Privacy Policy

Last updated: September 22, 2026

This policy describes the personal data Listelo processes, the providers we rely on, how long we keep data, and the rights you can exercise over your information.

1. Who we are

Listelo (“we”, “us”) provides an AI-assisted product listing workspace. This policy explains what personal data we process, why, and the choices you have. You can reach us at listelodestek@gmail.com.

2. What we collect

Account data: your email address and user ID, managed through our authentication provider. If you sign in with Google, Google shares your email address with us.

Product data you provide: the product photos you upload, the product facts you type or confirm (for example brand, material, size, condition), and the listing text you generate, edit or save.

Usage and billing data: your plan, credit balance, credit transactions and payment records (amount, currency, status, invoice number). Card details are handled entirely by our payment provider and never reach us.

Support data: messages you send through the support and feedback forms in Settings.

Anti-abuse data: to protect the free allowance we store a salted, irreversible hash derived from a coarse network prefix (for example an IPv4 /24 range). We do not store your raw IP address.

3. How we use your data

To provide the Service: analyse your photos, generate listings, store the listings you save, and let you edit, copy and export them.

To apply your plan limits and credit balance, and to process subscription and credit-pack payments.

To answer support requests and product feedback.

To detect and prevent abuse of the free allowance, rate limiting and fraudulent use of the Service.

To keep the Service secure and to diagnose technical errors.

4. Product photos

Photos are resized and compressed in your browser before they are sent, then transmitted to our AI provider so the listing can be generated.

Listelo does not store your photos. When you save a listing, we store the listing text and, optionally, the file name of the photos used — not the images themselves. There is no image storage bucket in your account.

Please do not upload photos that contain sensitive personal information (for example identity documents, faces of third parties, or documents showing addresses).

5. Service providers

We use a small number of processors, each of which handles data only as needed to deliver their part of the Service:

Supabase — database, authentication and access control for your account, listings, credits and settings.

DeepSeek — the AI model that analyses your photos and generates listing content. The prompts and images you submit are sent to this provider for processing.

Paddle (Paddle.com Market Limited) — payment processing and merchant of record. Billing data and invoices are handled by Paddle.

Resend — delivery of support and feedback emails to our team.

Vercel / Cloudflare — hosting and content delivery for the application.

6. Payments

We do not receive or store your card number or full payment details. Checkout is completed with Paddle, which processes the payment, handles applicable taxes and issues your invoice. We receive only the information needed to activate your plan and credits, such as the plan, amount, currency, status and invoice number.

7. Retention

Your saved Library keeps the newest 100 listings; older entries are removed automatically as new ones are saved.

Credit and payment records are retained while your account exists so your balance and invoices stay correct.

When you delete your account (Settings → Danger Zone), your account and the data linked to it — settings, listings, credit records, feedback and support history — are deleted through cascading deletion.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to receive a portable copy.

You can export your saved listings at any time from the Library as Etsy CSV, Shopify CSV, Amazon flat-file, generic CSV, JSON or TXT.

You can delete your account yourself from Settings → Danger Zone. For any other request, contact us at listelodestek@gmail.com and we will respond within the period required by applicable law.

9. Cookies and local storage

We do not use advertising trackers. The application stores a small amount of information in your browser’s local storage — your interface language, your dark/light theme preference and a flag that records that you have seen the onboarding tour — plus the session data needed to keep you signed in.

10. Security

Data is transmitted over encrypted connections. Database access is governed by row-level security so each account can only read and write its own rows, and administrative database access is restricted to server-side operations.

Only salted, irreversible hashes of coarse network signals are stored for abuse prevention, never raw IP addresses.

No system is perfectly secure. Please use a strong, unique password and contact us immediately if you believe your account has been compromised.

11. Children

The Service is intended for business users and is not directed to children. You must be at least 18 years old, or the age of majority where you live, to create an account.

12. Changes to this policy

We may update this policy. Material changes will be reflected by a new “last updated” date at the top of this page. If a change significantly affects how we use your data, we will make that clear in the product or by email.

Questions about this document? Contact us at listelodestek@gmail.com.