Privacy Policy
What LisTARDIS handles, why it is needed, where it may go, and what you can control.
Last updated: September 9, 2026
1. About This Policy
This policy applies to the LisTARDIS web app, its account features, and related services on LisTARDIS domains, and the Google Keep to LisTARDIS Chrome extension. In this policy, “LisTARDIS,” “we,” “us,” and “our” mean the service and its operator.
Privacy questions can go straight to privacy@listardis.com.
2. Information LisTARDIS Handles
The details depend on which features you use:
- Account information: your email address, display name, sign-in details, and active sessions.
- Your workspace: outlines, notes, files, images, settings, metadata, archives, backups, Trash, and recovery history.
- Features you choose: Google content, AI conversations, dictation, connected-app activity, and shared AI-thread links.
- Community and support: Forum profiles and contributions, direct messages, support requests, replies, and attachments.
- Technical information: request times, IP address, browser or device details, security signals, and error information processed by LisTARDIS and its service providers.
LisTARDIS also keeps working data in your browser so the app stays fast and can recover from brief connection problems. Clearing browser data removes those local copies; it does not delete the workspace stored in your LisTARDIS account.
3. How We Use Information
We use information to:
- Run, synchronize, back up, restore, and secure your LisTARDIS workspace.
- Perform the Google, AI, dictation, sharing, and connected-app actions you request.
- Operate the Forum, direct messages, and support.
- Prevent abuse, diagnose problems, maintain reliability, and meet legal obligations.
We use personal information because it is needed to provide LisTARDIS, because you chose an optional connection or action, because it helps us keep the service secure and reliable, or because the law requires it.
4. Service Providers and International Processing
LisTARDIS relies on a small set of providers to do practical jobs:
- Supabase: accounts, authentication, databases, file storage, synchronization, backups, and server functions.
- Vercel: web hosting and delivery of the app and public shared-thread pages.
- Cloudflare: Turnstile bot protection around public account actions.
- Resend: account and support email delivery.
- Grafana Cloud: operational metrics, logs, synthetic checks, and alerts used to keep the service healthy and investigate problems.
- OpenAI: dictation, AI requests when you select OpenAI, and bounded operational assistance used to review service health.
- Google and other AI providers: for the sign-in method, connection, model, or action you choose, as explained below.
Core providers process information to provide their part of LisTARDIS, protect the service, or comply with law. Providers you choose for Google, AI, or embedded content also apply their own terms and data practices.
LisTARDIS monitors service health using technical information and aggregate trends. Routine monitoring does not inspect private workspace content. Limited account or log details may be reviewed only when needed for support, account administration, reliability, security, abuse investigation, or legal requirements. Identifying details from those reviews are not copied into long-term operational records.
Some providers operate internationally, so information may be processed outside your country. LisTARDIS uses established providers and the contractual and security safeguards available through their services to protect information wherever it is handled.
We do not sell personal information, share it with data brokers, use it for targeted advertising, or run advertising trackers. Outside the providers and features described above, we disclose information only to protect LisTARDIS or its users, investigate abuse, or comply with a valid legal request.
5. Google
You may use Google to sign in, connect Google workspace features, or both. Google sign-in provides the basic account details needed to authenticate you. If you connect Calendar, Tasks, or Docs, LisTARDIS requests permission to:
- Use Google’s file picker and work with Google Docs you select or create through LisTARDIS.
- Read your Calendar list and read, create, update, or delete events for synchronization.
- Read, create, update, organize, or delete Google Tasks for synchronization.
LisTARDIS does not receive general access to every file in your Drive. Calendar and Tasks may synchronize automatically. Google Docs does not: LisTARDIS reads or updates a selected document only when you choose Pull or Push.
You can disconnect Google in Settings. That stops future access but does not delete information already copied into LisTARDIS or Google; you control those copies separately.
LisTARDIS’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data is not used to train generalized or non-personalized AI models. Human access is limited to support you request, security or abuse investigation, legal requirements, or information that has been aggregated and anonymized.
6. Google Keep Extension
- Your notes: the extension reads the Keep notes you choose, including text, checklists, images and formatting. They are saved in your LisTARDIS account using the providers described above.
- Your Google account: the email shown in Keep may be included in the return link so it opens the correct account. The extension does not read your Google password or sign-in credentials.
