Public trust overview

Data, trust and human control

Leora helps businesses use their own operational and customer information while keeping clear boundaries around consent, access, verification and human approval.

Core trust principles

Clear boundaries, throughout the platform.

Trust is expressed through access, evidence, consent and review—not through unsupported promises.

  1. 01

    Business-specific by design

    Business data remains within the relevant business context.

  2. 02

    Relevant customer context

    Customer information is used only within the context of the relevant business.

  3. 03

    Restricted sensitive handling

    Sensitive information receives additional handling boundaries.

  4. 04

    Human approval

    People remain available to review and approve important actions.

  5. 05

    Evidence before answers

    AI responses depend on recorded business evidence.

  6. 06

    Safe failure

    When supporting information is missing, Leora should say so rather than invent an answer.

Data categories

The information Leora may work with.

Actual data collected depends on the modules and integrations enabled by each business.

Business information

  • Services
  • Menus
  • FAQs
  • Opening hours
  • Policies
  • Uploaded documents
  • Staff-approved knowledge

Customer information

  • Contact details
  • Preferences
  • Consent status
  • Visit history
  • Conversation context
  • Explicitly disclosed allergies or dietary requirements

Operational information

  • Conversations
  • Tasks
  • Campaign activity
  • Staff actions
  • Delivery states
  • Audit events

Sensitive information

Health-related disclosures require a stricter boundary.

Allergies and similar health-related disclosures are treated as sensitive information, not ordinary preferences.

  • Allergies must not be inferred from orders.
  • Access should depend on role permissions, consent and venue policy.
  • Staff verification is required before safety-critical decisions.
  • AI must not guarantee that a dish or service is safe.

AI boundaries

Fact, inference and decision stay distinct.

Leora should retrieve recorded business information, identify uncertainty, show evidence where appropriate, avoid inventing unsupported facts and escalate where human confirmation is required.

  1. 01

    Recorded fact

    Information supported by recorded business evidence.

  2. 02

    Inference

    A conclusion drawn from available signals, clearly distinguished from fact.

  3. 03

    Recommendation

    A suggested next step for a person to review, edit or dismiss.

  4. 04

    Missing information

    A visible gap that should not be filled with an invented answer.

  5. 05

    Human decision

    The final judgement or approval retained by the responsible person.

Consent and customer control

Consent should be specific, visible and capable of being withdrawn. Customer rights requests need a defined business process.

Profile consent

Whether a customer profile may be created and maintained.

Personalisation consent

Whether relevant context may be used to tailor an experience.

Marketing consent

Whether the business may send permitted marketing communication.

Consent withdrawal

A customer can withdraw a permission previously given.

Correction

Customers can ask for inaccurate information to be corrected.

Deletion

Customers can request deletion where the applicable rules allow it.

Export requests

Customers can request a copy of relevant information through the business’s process.

Real production policies and response processes will depend on the business acting as controller and Leora’s final contractual and legal framework. These processes are not presented as certified or independently audited.

Security architecture

Defence in depth, described without absolutes.

Leora uses multiple technical and operational boundaries. Each control has a defined scope and must be maintained, monitored and reviewed in production.

Tenant isolation

Business records are scoped to the relevant tenant.

Supabase Row-Level Security

Database policies provide an additional tenant-aware access boundary.

Server-side tenant resolution

Protected operations resolve business context on the server rather than trusting browser-supplied identifiers.

Private document storage

Uploaded knowledge documents use private, tenant-scoped storage paths.

Controlled service-role operations

Elevated operations remain server-side and are limited to defined workflows.

Encrypted secret handling

Provider credentials and secrets are kept out of browser-facing payloads and handled through protected configuration.

Webhook signature verification

Supported inbound webhook requests are checked against provider signatures.

Replay protection

Time and event boundaries help reject repeated provider requests where supported.

Auditability

Important activity can produce records that support review and investigation.

Environment separation

Development and production configuration are kept as distinct operating contexts.

Human control

People remain responsible for consequential action.

Leora can organise context and prepare work. The responsible team keeps visibility and control where judgement matters.

  • Approving knowledge changes
  • Reviewing sensitive information
  • Confirming guest requests
  • Taking over WhatsApp conversations
  • Approving campaigns
  • Correcting customer data
  • Reviewing automation outcomes

Third-party services

Some capabilities depend on external providers.

Leora may depend on Meta and WhatsApp, OpenAI, Supabase, hosting providers, email providers, and booking, EPOS or CRM systems.

Meta and WhatsAppOpenAISupabaseHosting providersEmail providersBooking, EPOS or CRM systems

Availability, pricing, data processing and functionality may also depend on those providers and the business’s own configuration.

What Leora does not do

Clear limits are part of a trustworthy product.

Leora does not:

  • Guarantee allergen safety
  • Replace professional or staff judgement
  • Silently place orders
  • Submit reviews without the customer
  • Send campaigns without configured permission and controls
  • Make unsupported claims from missing evidence
  • Combine customer records across unrelated businesses
  • Automatically treat every conversation as permanent memory

Production status

A transparent view of readiness and dependencies.

Foundation, launch work, external approvals and legal review are shown separately.

Live foundations

Product foundations implemented in the Leora platform.

  • Tenant isolation
  • Knowledge controls
  • Evidence-based responses
  • Consent-aware customer model
  • Human takeover foundations
  • Audit foundations

Beta or launch-stage

Operational readiness that must be completed and proven in production.

  • Production deployment
  • Live customer operations
  • Real business onboarding
  • Production monitoring
  • Final operational policies

External approval dependent

Availability depends on provider review, access and supported configuration.

  • Meta Business Verification
  • WhatsApp Embedded Signup approval
  • Template approval
  • Live messaging access

Legal review required

Materials requiring final commercial and legal review before launch.

  • Privacy notice
  • Terms
  • Cookie policy
  • Data processing agreements
  • Retention schedules
  • Subprocessor disclosures

A considered foundation

Trust should be designed into the product