Privacy policy

Last updated: 3 August 2026

This policy explains what we collect through this website (leewyn.app), how the Leewyn app itself handles your teenager's data once you're a customer, and what rights you have either way. It's written by us, not a template — if anything is unclear, email hello@leewyn.app.

1. Who we are

The data controller is ToModern e.U. (Marc Jenni), Seitenstettengasse 5/37, 1010 Wien, Österreich — full company details are in our legal notice. You can reach us at hello@leewyn.app for anything to do with your data.

2. What we collect on this website

When you visit leewyn.app or sign up on the landing page, here's everything we collect — no more:

  • Email address.When you request early access, we store the email you give us so we can let you know when a spot opens up. That's the only thing we use it for.
  • IP address.Captured only on the signup endpoint, to spot and block bulk automated submissions of the landing page's signup form. Deleted on a rolling basis, never used for anything else, and never shown to anyone outside us.
  • Anti-spam "honeypot" field.Our form has a hidden field that only bots fill in. If a submission trips it, we discard the whole thing — we don't store anything from it, not even the fake email address.
  • Basic analytics.We use PostHog (hosted in the EU) to see how many people visit this site, which pages they look at, and whether the "Get Leewyn" button works. This can include your approximate location (derived from IP) and device/browser type at the moment of the event. We've deliberately turned off the things that would make this more invasive than it needs to be: autocapture is off (we only send the specific events listed below, nothing is tracked automatically), we don't set a cookie or any other persistent identifier — each visit is anonymous and unlinked from your last one — and we never build a profile tied to you as a person.

The specific events we send to PostHog are: a button click on "Get Leewyn" (with which button you clicked, e.g. header or hero), and whether a signup on the landing page was submitted, completed, or failed. That's the full list.

3. What the Leewyn app collects, once you're a customer

This is a different system from the website above, so it gets its own section. Leewyn works by becoming the device owner on your teenager's phone — the same kind of lock companies use on work devices — and enforcing rules locally, on the device itself:

  • We don't route your teenager's traffic through our servers to filter it — blocking happens locally on the device.
  • We don't see, log, or store which apps your teenager opens or which sites they visit. There's no browsing history, message content, call log, or location feed for us to collect, because we don't build one.
  • We don't take screenshots and we don't generate screen-time reports that leave the device.
  • The device-owner lock itself (what's blocked, that it can't be uninstalled or bypassed via safe mode/sideloading) is configuration data tied to the device and your parent account, not a log of your teenager's activity.

We'll need standard account details from you as the parent (email, and — once billing is live — payment information via whichever processor we use at the time). We don't have that integration built yet; this policy will be updated to name that processor before it goes live.

4. Why we process it

  • Running the landing page signup and letting you know when a spot opens.
  • Keeping the signup form working for real people, not scripts.
  • Understanding — in aggregate — how many people visit and what's working, so we can improve the site.
  • Meeting legal obligations, if we're ever required to (e.g. responding to a lawful request).

We don't use anything we collect for advertising, and we don't build marketing profiles. There's no ad pixel on this site, and there never will be.

5. Legal basis for processing (GDPR)

  • Consent— you submitting the landing page's signup form (Art. 6(1)(a)).
  • Legitimate interest— abuse prevention on the signup form, and basic aggregate analytics (Art. 6(1)(f)). We've weighed this against your privacy and kept collection to the minimum needed.
  • Legal obligation — where the law requires it of us (Art. 6(1)(c)).

We apply this same standard to every visitor, regardless of where you're located — not just to visitors in the EU/EEA.

6. Who we share it with

We keep the list of processors short on purpose: our database host (Neon, hosted in Frankfurt, Germany) and PostHog (analytics, EU Cloud). We don't sell your data to anyone, we don't share it with ad networks or data brokers, and we don't transfer it outside the EU. The only other case where we'd share information is if we were legally required to, or if Leewyn were ever acquired or merged — in which case your data would move under the same protections described here.

7. How long we keep it

  • Email addresses from the landing page: until we've offered you a spot, or you ask us to delete it — whichever comes first.
  • IP addresses collected for abuse prevention: deleted on a rolling basis, typically within days, never kept long-term.
  • Analytics events: retained according to PostHog's standard retention window for our plan — see PostHog's own privacy documentation for the current figure.

8. How we keep it safe

We use encrypted connections (TLS) between your browser, our servers, and our database, and we limit who and what can access the data described above to what's needed to run the site. No system is 100% secure, and we won't claim otherwise — but we keep the amount of data we hold small on purpose, so there's less that could ever go wrong.

9. Children's privacy

This website — the landing page you're reading about right now — is meant for parents and guardians, not children, and we don't knowingly collect personal data from children through it. The Leewyn app itself is different: it's designed to run on a teenager's device, installed and controlled by their parent, under the local-only model described in section 3.

10. Do Not Track

Unlike most sites, we actually honor it: if your browser sends a Do Not Track signal, our analytics respect it.

11. Your rights

Under the GDPR, you can ask us to access, correct, delete, or export the data we hold about you, restrict or object to how we use it, or withdraw consent at any time — none of that affects the lawfulness of anything we did before you asked. Email hello@leewyn.app and we'll sort it out ourselves, not via a support queue. If you think we've gotten something wrong, you can also complain to the Austrian data protection authority (dsb.gv.at).

12. Changes to this policy

If we change how we handle your data, we'll update this page and move the "Last updated" date at the top. For anything material — a new processor, a new purpose — we'll say so plainly here rather than burying it in legal language.

13. Contact, or to review/delete your data

ToModern e.U., Seitenstettengasse 5/37, 1010 Wien, Österreich — hello@leewyn.app. Email us to review, update, or delete anything we hold about you.