We never receive your policies.

Most privacy policies start by listing what a vendor collects. Ours starts with what it cannot: Listor stores a title and a URL, so your policy contents never reach our servers in the first place. Everything below covers the small amount that does.

What we collect

The whole list.

Not a representative sample. This is everything Listor stores about you and your organisation. Last updated 7 August 2026.

Account and identity
Your name, email address, and organisation membership. We store your email address as the sign-in identifier, a hash of your password, and your session records.
Document references
The title, URL, and optional description of each document you add, plus who created it and which groups or people it targets. We do not fetch, copy, or store the document contents.
Attestation records
For each attestation: who attested, which document, the timestamp, the renewal window it belongs to, and the IP address and user-agent of the request.
Click records
When someone opens a document link from Listor we record the user, document, timestamp, IP address, and user-agent. This is what lets an administrator distinguish "opened" from "attested".
Administrative actions
Document, group, and membership changes made by administrators, with the actor, timestamp, IP address, and user-agent. This is the audit log.
Site analytics
Our marketing site uses privacy-preserving analytics. No cookies are set, no personal data is collected, and visitors are not tracked across sites.

What we use it for.

Everything above exists to run the service: showing people their reading list, proving they confirmed it, and reminding them when it is due again. We do not sell personal data, share it with advertisers, or use it to train machine learning models.

Where you are the customer, our lawful basis is performance of our contract with you. Where you are an employee of a customer, your organisation is the data controller and Listor is the processor acting on its instructions, so access and deletion requests should go to your employer first.

IP addresses and user-agents are collected because an attestation record without them is weak evidence, and this is disclosed to employees at the point of attestation.

Sub-processors

Who else touches it.

The database holding everything above is ours, not a third party's. Current sub-processors, with a DPA in place for each:

Resend
Transactional email.
Automattic / Gravatar
Avatar images.
Retention

How long we keep it.

Audit-log entries are retained for 90 days on Free, 2 years on Pro, and for the life of the account on Business.

Account and document records are kept while your organisation has an active account. When you close an account we delete its data permanently: no soft-delete, no shadow copy, no restoration from us afterwards. Backups roll off within 30 days.

Export your audit log before you close the account. Once it is gone we cannot produce it for an auditor, and neither can you.

Your rights

Access, correction, erasure.

Under UK and EU data protection law you can ask for a copy of your data, correct it, delete it, restrict how it is used, or object to processing. Email [email protected].

We respond within 30 days. If you are an employee of a Listor customer, we will route your request to your organisation's administrator, because they control the account and we act on their instructions.

When this changes.

We will email account administrators before any change that materially affects what we collect or who processes it. This policy was last updated 7 August 2026.

Listor is operated by Outset Works. Privacy questions and security reports: [email protected].