We never receive your policies.
Most privacy policies start by listing what a vendor collects. Ours starts with what it cannot: Listor stores a title and a URL, so your policy contents never reach our servers in the first place. Everything below covers the small amount that does.
The whole list.
Not a representative sample. This is everything Listor stores about you and your organisation. Last updated 7 August 2026.
- Account and identity
- Your name, email address, and organisation membership. Authentication is handled by Clerk; we store the Clerk user ID alongside the name and email it returns.
- Document references
- The title, URL, and optional description of each document you add, plus who created it and which groups or people it targets. We do not fetch, copy, or store the document contents.
- Attestation records
- For each attestation: who attested, which document, the timestamp, the renewal window it belongs to, and the IP address and user-agent of the request.
- Click records
- When someone opens a document link from Listor we record the user, document, timestamp, IP address, and user-agent. This is what lets an administrator distinguish "opened" from "attested".
- Administrative actions
- Document, group, and membership changes made by administrators, with the actor, timestamp, IP address, and user-agent. This is the audit log.
- Site analytics
- Our marketing site uses a self-hosted Plausible instance. It sets no cookies, collects no personal data, and does not track visitors across sites.
One purpose. No resale.
Everything above exists to run the service you bought: showing people their reading list, proving they confirmed it, and reminding them when it is due again.
We do not sell personal data, share it with advertisers, or use it to train machine learning models. We do not build a profile of you across organisations.
Where you are the customer, our lawful basis is performance of our contract with you. Where you are an employee of a customer, the organisation is the data controller and Listor is the processor acting on its instructions; your access and deletion requests should go to your employer first, and we will support them in answering you.
IP addresses and user-agents are collected because an attestation record without them is weak evidence. That is a legitimate interest of the customer operating the account, and it is disclosed to employees at the point of attestation.
Who else touches it.
Production runs in the EU (Frankfurt). Listor data stays in-region. Current sub-processors, with a DPA in place for each:
- Clerk
- Authentication and identity. Processes name, email, and session data.
- Neon
- Managed Postgres. Stores everything listed above. EU region.
- Inngest
- Background jobs, including renewal sweeps and reminder scheduling.
- Resend
- Transactional email. Processes recipient name and email address.
- GlitchTip
- Error tracking. May incidentally receive a user ID or request path in a stack trace.
How long we keep it.
Audit-log entries are retained for 90 days on Free, 2 years on Pro, and for the life of the account on Business.
Account and document records are kept while your organisation has an active account. When you close an account we delete its data permanently: no soft-delete, no shadow copy, no restoration from us afterwards. Backups roll off within 30 days.
Export your audit log before you close the account. Once it is gone we cannot produce it for an auditor, and neither can you.
Access, correction, erasure.
Under UK and EU data protection law you can ask for a copy of your data, correct it, delete it, restrict how it is used, or object to processing. Email [email protected].
We respond within 30 days. If you are an employee of a Listor customer, we will route your request to your organisation's administrator, because they control the account and we act on their instructions.
If you are unhappy with how we have handled a request you can complain to your national supervisory authority. In the UK that is the Information Commissioner's Office.
When this changes.
We will email account administrators before any change that materially affects what we collect or who processes it. This policy was last updated 7 August 2026.
Listor is operated by Outset Works. Privacy questions: [email protected]. Security reports: [email protected].