Privacy Policy

Last updated: 10 August 2026

This Privacy Policy explains how Listly AI (“we”, “us”, “our”) collects, uses, and protects your personal data when you use our service at listlyaiapp.com. We are subject to the General Data Protection Regulation (GDPR) as we operate from Belgium and serve users in the European Union.

1. Who we are

Listly AI is operated by Brooke Baxter, based in Belgium. We are the data controller for the personal data described in this policy. If you have any questions, contact us at listlyai.contact@gmail.com.

We will update this policy with a registered company name and number once our legal entity is established.

2. What data we collect

Account data: When you sign up, we collect your email address and a hashed password. We never store your password in plain text.

Photos you upload: When you use the listing feature, you upload photos of items. These photos are processed by our AI provider (Anthropic, see Section 5) and stored in our database to power your listing history.

Usage data: We record how many listings you create per day and per hour in order to enforce your plan limits. We store timestamps of API calls for rate limiting purposes.

Listing data: The AI-extracted listing information (brand, condition, descriptions, etc.) is saved to your account so you can access your history and re-list items.

Payment data: If you upgrade to a paid plan, payment is handled directly by Stripe. We do not receive or store your card number. We receive confirmation of your subscription status from Stripe.

Analytics data: We collect information about how people find and use Listly AI: pages viewed, the referring site or campaign that brought you here, approximate location (country or city level, derived from your IP address — we do not store your full IP), device and browser type, and in-app actions such as creating a listing or upgrading a plan. When you are logged in, these events are linked to your account. See Section 6 for how consent works.

Reviews and feedback: If you choose to leave a review or send feedback, we collect the rating you give, any comments you write, and the name you ask us to display. You may optionally give an email address so we can contact you about your review; it is never published. We also store a one-way hashed form of your IP address so we can limit how many reviews a single source can submit per day — this hash cannot be reversed to recover your IP address or identify you. If you are signed in when you submit, the review is linked to your account so we can mark it as coming from a verified user. Leaving a review is entirely optional and the service works the same if you never do.

Browser storage: We use your browser's localStorage and sessionStorage to store your current session state (selected platforms, listing in progress, sidebar preferences). This session state stays on your device and is not transmitted to our servers. Analytics storage is separate and is covered in Section 6.

3. Why we process your data (lawful basis)

To provide the service (contract): Your email, photos, and listing data are processed because they are necessary to deliver the service you signed up for.

Legitimate interests: Usage data (rate limiting, daily counters) is processed to protect the service from abuse and to enforce fair use limits.

Analytics (consent, or legitimate interests): In the EEA, UK and Switzerland we ask for your consent before storing any analytics identifier on your device. You can decline and the service works exactly the same. Where we record product usage against your logged-in account without storing anything on your device, we rely on our legitimate interest in understanding how the product is used so we can improve it. You can object to this at any time — see Section 7.

Reviews (consent, and legitimate interests): We publish a review, together with the display name you chose, only because you asked us to by submitting it — that is your consent, and you can withdraw it at any time by emailing us, after which we remove the review from the site. Separately, we rely on our legitimate interest in preventing spam and abuse to store the hashed form of your IP address described in Section 2.

Legal obligation: We may retain certain records if required by applicable law.

4. How long we keep your data

Your account data and listings are kept for as long as your account is active. If you delete your account, we delete your personal data within 30 days.

Hourly rate-limit log entries are automatically deleted after 25 hours. Daily usage counters are kept for up to 90 days for billing and support purposes.

Reviews and feedback you submit are kept until you ask us to remove them, whether or not we published them. The optional contact email and the hashed IP address are stored alongside the review for the same period. If you delete your account, any review you left while signed in is deleted along with it. A review left without signing in is not connected to an account, so please email us if you would like it removed.

Analytics events are retained by our analytics provider for up to 12 months, after which they are deleted or kept only in aggregated form that cannot identify you.

Stripe retains payment records for its own legal and regulatory purposes, independently of us.

5. Who we share your data with

We do not sell your data. We share data only with the following service providers, who process it on our behalf:

  • Anthropic— your uploaded photos and prompts are sent to Anthropic's Claude API for AI-powered listing extraction. Anthropic may retain inputs and outputs for up to 30 days for safety purposes, after which they are deleted. Anthropic does not use your inputs to train their models. See Anthropic's privacy policy at anthropic.com/privacy.
  • Supabase — our database and file storage provider. Your account data, listing data, and uploaded images are stored on Supabase infrastructure (hosted on AWS in the EU where possible). See supabase.com/privacy.
  • Stripe — payment processing for Pro and Power plan subscriptions. See stripe.com/privacy.
  • Vercel — our hosting provider. Request logs may be retained by Vercel for a limited period. See vercel.com/legal/privacy-policy.
  • PostHog— our product analytics provider. We use PostHog's EU Cloud, so analytics data is stored on servers inside the European Union. PostHog receives the analytics events described in Section 2, plus your user ID and email address when you are logged in. See posthog.com/privacy.

All providers are contractually required to process your data only as instructed by us and to maintain appropriate security measures.

6. Cookies and similar technologies

We use a limited number of cookies and similar technologies, none of which are used for advertising.

Strictly necessary (no consent needed):

  • Authentication cookies set by Supabase, which keep you logged in.
  • A cookie recording whether you are in a region where we must ask for analytics consent, and a record of the choice you made. We cannot apply your choice without recording it.
  • Cookies set by Stripe during checkout, if you choose to subscribe.

Analytics (consent needed in the EEA, UK and Switzerland):

  • PostHog stores an identifier on your device so we can tell whether you are a returning visitor and which channel brought you to us.

If you are in the EEA, UK or Switzerland we ask before setting any analytics storage. If you decline, PostHog runs in a memory-only mode that writes nothing to your device, so we cannot recognize your browser across visits. If you are logged in, we still record product usage against your account as described in Section 3, and you can object to that at any time. If you are outside these regions, analytics storage is enabled by default.

You can change your mind at any time, and it is as easy to withdraw consent as it was to give it: go to Settings → Preferences → Privacy and turn product analytics off. We will then erase the analytics identifier already stored on your device and stop storing new ones. You can also email us and we will process the request on your behalf.

We do not use advertising, cross-site tracking, or fingerprinting technologies of any kind.

7. Your rights under GDPR

If you are in the European Economic Area or UK, you have the following rights:

  • Access: request a copy of the personal data we hold about you
  • Rectification: ask us to correct inaccurate data
  • Erasure: ask us to delete your personal data (“right to be forgotten”)
  • Portability: receive your data in a structured, machine-readable format
  • Restriction: ask us to pause processing of your data in certain circumstances
  • Objection: object to processing based on legitimate interests

If you have left a review, you can withdraw it at any time and we will remove it from the site. You do not need to give a reason, and withdrawal has no effect on your account or your plan.

To exercise any of these rights, email us at listlyai.contact@gmail.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Belgian data protection authority: Autorité de protection des données (APD), gegevensbeschermingsautoriteit.be.

8. Data security

We use industry-standard security measures: HTTPS everywhere, hashed passwords, row-level security on our database (so users can only access their own data), and authentication checks on every API route. No system can be guaranteed perfectly secure, but we take reasonable precautions to protect your data.

9. Children

Listly AI is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. When we make significant changes, we will update the “Last updated” date at the top and notify active users by email where required by law.

11. Contact

For any privacy questions or data requests, email: listlyai.contact@gmail.com