ClickCease

Leni developers

Developer integrations privacy notice

This notice explains how Leni handles information when a customer uses the Leni HTTP API or connects an AI assistant through Leni's remote MCP runtime. It supplements the Leni Privacy Policy and the Leni Terms and Conditions. If those documents conflict with this notice, the applicable agreement controls.

Information involved

Depending on the tool a customer chooses to use, Leni may process:

  • account, organization, property-access, OAuth-grant, and project-key identifiers;
  • requests and tool arguments sent by the customer or connected AI assistant;
  • authorized operating and financial metrics returned through the Leni semantic layer;
  • analysis messages, status information, results, and authorized attachments;
  • Personal Context and eligible Organization Context consulted for relevant knowledge;
  • authorized Context folder names and safe attachment metadata;
  • files attached to authorized Context notes when the customer separately authorizes file access;
  • Context notes created, changed, or deleted only through an authorized Context action; and
  • usage, security, diagnostic, and audit information needed to operate and protect the service.

How Leni uses the information

Leni uses this information to authenticate the customer, enforce organization and property boundaries, answer authorized requests, run requested analyses, retrieve relevant Context, perform explicit Context operations, apply plan and usage rules, prevent abuse, troubleshoot failures, and maintain the service.

A connected assistant cannot use the MCP runtime for raw SQL, unrestricted warehouse access, money movement, or property-management record changes. Leni applies server-owned tenant and property filters to supported data tools.

Connected assistants and service providers

The connected assistant provider sends authorized tool requests to Leni and receives the tool results needed to answer the customer. The provider may retain the customer's conversation and returned results under its own terms and privacy policy. Removing the Leni connection stops future access but does not automatically delete copies already retained by that provider.

Leni may also use infrastructure, security, analytics, storage, and model providers to operate requested features. These providers receive only the information needed for their role and are subject to the applicable contractual and security controls.

Retention and customer controls

Analysis records, operational logs, and account data follow Leni's applicable product, contractual, security, and legal retention practices. Saved Context remains available until it is changed or deleted by an authorized user, removed with the associated account or organization, or otherwise handled under the applicable agreement.

Customers can control the integration by:

  • approving or denying the requested OAuth scopes during connection;
  • removing the connector or revoking its Leni authorization;
  • reviewing, correcting, or deleting authorized Context notes;
  • using existing Leni account, plan, and access-management controls; and
  • contacting Leni for privacy, deletion, or support requests.

Security and tenant boundaries

Leni verifies the connected user, organization membership, granted scopes, and applicable property access on the server. Personal Context remains user-scoped. Organization Context is available only when the account and plan permit it. Context file links are short-lived bearer links issued only after the source note is revalidated under the user, organization, and model partition. Leni does not use client-supplied organization or property filters as the authority for access decisions.

Contact

For privacy or integration questions, email info@leni.co. For implementation guidance, see the Leni developer documentation.