# Privacy Policy - leanmodels.ai

*Last updated: September 22, 2026*

leanmodels.ai ("we", "us") makes lean, a program that runs AI models on your own computer, and the model packs it runs. This policy explains what information we collect, why we collect it, who we share it with, and what we do not collect.

## Summary

- **Your prompts and outputs never leave your computer.** lean runs models locally. It does not send what you type, or what the model writes, to us or to anyone else.
- **Downloads are counted, not tracked.** When lean downloads a model or checks for updates, our server records which model and lean version were involved, and the country and city the request came from. It does not record your IP address or any identifier for you or your computer, and you can turn it off with `LEAN_TELEMETRY=off`.
- **Purchases need an email address.** If you buy a model, we keep your email address and what your license key unlocks, so we can deliver and support your purchase. Your payment card details are handled by Stripe and never reach us.
- **No selling, no ads, no tracking cookies.**

## What we collect

### Usage events from lean

lean contacts our model registry (`registry.leanmodels.ai`) when you download a model with `lean pull`, when it checks whether a newer version of lean exists, when it reads the model catalog (`lean models --remote`, the recommendations in `lean tune`, and the check `lean models` makes for newer versions of the models you have installed), when it downloads the GPU runtime libraries your graphics card needs (on Windows, once, the first time lean uses the GPU), and when you download a test build. Each of these actions records one event containing:

- the kind of action (download, version check, catalog view, runtime library download, test build download)
- for downloads, the model, its version, and whether it is free or paid; for runtime library downloads, which library bundle
- the version of lean that made the request
- the country and city the request came from
- the date and time

The country and city are worked out by our hosting provider, Cloudflare, from your IP address at the moment of the request. We do not receive or store the IP address itself, a hash of it, or any device or installation identifier. A model download is recorded once, not once per file.

lean's requests also name the operating system and processor type it runs on. We keep only the lean version.

These events carry no identifier, so they cannot be linked to you or to one another. We use them to understand how many people download which models, which versions of lean are in use, and in which regions.

To keep your requests out of these records entirely, set the environment variable `LEAN_TELEMETRY=off` (supported by lean releases published after September 22, 2026). lean then marks every request it makes, and the registry records nothing for a marked request. Downloads and every other feature work the same either way.

The model update check in `lean models` is separately optional: set `LEAN_NO_UPDATE_CHECK=1` to stop lean making that request at all.

### Purchases

Payments are processed by Stripe. When you buy a model, Stripe tells us your email address and what you bought. We never see or store your card number; Stripe handles payment details under its own privacy policy.

We store your email address, your license key, the models it unlocks, and when it was issued. We send your key to you by email through Resend.

### License key checks

When you run `lean login`, download a paid model, or view the catalog with a key saved, lean sends your license key to our registry to confirm what it unlocks. It is used only for that check and is not recorded with usage events.

### Crash reports

If lean crashes, it saves a report on your computer and asks whether to send it to us. Nothing is sent unless you answer yes, or run `lean bug --send` yourself. With `LEAN_TELEMETRY=off` set, lean does not ask.

A report contains the lean version and build, the name of the command you ran (not its arguments), your operating system, processor type, amount of memory, GPU model, any `LEAN_*` settings with secret values removed, the error message, and a backtrace. It does not contain prompts, conversation text, license keys, or file contents. An error message can include a file path from your computer if the error was about that file.

Crash reports are stored privately and used only to find and fix bugs.

### Email you send us

If you email us, we receive your message and address and keep them to answer you. Our email is hosted by Google Workspace.

### This website

leanmodels.ai is a static website hosted by Cloudflare. It sets no cookies of its own and runs no analytics, advertising, or tracking scripts. Cloudflare processes technical request data, such as IP addresses, to deliver the site and protect it from abuse, and may set cookies strictly needed for that, under its own privacy policy.

### Downloading and updating lean

lean is downloaded from GitHub, and `lean update` checks GitHub for new releases. GitHub handles those requests under its own privacy policy. We see only the total number of downloads of each release.

## What we do not collect

- prompts, conversations, documents, or model outputs
- files on your computer
- IP addresses, device identifiers, installation identifiers, or fingerprints
- payment card numbers
- anything at all while a model runs: `lean run`, `lean serve`, and `lean bench` make no network requests

## How we use information

We use the information above to deliver and support purchases, to check license keys, to fix bugs, to understand overall usage so we know what to build, and to meet legal obligations such as tax and accounting records.

We do not sell or rent personal information, we do not use it for advertising, and we do not use your data to train AI models.

## Who we share it with

We share information only with the service providers that run parts of leanmodels.ai for us, and only as much as each one needs:

- **Cloudflare** hosts this website, the model registry, and model storage, and determines the country and city of registry requests
- **Stripe** processes payments
- **Resend** sends license key emails
- **Google Workspace** hosts our email
- **GitHub** hosts lean downloads

We may also disclose information if the law requires it.

## How long we keep it

- **Usage events:** kept indefinitely, since they contain no identifiers.
- **Purchase records:** for as long as your license key is valid, and afterwards for as long as tax and accounting law requires.
- **Crash reports:** until the bug they describe is resolved.
- **Email:** for as long as needed to handle your request.

## Your rights

You can ask us to show you, correct, or delete the personal information we hold about you, which is your purchase record, any crash report you sent, and any email you sent us. Email the address below and we will respond within 30 days. Depending on where you live, laws such as the GDPR in the EU and UK or the CCPA in California give you these and other rights; we honor these requests for everyone, wherever you live. We do not treat you differently for making one.

If you are in the EU or UK, our legal bases are: performing our contract with you (purchases and license keys), your consent (crash reports), and our legitimate interest in understanding aggregate usage, fixing bugs, and keeping our services secure. You also have the right to complain to your local data protection authority.

## Where information is processed

leanmodels.ai is operated from the United States. Information is processed in the United States and wherever our service providers operate.

## Security

Information is sent over encrypted connections and stored with the providers listed above. Only we have access to purchase records and crash reports.

## Children

leanmodels.ai is not directed at children under 13, or under 16 in the EU and UK, and we do not knowingly collect their personal information.

## Changes to this policy

If we change this policy, we will update the date at the top of this page, and we will describe significant changes here.

## Contact

Questions or requests: [privacy@leanmodels.ai](mailto:privacy@leanmodels.ai)
