Business information
- Services
- Menus
- FAQs
- Opening hours
- Policies
- Uploaded documents
- Staff-approved knowledge
Public trust overview
Leora helps businesses use their own operational and customer information while keeping clear boundaries around consent, access, verification and human approval.
Core trust principles
Trust is expressed through access, evidence, consent and review—not through unsupported promises.
Business data remains within the relevant business context.
Customer information is used only within the context of the relevant business.
Sensitive information receives additional handling boundaries.
People remain available to review and approve important actions.
AI responses depend on recorded business evidence.
When supporting information is missing, Leora should say so rather than invent an answer.
Data categories
Actual data collected depends on the modules and integrations enabled by each business.
Sensitive information
Allergies and similar health-related disclosures are treated as sensitive information, not ordinary preferences.
AI boundaries
Leora should retrieve recorded business information, identify uncertainty, show evidence where appropriate, avoid inventing unsupported facts and escalate where human confirmation is required.
Information supported by recorded business evidence.
A conclusion drawn from available signals, clearly distinguished from fact.
A suggested next step for a person to review, edit or dismiss.
A visible gap that should not be filled with an invented answer.
The final judgement or approval retained by the responsible person.
Consent and customer control
Consent should be specific, visible and capable of being withdrawn. Customer rights requests need a defined business process.
Whether a customer profile may be created and maintained.
Whether relevant context may be used to tailor an experience.
Whether the business may send permitted marketing communication.
A customer can withdraw a permission previously given.
Customers can ask for inaccurate information to be corrected.
Customers can request deletion where the applicable rules allow it.
Customers can request a copy of relevant information through the business’s process.
Real production policies and response processes will depend on the business acting as controller and Leora’s final contractual and legal framework. These processes are not presented as certified or independently audited.
Security architecture
Leora uses multiple technical and operational boundaries. Each control has a defined scope and must be maintained, monitored and reviewed in production.
Business records are scoped to the relevant tenant.
Database policies provide an additional tenant-aware access boundary.
Protected operations resolve business context on the server rather than trusting browser-supplied identifiers.
Uploaded knowledge documents use private, tenant-scoped storage paths.
Elevated operations remain server-side and are limited to defined workflows.
Provider credentials and secrets are kept out of browser-facing payloads and handled through protected configuration.
Supported inbound webhook requests are checked against provider signatures.
Time and event boundaries help reject repeated provider requests where supported.
Important activity can produce records that support review and investigation.
Development and production configuration are kept as distinct operating contexts.
Human control
Leora can organise context and prepare work. The responsible team keeps visibility and control where judgement matters.
Third-party services
Leora may depend on Meta and WhatsApp, OpenAI, Supabase, hosting providers, email providers, and booking, EPOS or CRM systems.
Availability, pricing, data processing and functionality may also depend on those providers and the business’s own configuration.
What Leora does not do
Leora does not:
Production status
Foundation, launch work, external approvals and legal review are shown separately.
Product foundations implemented in the Leora platform.
Operational readiness that must be completed and proven in production.
Availability depends on provider review, access and supported configuration.
Materials requiring final commercial and legal review before launch.