Listto legal
Privacy Policy
Version 2026-08-10-v9 ยท Effective 10 August 2026
About this policy
Vinicius Martins Delgado trading as Listto, ABN 68 820 965 824, is responsible for the personal information described here. Privacy questions and complaints can be sent to admin@listto.com.au.
Account and provider information
Before collecting email or provider account information, Listto processes your date of birth only to determine whether you are 16 or older. Listto does not retain the submitted birth date. It stores only the eligibility result, rule version, method and evaluation time.
Email signup collects your email address, public Full name, unique public username and password-derived security data. Listto does not collect country or gender during signup.
Google or Facebook signup receives a stable provider-specific identifier, email evidence and the name made available through the provider authentication response. The provider-supplied name becomes the initial public Full name and cannot be replaced by browser-supplied data during provider signup. You may edit it later through Profile. Listto does not merge accounts merely because provider and Listto email addresses match.
Email choices and evidence
At signup you may separately choose to receive recipe inspiration, trending recipes and Listto product updates by email up to once a week. This optional choice is off by default and is not required to create or use an account.
When you opt in, Listto records the communication category, the exact prompt version and hash, source and time so the choice can be demonstrated. You can withdraw it at any time in communication settings or through an unsubscribe link. Withdrawal updates the preference and creates a purpose-specific suppression; it does not disable necessary account or security messages.
Service notifications
Shopping-list invitation emails are factual collaboration messages, separate from weekly marketing. They may include the inviter Display Name, list name, permission and a safe link to Listto notifications, but no list items or promotional copy.
You can disable shopping-list invitation email in account settings without removing the in-app notification. Security, verification, recovery and legal messages remain available where necessary to operate and protect the account.
Purposes, disclosure and overseas processing
Listto uses the eligibility result to enforce its 16-plus account rule. Account information is used to create, authenticate, secure, administer and recover accounts, display the public Full name and @username, prevent provider mix-ups and fraud, and provide requested recipe and collaboration features.
Authorised Listto personnel and contracted hosting, security and email providers process only the information needed for their function. Google or Meta receives the authentication request you choose. Resend processes recipient addresses, transactional message content and delivery events in the United States, with Listto sending routed through Tokyo, Japan.
Delivery events, retention and security
Listto may process delivery, bounce, complaint and suppression events to protect sender reputation and prevent unwanted repeat delivery for the affected purpose. Email eligibility is checked again immediately before applicable service or future marketing delivery.
Listto protects credentials and action secrets with hashing, encryption and access controls, uses short-lived verification records and revocable sessions, and retains personal information and consent evidence only as needed for account, security, preference, complaint and legal purposes. No internet service can guarantee absolute security.
Listto protects Admin access with an authenticator-app secret protected at rest and separate one-time recovery-code hashes. Authenticator secrets, QR setup data and recovery codes are not placed in ordinary logs or browser storage.
Shopping list suggestions and activity data
After the feature is enabled, the exact policy versions are approved and you complete the required review, Listto may record append-only shopping activity used for suggestions. This can include adds and duplicate merges, actual purchased or returned changes, removals and renames, recipe imports, and suggestions shown, selected or used to assist an add. Records can include your account identifier, an immutable shopping-list context identifier, a catalog item identifier or version-normalized custom-item identity, a safe item-name snapshot, normalized list-title tokens, the event and source type, source-record and decision/model details, rank, and time.
Listto uses frequency, recency, purchase cadence, day or month timing, normalized list-title context, same-list history and current-item co-occurrence to rank candidates. Shared-list actions contribute only to the acting user's personal history and also to that list's context. Population suggestions use privacy-thresholded aggregation: one person contributes at most one vote per item, catalog items require at least three distinct people and custom items require at least ten. Custom names, list titles, user identifiers and decision contents are not written to recommendation timing or mode metrics.
Raw recommendation events are retained for no more than 730 days, described as 24 months, and are then removed in batches. Actor-item and actor-list-item signal projections are rebuildable from retained events. Listto does not send this activity to an external recommendation service, embedding model, large language model or Python analytics stack.
Account deletion and retained information
A signed-in account owner may permanently delete the account through Account Security after typing the exact confirmation phrase containing the account's @username and completing a fresh code sent to the verified email. Listto immediately disables sign-in, revokes sessions, removes password and provider-login associations, and de-identifies the former email address, Full Name, date of birth, gender, country, phone number, profile biography and avatar.
The username, its reservation and its relationship to the deleted account are retained permanently to prevent reuse, impersonation and confusion in historical records. Public recipes remain available under 'Anonymous'. Authorised administrators may see the protected historical Display Name, @username and deletion date for legal, safety, moderation, security and ownership work; ordinary users cannot. Published reviews retain the historical Display Name with a deleted-account indication but no username or active profile link.
Private recipes, pantry records, private shopping lists and other non-public content stay non-public and become inaccessible through the deleted account. Listto may retain that content and minimal account, legal-acceptance, security, complaint, moderation and deletion evidence where reasonably needed for legal compliance, dispute handling, safety, fraud prevention, service integrity and controlled backup retention.
Account deletion is intended to be irreversible for the ordinary user. A later account using a released email or provider identity is separate and is not reconnected to deleted-account data. The former Display Name may be used by another account because Display Names are not unique.
When account deletion completes, Listto purges recommendation events and derived recommendation signals attributed to that account. Shopping-list rows and other content may still be handled under the separate retention rules above, but they are not retained as that deleted user's personal recommendation history.
Your choices and rights
You may edit your public Full name, request access to or correction of personal information, change communication preferences, unsubscribe, unlink an external provider when another usable method remains, complain about privacy handling or permanently delete the account through Account Security. Username changes are restricted to authorised administrator corrections and retain the previous reservation and audit evidence. Contact admin@listto.com.au for privacy questions or complaints.
Shopping list suggestions are controlled from account settings. The personalization preference defaults to on, but collection, personalised serving and any legacy bootstrap remain inactive unless the feature is enabled, these exact policy revisions are approved and you have completed the required review. Turning personalization off stops personal recommendation collection, purges recommendation events and derived signals attributed to you, and uses only curated fallback items. You may instead reset the same history while leaving personalization enabled.