Privacy policy
Privacy
Last updated: 26 August 2026
The English version is the official and authoritative version. Translations are provided for convenience only. If a translation differs, the English version applies to the extent permitted by law. This does not limit any mandatory rights under applicable law.
1. Who is responsible for your information
LEAF London is a volunteer-run community. The LEAF London organising team determines how personal information is used for this website and the LEAF Board and acts as the data controller for that processing.
For questions, rights requests or complaints about personal information, contact hello@leafmeetup.com. We may ask for enough information to confirm your identity before acting on a request.
2. Information we collect
We collect only the information needed to operate the website, respond to people and keep the community usable and safe.
- Account and sign-in information: the name, email address, email-verification status, provider identifier and profile image supplied by Google or Apple, together with session records, IP address and browser information used by the authentication system.
- Profile information: your display name, profile image, biography, role, account status and the date you accepted the Community Guidelines.
- Board content: posts, comments, chosen topic and visibility, images, edits, deletion status and cached translations of public posts.
- Safety information: reports, report details, moderation outcomes, administrator notes and records of actions taken to protect the community.
- Contact information: your name, email address, message, selected topic and whether you asked to receive a copy.
- Notification information: whether you want email about comments or replies, the language used for those emails, unsubscribe status, and limited delivery records such as message identifiers, delivery state, bounces or spam complaints.
- Technical and security information: security-check results, rate-limit signals, request metadata and operational error logs. We do not intentionally keep raw Turnstile response tokens as community records.
- Language preference: the language you choose or the language inferred from your browser, stored locally on your device.
3. Where information comes from
Most information comes directly from you when you sign in, edit a profile, post, comment, report content or contact us. Google or Apple supplies the account information needed for social sign-in. Our systems and Cloudflare generate limited technical and security information when you use the service.
Event details come from the public LEAF Meetup calendar. Meetup remains the source for RSVP information and last-minute event changes. If you visit Meetup, WhatsApp, Instagram or another external service, that service collects information under its own privacy policy.
4. Why we use information and our lawful bases
We use different lawful bases for different purposes. We rely on contract where processing is necessary to create and operate your account and provide the Board under our Terms of Use. If you do not provide the required sign-in or post information, we cannot provide that feature.
We rely on legitimate interests to run a useful volunteer community, answer enquiries, prevent spam and abuse, secure the service, moderate content, maintain records needed for fair appeals, and understand and fix operational problems. We balance those interests against the rights and reasonable expectations of members.
Board comment and reply emails are optional account notifications. You can turn either type off in your account or use the unsubscribe link in an email. An email may contain a short excerpt from a comment on a public post. We never include comments or other content from members-only posts.
We may use information to comply with a legal obligation, respond to lawful requests, establish or defend legal claims, or protect someone in an urgent safety situation. We document and review the basis that applies to each purpose.
5. Visibility, translation and moderation
When you publish a public post, its title, body, author profile and public comments can be viewed without signing in, indexed by search engines and discovered by AI-enabled search services. Copies outside LEAF may remain after the original is edited or deleted. Members-only content is restricted to signed-in members and excluded from public search features, but other members can still copy or share what they see.
Public post titles and bodies may be sent to OpenAI to create a translation. The request is configured not to be stored by the OpenAI API, and the translated result is cached in LEAF's database. Members-only posts are not sent to OpenAI for translation. Machine translations can be wrong, so the original remains available.
Posts and comments may be checked by Cloudflare Workers AI for possible safety issues. An unsafe result creates an internal report for human review. The AI does not automatically delete content, restrict an account or ban a member, and LEAF does not make solely automated decisions with legal or similarly significant effects.
Do not publish sensitive information about yourself or another person unless it is necessary and you are comfortable with the selected audience. Use the private reporting route for safety concerns rather than posting them publicly.
6. Who receives information
LEAF organisers and moderators can access information only where needed to operate the service, answer enquiries and handle safety or legal matters. We also use carefully selected service providers for specific jobs.
