Skip to content
listlis

Privacy

Listlis privacy policy

Last updated September 8, 2026

This policy covers the Listlis web app, website, Chrome extension, API, Model Context Protocol (MCP) server, sharing features, and email or webhook ingestion. Listlis is the product name used throughout this policy. The operator's formal legal name and address have not yet been published.

Data Listlis handles

Account and authentication data

Listlis stores your email address, optional profile name and image, email-verification state, and a one-way scrypt hash of your password. If you register a passkey, Listlis stores its public key, credential identifier, counter, transports, name, and dates. It never receives the private half of a passkey. Sessions record a hashed bearer token, creation and expiry dates, your IP address, and browser user agent. Password-reset and email-verification records contain short-lived hashed tokens.

Outline and feature data

Listlis stores the titles, Markdown bodies, hierarchy, dates, completion records, styles, saved views, Reader state, preferences, shares, collaborators, and attachments that make up your account. Text history keeps limited earlier title and body versions so you can recover an edit. Public links, email intake addresses, inbound and outbound webhooks, API keys, connected apps, and push notifications also require identifiers, permissions, delivery details, and security metadata.

Archive captures can include a source URL, page title, readable page or selected text, your note, images, byline, publication date, and an MHTML, HTML, or PDF source copy. Capturing a public URL does not send your browser cookies or site credentials to Listlis.

Service, safety, and support data

Content-free events help operate the service. Depending on the event, they can include an account identifier, feature or route name, outcome code, timestamps, counts, latency, a daily keyed fingerprint of an IP address, and basic client information. Listlis also keeps transactional email status, abuse-suppression records, support messages, and public issue reports. Support content is used to answer the request and diagnose the reported problem.

Website and browser data

The public website uses Google Analytics. Google can receive page, referral, device, browser, network, approximate-location, and interaction data under the site's analytics configuration. The app stores interface preferences and recoverable writing drafts in your browser. A push subscription includes an endpoint and encryption keys issued by your browser's push service.

Listlis Archive for Chrome

The extension reads a page only when you choose Save, use its shortcut, or ask it to save a selection. It sends the chosen capture data over HTTPS to your Listlis account. Chrome local storage holds the connected account, OAuth refresh token, destination, and appearance preferences; the shorter-lived access token uses session storage.

A capture waiting for upload is kept in the extension's IndexedDB storage. The queue is capped at 100 items or 100 MiB. A successful upload removes the queued page data. Failed or paused captures remain until they succeed or you discard them. A small recent-save receipt remains for the extension's Open, Move, and Add note actions. The extension also keeps up to 20 content-free failure records for a reliability report.

Listlis Archive's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

How Listlis uses data

  • Provide, synchronize, search, export, recover, and secure your outline.
  • Run the features you choose, including sharing, capture, reminders, and integrations.
  • Authenticate you, enforce permissions and service limits, and prevent abuse.
  • Deliver transactional email, push notifications, and user-configured webhooks.
  • Measure reliability and public-site use, answer support, and improve the product.
  • Meet legal obligations and protect users, Listlis, and the public.

Listlis does not sell personal data, run ads, or use your outline to train an AI model.

Search and Cloudflare AI

Listlis runs on Cloudflare. Account data can pass through Cloudflare Workers and be stored in Durable Objects, D1, and R2. To provide semantic search, Listlis sends node titles, bodies, and account and node identifiers to Cloudflare AI Search. AI Search keeps a search copy in Cloudflare R2 and Vectorize and uses a Cloudflare Workers AI embedding model. The app disables AI Search response caching. Search results are checked against the live tree before Listlis returns them.

Cloudflare states that it does not use Workers AI customer content to train models without explicit consent or share that content with other Cloudflare customers. See Cloudflare's Workers AI data-use documentation.

Connected AI clients, including ChatGPT

Connecting an AI client is optional. The client redirects you to Listlis, where the consent screen names the permissions requested. Read permission covers your account's outline and derived views; write permission covers creating, editing, moving, and deleting outline content. Separate permissions cover sharing and REST-key metadata. These permissions are account-wide within their stated scope, even if your prompt names one branch.

