Privacy Policy
Effective date: June 24, 2026 · Last updated: July 15, 2026
1. Introduction
ListOptimize ("we," "our," or "us") operates the website at listoptimize.online — an AI-powered tool that helps Etsy and Shopify sellers generate product titles, descriptions, tags, alt text, social content, and listing audits.
This Privacy Policy explains what personal information we collect, how we use it, and what your rights are. If you have questions, contact us at listoptimize@gmail.com.
2. Information We Collect
Account Information
When you create an account, we collect:
- Full name — entered during sign-up
- Email address — used to identify your account and for transactional communications (e.g., password reset)
- Password — hashed and stored securely by Supabase; we never see your plaintext password
Content You Submit
When you use our generation tools, you submit content to receive AI-generated output. This includes:
- Product names, categories, and descriptions (used in the Listing Generator, Alt Text Generator, and Bulk Generator)
- Existing listing text you paste for auditing (used in the Listing Checker)
- Customer reviews you paste for analysis (used in the Reviews Analyzer)
- Shop and content preferences (used in the Social & Shop Content tool)
- A product type you want keywords for (used in Keyword Research)
- A snapshot of your shop — name, listing titles, tags, price range, shipping terms (used in the Shop Audit)
- Your shop name and the search queries you want to track (used in the AI Visibility Checker)
- A product photo you upload for feedback (used in Photo Check)
We store both your inputs and the AI-generated outputs in your account history so you can access them later. Uploaded product photos are stored separately, in Supabase Storage rather than the database — see §5.
Assistant Conversations
If you use the on-site assistant, the messages you type are sent to our AI provider to generate a reply. Assistant conversations are not saved to your account and are not stored in our database — they exist only for the duration of the page session.
Usage Data
We track how many AI generations you have used in the current billing month, and how many times you have used the daily-limited analysis tools today, to enforce plan limits (Free plan: 10 generations/month). We do not track your browsing behavior, pages visited, or time on site, and we do not use analytics or advertising trackers.
IP Address
We read your IP address from the request in two situations: when you send a message to the on-site assistant, and when a free trial is granted on your account. In both cases it is used only to enforce a rate limit or flag an unusual pattern — for example, an unusually high number of trials starting from the same IP in a short window — never to identify or track you personally.
The IP is stored in our database as part of a simple rate-limit counter (a key such as chat:<ip address>, a count, and a timestamp), not only in server memory. Each counter's own limit window is short (a few minutes for the assistant, 24 hours for the trial signal), but the counter row itself is not automatically deleted once created, so it persists in our database rather than expiring on its own. It is never linked to your account or profile, and it is never used for analytics, profiling, or tracking.
Session Data
We use authentication cookies (set by Supabase) to keep you signed in across visits. These are strictly functional — they contain only your encrypted session token and no tracking information.
3. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Create and manage your account | Email, name |
| Deliver AI-generated content | Your product inputs, listing text, reviews, or photo |
| Enforce plan usage limits | Monthly generation count linked to your account |
| Display your history | Stored inputs and outputs |
| Allow you to delete your content | User ID linked to each record |
| Answer your questions in the on-site assistant | The messages you type (not stored afterwards) |
| Rate-limit the assistant and flag unusual trial activity | IP address, stored as a rate-limit counter (see §2) |
| Send your weekly AI Visibility report (Pro add-on) | Email address, shop name, tracked keywords, scan results |
| Respond to support requests | Email, account details |
We do not use your data for advertising, sell it to third parties, or use it to train AI models that we own.
4. Third-Party Services
We send data to the following external services to operate the product. Each service receives only what is necessary for its function.
Supabase
Handles all user authentication (sign-up, sign-in, sessions) and stores your account data, generated listings, listing checks, and review analyses in a PostgreSQL database.
Data received: Email, name, hashed password, all stored content tied to your account, usage counters.
Privacy policy: supabase.com/privacy
DeepSeek
Provides the primary large language model behind our Faster generation mode — used by the Listing Generator, Alt Text Generator, Bulk Generator, Social & Shop Content tools, and Keyword Research when Faster mode is selected.
