Version 1, published 2026-10-04
Privacy policy
This policy says what ListWarden stores about you and your assets, why, for how long, and who else sees it. It is published by Letail, LLC, 2969 Riverside Blvd, Sacramento, CA 95818, United States ("ListWarden", "we"), which decides how this data is used. You accept it together with the terms of service; the version and date above identify the text you accepted.
1. What we store
- Account data: your email address, a hash of your password (never the password itself), your plan and billing state, the time you accepted each version of these documents, your optional contact phone, your alert destinations, and the hosted mailbox and DMARC addresses we create for you. API keys are stored only as hashes; a verification or reset link is kept in the mail queue until it is delivered, and only its hash after that.
- Assets: the IPv4 addresses and domains you add, with their labels.
- Verdicts and raw evidence: every check result for each asset, including the raw evidence as the authority returned it, and the history of changes.
- Cases: the evidence assembled for each removal request, what was submitted, and the authority's response.
- Complaint mail: abuse mail and feedback-loop reports that reach your hosted mailbox or your abuse domain, stored as received, including recipient addresses where the report contains them.
- DMARC reports: aggregate and forensic reports sent to your DMARC address, stored as received, with the sending sources derived from them.
- Encrypted mailbox credentials and dashboard tokens: mailbox credentials you give us, tokens for dashboards you delegate to us, and data-access URLs. These are encrypted at rest with AES-256-GCM, and the key is kept apart from the database.
- Cookies: one first-party session cookie that keeps you signed in, and, during a sign-in with Google or GitHub, a short-lived cookie that remembers where to return you. No tracking or advertising cookies.
2. Why we store it
Only to run the service you signed up for: to check your assets, alert you, prepare and submit removal requests under the standing authority in the terms, bill you, and keep the service secure. We do not sell your data or use it for advertising.
3. How long we keep it
History (verdicts and raw evidence, cases, complaint mail and DMARC reports) is kept for your plan's retention period:
- Free: 30 days.
- Paid plans: 1 year.
- Quote: the period negotiated in your agreement.
Older history is deleted at the next retention run. Moving to a plan with a shorter retention period deletes history older than the new period at the next run. Account data is kept while the account exists; after an account is closed, its account data and history are deleted within 30 days, and copies in our nightly backups are gone within a further 30 days.
4. Who else sees it
- Authorities you ask us to contact. A removal request carries what the authority needs: the asset, the evidence, and the requester address used for the case.
- Service providers who process data for us under contract: Cloudflare (sending and receiving mail), Amazon Web Services (fallback mail sending), Stripe (card payments; we never see or store your card number), and DigitalOcean (hosting the service and its database, in the United States).
- Authorities of law, when the law requires it.
5. Security
Passwords are hashed with scrypt, API keys and emailed links are kept as hashes, and mailbox credentials and dashboard tokens are encrypted, as section 1 describes. Connections to the service use TLS.
6. Your choices and rights
You can see your account data and assets in the dashboard, and delete assets there. To ask for a copy of your data, a correction, or deletion of your account, write to [email protected]. A data-processing addendum is available on request.
7. Changes to this policy
A new version of this policy carries a new version number and date, and you are asked to accept it at your next sign-in before using the service further.