- Cloudflare provides website hosting, D1 database storage, R2 image storage, image processing, queues, Turnstile security checks, rate limiting, AI moderation and transactional email delivery. Cloudflare processes the recipient address, email message content and limited delivery metadata needed to send, troubleshoot, suppress bounces and honour spam complaints.
- Google and Apple provide social sign-in and send us the account details described above.
- OpenAI receives the title and body of public posts when a translation is requested.
- Meetup supplies public event information. WhatsApp, Meetup, Instagram and other external services receive information directly from you when you follow a link or use their service.
- Professional advisers, insurers, regulators, courts or law-enforcement bodies may receive information where reasonably necessary and lawful.
7. International processing
Some providers operate internationally, so personal information may be processed outside the United Kingdom. Where UK data-transfer rules apply, we require an applicable safeguard, such as UK adequacy regulations or approved contractual protections, and take reasonable steps to ensure the information remains protected.
You can contact us for more information about the safeguards relevant to a particular transfer.
8. Cookies and browser storage
The website uses secure, essential cookies for authentication, OAuth state, session protection and bot prevention. These are needed to provide the sign-in and security features you request. Cloudflare Turnstile may also use essential storage to distinguish people from automated abuse.
We store your preferred language in local browser storage so equivalent pages can open in that language. You can clear cookies and local storage in your browser, but doing so may sign you out, reset your language or interrupt an in-progress security check.
We do not currently use advertising pixels, behavioural advertising cookies or third-party audience analytics. If that changes, we will update this policy and obtain consent where required before using non-essential storage.
9. How long we keep information
We keep personal information only for as long as it is needed for the purpose described here. We review records and delete or anonymise information that is no longer needed.
- Account, profile and active Board content are normally kept while the account or content remains active.
- Sessions and OAuth verification records are kept until they expire, are revoked or are no longer needed for secure sign-in.
- Deleted or hidden content, reports and moderation records may be kept for a limited period where needed to investigate safety issues, handle an appeal, prevent repeated abuse, or meet legal obligations.
- Post images are kept while attached to an active post and are scheduled for removal when the post is deleted. Technical copies may take additional time to disappear from caches or provider backups.
- Public-post translations are kept with the source post and replaced when the source changes. They are removed through the same account/content cleanup process.
- Contact messages and delivery records are kept until the enquiry is resolved and then only while reasonably needed for administration, safety, dispute handling or legal obligations.
- Notification preferences are kept with the account. Notification delivery records are retained only as reasonably needed to prevent duplicates, troubleshoot delivery, honour opt-outs and manage bounces or complaints, then deleted or anonymised.
- Security and operational logs follow short provider or operational retention periods appropriate to investigating abuse and service failures.
10. Your data protection rights
Depending on the circumstances, you can ask for access to your personal information, correction, deletion, restriction, portability, or an explanation of how it is used. You can also object to processing based on legitimate interests. That right to object is brought to your attention explicitly here.
Email hello@leafmeetup.com to exercise a right or make a data protection complaint. We aim to respond within the period required by UK data protection law. Some rights are not absolute, and we will explain if an exemption applies.
Please give us a chance to address the concern first. You also have the right to complain to the UK Information Commissioner's Office (ICO).
11. Adults, sensitive information and other people
LEAF's website account and Board are intended for adults aged 18 and over. We do not knowingly create accounts for children.
LEAF does not require you to provide sensitive information such as ethnicity, religion, health information, political views or sexual orientation. A post, image or safety report may nevertheless reveal sensitive information. Share only what is necessary, choose visibility carefully, and do not disclose another person's information without a valid reason and appropriate permission.
Where a private safety report contains sensitive or offence-related information, access is restricted and we use it only where an appropriate legal basis and additional data-protection condition apply.
12. Security and changes to this policy
We use access controls, secure cookies, encrypted connections, private media storage, input validation, rate limits and human moderation processes to reduce risk. No online service can promise absolute security, so please contact us promptly if you believe an account or personal information has been compromised.
We may update this policy when the service, providers or law changes. The date above shows the current version. We will bring material changes to members' attention before a new use of personal information begins where required.
