACY E-MAIL]. We will stop that use going forward; material already incorporated into a trained model cannot always be extracted, and we will tell you if that is the case.
We do not make decisions producing legal effects about you by solely automated means. You can ask for a person to review your case at any time.
6. Who we share data with
Platforms and hosting providers: to obtain removal, we send Removal Requests that necessarily disclose the URL of the Reported Material and the minimum information the Platform requires, which may include your name or a statement that you are the person depicted. We tell you in advance what a given Platform requires, and we do not send more than that. Some Platforms forward a copy of a complaint to the uploader; where we know that a Platform does this, we will warn you before sending.
Service providers acting on our instructions (processors): hosting and cloud infrastructure, our website builder (Tilda), Telegram as the channel through which the bot operates, AI and machine-learning providers, e-mail and ticketing tools, error monitoring and analytics. They may process data only for us, under a written agreement with confidentiality and security obligations.
Professional advisers: lawyers, auditors and insurers, where necessary and under a duty of confidentiality.
Competent authorities: courts, police, prosecutors, regulators and other bodies where disclosure is required by applicable law or necessary to protect the life, health or rights of a person. We assess each request, disclose only what is legally required, and inform you unless we are prohibited from doing so.
In a reorganisation, merger or transfer of the Service, to the acquiring entity, subject to this Policy or an equivalent one.
We do not sell your personal data, and we do not share it for advertising or marketing by third parties.
7. International transfers
Some of our providers, and many Platforms, are located outside the Russian Federation, so your data may be transferred across borders, including to countries whose data-protection law differs from that of your own country.
Cross-border transfers of personal data from the Russian Federation are made in accordance with Art. 12 of 152-FZ, including, where required, on the basis of your consent and after notification to Roskomnadzor.
Where the GDPR applies, transfers outside the EEA or the UK are made on the basis of an adequacy decision, the European Commission's Standard Contractual Clauses (or the UK IDTA / Addendum), or another lawful transfer mechanism, together with additional safeguards where necessary. You can ask us for a copy of the relevant mechanism at [PRIVACY E-MAIL].
8. How long we keep data
Submitted content (images, videos, screenshots): kept only as long as needed to process your case, and deleted within [NUMBER, e.g. 30] days of the case being closed or of your deletion request, whichever comes first. Where technically feasible, we store a cryptographic hash rather than the file itself for re-upload monitoring, and the hash is deleted with the case.
Case and correspondence data: kept for [NUMBER, e.g. 12] months after the case is closed, so that we can handle re-uploads, appeals and follow-up questions.
Records of Removal Requests sent to Platforms: kept for [NUMBER, e.g. 3] years, to evidence what was sent and to defend potential claims.
Security and access logs: kept for [NUMBER, e.g. 6] months.
Data we must keep by law (including accounting and regulatory records): for the period the relevant law prescribes.
Consent records: for the period during which they may be needed to prove the lawfulness of processing.
When a retention period ends, we delete the data or irreversibly anonymise it. Backups are overwritten on their own cycle, which may take up to [NUMBER, e.g. 90] days after deletion from live systems.
9. How we protect your data
We apply the organisational and technical measures required by Art. 19 of 152-FZ and Art. 32 of the GDPR, including: encryption in transit (TLS) and encryption at rest for submitted content; strict access control on a need-to-know basis with multi-factor authentication; logging of access to case data; confidentiality undertakings for everyone with access; segregation of production data from testing; regular backups; and an internal incident-response procedure.
We minimise what we collect: we ask you not to send documents or files we do not need, and to redact what is not relevant.
No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent authority and you, without undue delay and in the manner and within the deadlines set by applicable law.
10. Your rights
Subject to applicable law, you have the right to: obtain confirmation that we process your data and access it; obtain a copy in a portable format; have inaccurate data corrected and incomplete data completed; have your data deleted; obtain restriction of processing; object to processing based on our legitimate interests, including profiling; withdraw your consent at any time; not be subject to a solely automated decision with legal effect; and lodge a complaint with a supervisory authority.
Under 152-FZ you additionally have the right to require us to block or destroy data that is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary for the stated purpose, and to appeal our actions to Roskomnadzor or in court.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. If you withdraw the consent on which the handling of your case depends, we will have to stop working on that case; we will tell you before doing so.
To exercise any right, write to [PRIVACY E-MAIL] from the contact you used with us, or send a message through @leakvicbot. We may ask a limited question to confirm it is really you — never a copy of an ID unless there is no other way. We answer within 30 calendar days (10 working days for access requests under 152-FZ), and we will tell you if we need longer and why.
Exercising your rights is free of charge. If a request is manifestly excessive or repetitive, we may charge a reasonable fee or decline it, and we will explain why.
11. Children
The Service is intended only for people aged 18 and over, and we do not knowingly collect personal data from children.
We do not accept material depicting sexual content involving a person under 18. Please do not send such material to us: report it to your local police and to a specialised body such as NCMEC (report.cybertip.org; takeitdown.ncmec.org, which works from a hash and does not require you to upload the image) or the Internet Watch Foundation (report.iwf.org.uk).
If we learn that we hold data of a child in breach of this clause, we will delete it promptly, except where we are required to preserve and report it to the competent authorities.
12. Cookies and analytics
The website uses cookies and similar technologies that are strictly necessary for it to work (session, security, load balancing, and the settings of our website builder Tilda).
We [use / do not use] analytics tools: [LIST, e.g. Yandex.Metrica, Google Analytics]. Where analytics or any non-essential cookies are used, we ask for your consent before setting them, and you can withdraw it at any time through the cookie settings on the website or in your browser.
Analytics data is aggregated and used to understand how the site is used, not to profile you or to target advertising. Blocking non-essential cookies does not limit your access to the Service.
The Telegram bot does not use cookies; Telegram's own processing of your account and messages is governed by Telegram's privacy policy, over which we have no control.
13. Changes to this Policy
We may update this Policy to reflect changes in the Service, our providers or applicable law. The current version, with its effective date, is always published at leakvic.tilda.ws.
If a change materially affects how we use your data, we will announce it on the website and, where we can reach you, through the bot or by e-mail before it takes effect, and we will ask for fresh consent where the law requires it.
14. Contact and complaints
Privacy questions and requests: [PRIVACY E-MAIL]. Postal address: [REGISTERED ADDRESS].
If you are not satisfied with our response, you may complain to the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor), rkn.gov.ru, or, where the GDPR applies to you, to the supervisory authority of your country of residence, work, or of the place of the alleged infringement.
You also have the right to seek a judicial remedy.