When you invoke a Listlis tool in ChatGPT or another client, that client sends Listlis the selected tool, its arguments, and an OAuth credential. Listlis returns the requested content or operation result to that client. Listlis tools do not request the rest of your conversation, but information you include in tool arguments reaches Listlis. Once Listlis returns data to the client, that client's terms and privacy policy govern its handling.

You can disconnect one grant in the app's Connected Apps panel. Its access stops on the next authenticated request, and its refresh tokens are deleted. Other clients and separately issued API keys remain connected until you revoke them. Listlis REST API keys last no more than 24 hours.

When data goes to someone else

Listlis discloses data to these categories of recipients:

  • Cloudflare for hosting, storage, security, logs, search, and AI embeddings.
  • SMTP2GO to deliver verification, reset, invite, and other service email.
  • Google Analytics to measure use of the public website.
  • Browser push services to deliver reminders on devices where you enable them.
  • People and destinations you choose, such as anyone with a public link, invited collaborators, connected AI clients, inbound-email senders, and outbound webhook endpoints. A public link is a bearer capability: anyone who has it can open the shared snapshot.
  • Authorities or affected parties when disclosure is required by law or reasonably needed to prevent fraud, abuse, or harm or to protect legal rights.

Retention and deletion

  • Live account data remains while the account is active. Outline data remains until you delete it or close the account through support.
  • Deleted subtrees stay in Trash for 30 days so you can restore them. The hourly purge then removes their nodes, text history, Reader copies, attachments, capture sources, shares, and related records. Search stops returning a deleted node immediately. Removal from the separate search index is queued and can lag after deletion.
  • Text recovery keeps up to 25 recent revisions per node and 500 per account. These copies disappear when the related subtree is hard-deleted.
  • Cloudflare Durable Object point-in-time recovery keeps database history for about 30 days. A cold copy of the former tree database, frozen on July 17, 2026, remains for recovery verification. The product does not read it, and it has no automatic expiry yet.
  • Browser sessions expire after 30 days without use. Password-reset links expire after one hour and email-verification links after 24 hours. MCP refresh-token families expire after 30 days without use. MCP access tokens last 30 days; API access tokens last 15 minutes.
  • Active OAuth grants remain until disconnected. API-key rows and registered OAuth client metadata do not currently have a separate automatic deletion date. Expired or revoked key rows can remain as security records.
  • Outbound-webhook delivery records are removed after 30 days. Transactional email records are capped at 50 per account and removed after 90 days; abuse-suppression records can remain longer so blocked delivery is not retried.
  • Security and operations events are kept for 30 days; product, capture, and extension reliability events for 120 days; public-report records for 90 days; and closed attention cases for 180 days.
  • Cloudflare platform logs and Google Analytics data follow their configured provider retention. Listlis does not currently publish a shorter source-controlled period for those copies.

Your controls

The app lets you edit and delete content, restore items during the Trash window, revoke shares and webhooks, remove push subscriptions, disconnect apps, and revoke API keys. You can export the live outline as Markdown or OPML. That export includes live titles, bodies, and structure; it does not include attachments, deleted items, edit history, credentials, shares, or analytics data.

Account closure is handled through support and is not yet self-service. Email [email protected] from your account address. Listlis will verify the request and tell you the scope and timing before taking action. You can also ask about access, correction, deletion, or another privacy right that applies where you live.

Security

Listlis uses HTTPS, scoped account access, hashed passwords and bearer credentials, short-lived REST keys, and explicit OAuth consent. No online service can promise absolute security. Keep your password, public links, ingestion addresses, webhook secrets, and API keys private. Contact support if you believe your account or a capability has been exposed.

Changes and contact

This policy will be updated when the product or its data practices materially change. The date above shows the latest version. Questions and privacy requests can go to [email protected]. Product help is available on the support page.