Data received: Your product name, description, category, and any other inputs you provide to those tools. Requests are made server-side — your data is never sent to DeepSeek directly from your browser.
Privacy policy: deepseek.com privacy policy
Groq
Backup provider for Faster generation mode, used automatically only if DeepSeek is unavailable, and one of the two models queried by the AI Visibility Checker.
Data received: Your product name, description, category, and any other inputs you provide to Faster-mode tools. Requests are made server-side — your data is never sent to Groq directly from your browser.
Privacy policy: groq.com/privacy
Anthropic (Claude)
Provides the large language models behind our Standard generation mode, the deep-analysis tools (Listing Checker, Shop Audit), the Reviews Analyzer, Photo Check, the AI Visibility Checker, and the on-site assistant.
Data received: Whatever you submit to those tools — product details, listing text, customer reviews, shop details, a product photo, or the messages you type to the assistant. Requests are made server-side — your data is never sent to Anthropic directly from your browser.
Privacy policy: anthropic.com/privacy
Resend
Sends the weekly AI Visibility report email to Pro subscribers who are tracking keywords, and other transactional email.
Data received: Your email address, and the content of the report (your shop name, tracked keywords, and scan results).
Privacy policy: resend.com/legal/privacy-policy
Vercel
Hosts the ListOptimize application and serves it to your browser.
Data received: Standard web-server request data (such as your IP address and browser user-agent) processed to deliver the site. We do not receive or store this as analytics.
Privacy policy: vercel.com/legal/privacy-policy
5. Data Storage and Security
All data is stored in Supabase's hosted PostgreSQL database, which is encrypted at rest and in transit (TLS/SSL). Our application is hosted on Vercel.
We enforce Row Level Security (RLS) on all database tables, meaning your account data is isolated — only you can read or modify your own listings, checks, and analyses.
API keys for DeepSeek, Groq, Anthropic, Resend, and Supabase are stored as server-side environment variables and are never exposed to your browser.
Product photos uploaded to Photo Check are stored in a private Supabase Storage bucket, scoped to your account, separate from the database tables that hold your other content.
Retention: Your data is stored for as long as your account exists. When you delete a listing from your history, it is permanently removed. If you request full account deletion, all database records associated with your account are deleted via cascading database constraints, and any product photos you uploaded are removed from storage as part of the same deletion process.
6. Cookies and Local Storage
We use one type of cookie only: a session cookie set by Supabase's authentication library to keep you signed in. This cookie:
- Contains only an encrypted session token
- Is required for the app to function (it is not optional)
- Is not used for tracking or advertising
- Is deleted when you sign out
We also store one preference in your browser's localStorage: whether you last chose Standard or Faster generation mode, so the dashboard remembers your choice between visits. It contains no personal information, never leaves your browser, and you can clear it at any time through your browser settings.
We use no other localStorage, sessionStorage, or persistent browser storage, and no advertising, analytics, or tracking cookies of any kind.
7. Your Rights
Regardless of where you live, you have the following rights regarding your data:
- Access: View all your generated content on the History page and your account details on the Settings page.
- Delete: Delete individual listings, listing checks, and review analyses from your history page at any time. Deletion is immediate and permanent.
- Account deletion: Email us at listoptimize@gmail.com and we will delete your account and all associated data within 7 business days.
- Data portability: Copy your generated content from the History page at any time.
- Correction: To update your name or email address, contact us at the email above.
If you are in the European Economic Area (EEA) or the UK, you have additional rights under GDPR/UK GDPR, including the right to lodge a complaint with your local supervisory authority.
If you are in California, you have rights under the CCPA. We do not sell personal information.
8. Children's Privacy
ListOptimize is not intended for children under the age of 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, please contact us at listoptimize@gmail.com and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the service after a change constitutes acceptance of the updated policy.
10. Contact
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: listoptimize@gmail.com
Website: listoptimize.online