Skip to content
listlis

Privacy

What we keep, and why

Last updated July 2026

listlis is a place to keep your own writing. We store what we need to show you your tree and nothing we do not. This page is written to be read, not to be survived.

Your account

Sign-in is ours, not a third party's. We hold your email address, a scrypt hash of your password (never the password), and — if you add one — the public half of a passkey. A sign-in leaves an opaque session cookie in your browser, and nothing about you goes to an outside identity provider.

Your outline

The titles, Markdown bodies, and attachments you create are stored so we can render them back to you across your devices. Every record is scoped to your account; we do not read your notes to train anything or sell them.

Search and AI clients

So that search can find a thought you half remember, your titles and bodies are indexed by Cloudflare's search service running on our own account — the same infrastructure the rest of listlis runs on, not an outside AI vendor, and not training data. If you connect an AI assistant yourself, over MCP or an API key you minted, then that assistant can read and write the parts of your tree you point it at, for as long as the connection or key lives. Nothing is connected unless you connect it, and revoking the key ends it.

Sharing and inbound mail

A public link or an inbound email or webhook address exists only after you create it, and stops working the moment you revoke or rotate it. Public pages are served as a snapshot and asked not to be indexed. Mail and webhook payloads you send to a node are stored as part of your tree like anything else.

Deletion

Delete a node and its subtree goes with it, into a trash you can restore from for thirty days; after that it is purged for good. Ask us to close your account and we remove your data.

Contact

Questions about your data can go to [email protected].

← Back to listlis