- In your browser: the extension finds your Keep and LisTARDIS tabs to transfer notes. Temporary import data clears when the browser session ends; copied notes may remain in your clipboard history, depending on your device settings.
- Your control: you choose whether to archive originals after saving; they remain recoverable in Keep. Removing the extension does not delete saved notes. You control your copies in Keep and LisTARDIS separately.
7. AI, Dictation, and Connected Apps
- AI: when you start an AI request, LisTARDIS sends your prompt, relevant conversation history, and any outline context gathered for that request to the provider and model you chose. Supported providers currently include OpenAI, Anthropic, Google Gemini, and xAI. Your provider’s own terms and data practices also apply.
- Provider keys: API keys you save are encrypted before storage, briefly decrypted to make requests you start, and never displayed in full again. Usage is billed through the provider account that owns the key.
- Dictation: recorded audio is sent through LisTARDIS to OpenAI for transcription. A failed or unfinished recording may remain temporarily in your browser so you can retry or discard it.
- MCP and connected AI apps: a connection can read or write LisTARDIS information only within the permissions you configure. Connections and optional tokens can be reviewed and revoked in Settings.
- AI-thread sharing: a shared thread link is unlisted, not private. Anyone with the link can read the shared conversation until you revoke it.
LisTARDIS does not use your content to train a generalized AI model. AI and transcription providers process requests under their own terms, account settings, and retention practices.
8. Public, Private, and Embedded Content
- Forum profiles, posts, replies, and reactions are public.
- Direct messages are visible to their participants.
- Support requests, replies, and attachments are available to you and LisTARDIS Support; email delivery is handled through Resend.
- External images, links, maps, videos, audio, and other embeds may contact the provider that hosts them. Examples include YouTube, Loom, Figma, Miro, Google Maps, Spotify, SoundCloud, and Apple Podcasts. That provider may receive your IP address, browser details, and information covered by its own policy.
Please do not publish personal information or content in the Forum that you do not want others to see. Public does, rather stubbornly, mean public.
9. Retention and Deletion
Your account information and private workspace remain while your account is active. You can delete individual content, remove integrations and provider keys, revoke shared links and connected apps, export your data, or delete the account from Settings.
Items in Trash and automatic recovery history remain available for up to 30 days. You can permanently delete Trash sooner, and older recovery information is removed as the recovery window moves forward.
Deleting your account permanently removes your private LisTARDIS workspace, including its stored content, files, settings, integrations, backups, and recovery history. Public forum contributions, direct messages retained for other participants, and support correspondence may remain as part of community conversations, recipient records, support operations, security, or dispute resolution. You may contact help@listardis.com to request review or deletion of retained personal information. Deleting your account also permanently deletes everything in Trash; the 30-day recovery period applies only while your account remains active.
LisTARDIS keeps technical and support records only as long as they are needed for security, fraud prevention, troubleshooting, legal compliance, or resolving a dispute. Providers may keep limited records according to their own retention rules and legal obligations.
10. Your Choices and Rights
You can use LisTARDIS Settings to:
- Export or back up your workspace.
- Delete content, empty Trash, or delete your account.
- Disconnect Google, revoke connected apps, delete connector tokens, remove AI provider keys, and revoke shared AI-thread links.
You can ask to see, correct, export, or delete personal information LisTARDIS holds about you, or ask us to stop using it in a particular way. Email privacy@listardis.com and we will work with you to handle the request. We may first verify that the account or information is yours so we do not expose or change someone else’s data.
11. Security
LisTARDIS is built around modern, layered security practices. Information is protected through encrypted connections, authenticated access, account-scoped authorization, and encrypted storage for Google credentials and AI provider keys. These safeguards are actively maintained, monitored, and strengthened as security threats and attack methods become more sophisticated.
12. Children
LisTARDIS is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has used LisTARDIS, contact privacy@listardis.com so we can investigate and take appropriate action.
13. Changes and Contact
When LisTARDIS changes in a way that materially affects how personal information is handled, we will update this policy, show the latest revision date at the top, and explain the change in the app, by email, or through another clear notice.
Privacy questions: privacy@listardis.com
Legal notices: legal@listardis.com
Copyright 2026 LisTARDIS. All rights reserved.