Privacy Policy
What listai.tools collects, why it collects it, who processes it, and how to get it changed or deleted.
Last updated: 30 August 2026.
This policy covers everything at listai.tools: the site, the dashboard, the email we send you and the MCP endpoint. The controller responsible for it all, and the address to write to, are in section 10.
1. What we collect
What you give us. Your email address and password (stored hashed, never in the clear) or, if you sign in by magic link, just the address. A display name and an avatar if you set one. The content of anything you submit: listings, logos, screenshots, reviews, claims, guest posts, report messages, and whatever you write to us in an email.
What a purchase creates. Payments run through Stripe. Stripe collects and holds the card details; we never receive them. What comes back to us and is stored is a Stripe customer and session reference, the amount, the currency, the status of the order, and any refund or dispute against it. Billing address and tax information, where required, are held by Stripe.
What is public by design. A published listing, its content and images, your display name and avatar where they appear beside a listing or a review, upvotes, reviews and leaderboard positions. Treat everything in a listing as published to the world, including to search engines and to AI crawlers.
What we collect automatically. Server logs (IP address, user agent, the URL requested, timestamps, error traces) kept for security and debugging. A session cookie once you sign in. Aggregate analytics — page views, referrers, approximate country, device class — through Google Analytics 4. Counts that feed rankings: listing views, upvotes, and reads of our MCP endpoint. Rate limiting keeps short-lived counters keyed to an IP address.
What we fetch about a submitted tool. When a listing is submitted we visit the URL to take a screenshot and read publicly available details about the product. That is a request to a public website, not a collection of your personal data, but it is worth knowing it happens.
We do not knowingly collect special-category data, and you should not put any into a listing or a review.
2. Why we use it, and on what legal basis
- Running your account and publishing your listings — performance of the contract in our Terms of Service (Art. 6(1)(b) GDPR).
- Taking payment, issuing receipts, handling refunds and disputes — contract, and our legal obligation to keep accounting records (Art. 6(1)(b) and (c)).
- Service email — sign-in links, receipts, review outcomes, badge warnings, expiry notices: contract. These are not marketing and cannot be switched off while you hold a listing or an account.
- Newsletter and product announcements — your consent, withdrawable at any time from the unsubscribe link in every such email (Art. 6(1)(a)).
- Moderation, anti-fraud, anti-manipulation and security — our legitimate interest in a directory that is not gamed and a service that is not abused (Art. 6(1)(f)).
- Analytics and improving the site — your consent where local law requires it for the cookies involved (the EEA, the UK and Switzerland, where the tag stays denied until you accept), and our legitimate interest in aggregate measurement everywhere else (Art. 6(1)(a) and (f)).
- Defending or bringing legal claims — legitimate interest (Art. 6(1)(f)).
We do not sell personal data, we do not share it with data brokers, and we do not use it to train models.
3. Cookies, and the choice you get
We use a small number of cookies and similar local storage. The session cookie that keeps you signed in and the cookies that protect forms from abuse are strictly necessary and cannot be turned off without breaking the site. Analytics cookies measure traffic in aggregate. Your browser can block or clear any of them; blocking the necessary ones means you cannot stay signed in.
Analytics runs under Google Consent Mode. In the EEA, the UK and Switzerland it starts denied and stays that way until you accept on the cookie banner — nothing is stored on your device for analytics before that. Elsewhere it starts granted and Essential only on the banner turns it off. Either way the choice is kept on your own device, and “Cookie settings” in the footer takes it back at any time. Advertising signals are denied for everyone, always.
We set no advertising or cross-site tracking cookies. Sponsor slots on the rails are plain links and images served by us — they do not profile you.
4. Who processes it for us
We use a small set of providers, each bound by a data processing agreement and each given only what its job needs:
- Hosting and database — a virtual server in the EU, where the application and its Postgres database run.
- Stripe — payments, refunds and disputes.
- Resend or Amazon SES — sending transactional and newsletter email.
- Object storage (S3-compatible) — logos, screenshots and uploaded images.
- Google Analytics 4 — aggregate traffic measurement.
- Screenshot and page-reading services — capturing a listing’s screenshot and reading its public page.
- Telegram — an internal operations channel that receives notifications about submissions and orders. It carries listing details and, where relevant, the submitter’s email.
Beyond those, we disclose data only where the law requires it, where it is necessary to investigate abuse or fraud, or where a business transfer would move the Service to a new operator — in which case this policy travels with it and you will be told.
5. Transfers outside the EEA
Some of those providers are established in the United States or process data there. Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the provider is certified under it. Ask us and we will tell you which mechanism covers which provider.
6. How long we keep it
- Account data — while the account exists, then deleted or anonymised within 30 days of closure.
- Published listings — for as long as they are published. A deleted listing is removed from the site; copies may persist in search-engine caches and web archives we do not control.
- Orders and invoices — five years from the end of the accounting year, because Polish tax law requires it. This survives account deletion.
- Server logs — up to 90 days.
- Email records and support threads — up to 24 months.
- Moderation records of a ban or a fraud finding — as long as needed to keep the decision enforceable.
7. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to you in a portable format. Where we rely on consent you can withdraw it at any time, which does not affect what was lawful before. Where we rely on legitimate interest you can object, and we will stop unless we have grounds that override yours.
Write to [email protected]. We answer within 30 days. We may ask you to confirm you control the account’s email address before acting — not to obstruct, but because handing an account’s data to the wrong person is the worse failure.
If you think we have got this wrong you can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, or to the authority where you live.
8. Security
Traffic is served over HTTPS. Passwords are stored hashed. Access to the server and the database is restricted to the operator. Payment card data never reaches our systems. No service is perfectly secure, and we do not claim otherwise; if a breach affects your data and is likely to put you at risk, we will tell you and the supervisory authority as the GDPR requires.
9. Children
The Service is not for anyone under 16. We do not knowingly collect their data, and we delete an account we learn belongs to a child.
10. Who is responsible
The controller of personal data collected through listai.tools is Piotr Boroń, conducting unregistered business activity under Article 5 of the Polish Entrepreneurs’ Law Act of 6 March 2018, al. Solidarności 68/121, 00-240 Warsaw, Poland. Contact: [email protected] — the same address as every request in section 7.
The Service is operated from Poland and falls under the General Data Protection Regulation (GDPR). There is no data protection officer; the operator handles these requests directly.
11. Changes
We may update this policy. The date at the top says when it last changed, and material changes are announced by email or on the site before they take effect.