Leela

L2 Legal · Privacy

Privacy Policy.

What we collect, how we use it, who we share it with, and the choices you have. Written to be read, not skimmed.

Last updated

01

Overview

Humblepaper, Inc. ("Humblepaper," "Leela Works," "we," "our," or "us") operates the Leela Works service, formerly known as Outbox Black (the "Service"). This Privacy Policy explains what data we collect, how we use it, how we share it, how we protect it, and the choices available to you.

This policy applies to information you provide directly to us, data generated through your use of the Service, and data we receive from connected third-party services, including Google, when you choose to connect them.

02

Information We Collect

2.1 Information you provide

  • Name, email address, phone number, and account details
  • Contracts, legal documents, drafts, comments, and redlines
  • Negotiation notes, playbooks, workspace content, and related instructions
  • Support requests and other communications with us

2.2 Information collected automatically

  • Device, browser, and operating system information
  • IP address, approximate location, and log data
  • Usage events, settings, and product interaction data

2.3 Google user data we may access when you connect Google

If you choose to connect a Google account, we may access and process the following categories of Google user data, depending on the scopes you authorize:

  • Connected Google account information: Your Google account email address, account identifier, granted scopes, and, if provided through the Google OAuth connection, name and profile image
  • Google Calendar data: Read-only calendar event metadata and related scheduling information, including calendar identifiers, event titles, descriptions, times, locations, attendees, conferencing links, and recurrence information if you authorize calendar access
  • Gmail metadata: Message and thread IDs, sender and recipient addresses, subject lines, labels, timestamps, snippets, attachment metadata, history IDs, and related message metadata
  • Gmail content: Email body text, HTML body, and attachments or other content contained in messages and threads associated with your negotiations or mailbox views in the Service
  • Gmail sending data: Recipient addresses, subject line, message body, reply references, and related data needed to draft or send an email on your behalf when you instruct the Service to do so

If you connect Google, the Service may request Google profile information, Gmail read-only access, Gmail send access, and read-only Google Calendar access. We use those permissions only to provide the connected email, negotiation, and scheduling features you enable.

03

How We Use Information

We use information we collect to operate, secure, and improve the Service. This includes:

  • Creating and managing your account and workspaces
  • Analyzing contracts, drafts, and negotiation materials
  • Generating redlines, comments, summaries, and workflow suggestions
  • Operating connected inbox, drafting, and message sending features
  • Providing support, troubleshooting, security, and fraud prevention
  • Complying with legal obligations and enforcing our terms

3.1 How we use Google user data

  • We use connected Google account information to authenticate you, connect your account, identify the connected mailbox, and maintain the authorized connection.
  • We use Gmail metadata and message content to retrieve, display, organize, search, summarize, and analyze emails relevant to your negotiations and related workflows inside the Service.
  • We may use read-only Google Calendar data to sync and display calendar events and scheduling context inside the Service where those features are enabled.
  • We use Gmail send permissions only when you choose to draft, reply to, or send an email through the Service using your connected Google account.
  • We may store synced Gmail data in our systems so your emails, thread context, and negotiation history remain available inside the Service.

We do not sell Google user data. We do not use Google user data to train generalized artificial intelligence or machine learning models. We use Google user data only as needed to provide or improve user-facing features that are part of the Service you requested. The use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

04

Data Sharing

We do not sell personal information, including Google user data. We may disclose information only in the following limited circumstances:

  • Service providers and subprocessors: Cloud hosting, managed infrastructure, storage, security, analytics, customer support, email delivery, and AI processing providers that process data on our behalf and under contractual restrictions, but only as needed to provide, secure, support, or improve the user-facing features of the Service
  • Your organization and authorized users: If you use shared workspace or collaboration features, information may be visible to users your organization authorizes
  • Legal and safety reasons: When required by law, regulation, legal process, or to protect rights, safety, and the security of the Service
  • Corporate transactions: In connection with a merger, financing, acquisition, or sale of assets, subject to appropriate confidentiality and legal safeguards
  • With your direction or consent: When you ask us to share data or authorize an integration or workflow that requires it

We do not share Google user data with advertisers, data brokers, or information resellers. We do not transfer, sell, or use Google user data for advertising, retargeting, personalized advertising, credit decisions, or generalized AI or machine-learning model training.

05

Data Storage and Protection

We use administrative, technical, and physical safeguards designed to protect personal information and Google user data. These measures include:

  • HTTPS/TLS encryption for data in transit
  • Encryption at rest for stored Google user data and other sensitive data
  • Encrypted storage of OAuth access and refresh tokens
  • Access controls, authentication checks, and least-privilege practices
  • Logging, monitoring, and security review processes
  • Restricted internal access to production systems and customer data

No method of transmission or storage is perfectly secure, but we use reasonable measures designed to reduce risk and protect the data we process.

06

Data Retention and Deletion

We retain personal information and Google user data only for as long as needed to provide the Service, maintain account functionality, preserve negotiation history and workspace records, meet legal or compliance obligations, resolve disputes, and enforce our agreements.

If you disconnect a connected Google account through the Service, we revoke the Google token on a best-effort basis and delete the connected account record from our system. Depending on how you used the Service, related synced email and workspace data may remain in our systems until it is deleted under our account or workspace data retention processes.

You may request deletion of your account data, including Google user data stored by us, by emailing humans@humblepaper.co. We will review and process verified deletion requests in accordance with applicable law and our operational requirements. When a verified deletion request is processed, we delete or de-identify the applicable Google user data from active systems unless retention is required for legal, security, fraud-prevention, or dispute-resolution purposes; backup copies expire on our regular backup lifecycle.

You can also remove our access from your Google account settings at any time through Google's security and connected apps controls.

07

Legal Bases and Your Rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent where processing is based on consent. Where applicable, we process data based on contract performance, legitimate interests, consent, and legal obligations.

To exercise privacy rights, contact humans@humblepaper.co.

08

International Transfers

We may process information in countries other than your country of residence. Where required, we use appropriate safeguards for cross-border transfers.

09

Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16.

10

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy here and revise the "Last updated" date above.

11

Contact

If you have questions about this Privacy Policy or our privacy practices, write to us:

Humblepaper, Inc.
169 Madison Ave STE 11274
New York, NY 10016
humans@humblepaper.co