Privacy Policy

Last updated: March 18, 2026

1. What we collect

When you create an account, we collect your email address and password (hashed). When you use lst.so, we store the tasks, subtasks, tags, notes, and activity logs you create. We also collect basic usage data (page views, feature usage) through privacy-friendly analytics.

2. How we use your data

We use your data to provide and improve lst.so. Specifically:

  • - To operate your account and deliver the service
  • - To send transactional emails (account verification, password resets)
  • - To process payments through Stripe
  • - To improve the product based on aggregate usage patterns

We do not sell your data. We do not use your task content to train AI models.

3. Third-party services

We use the following third-party services:

  • - Stripe for payment processing. Stripe handles your payment information directly; we never see or store your card details.
  • - Resend for transactional email delivery.
  • - Render for hosting infrastructure.
  • - Plausible Analytics for privacy-friendly, cookieless usage analytics.

4. MCP and AI agents

When you connect AI agents (such as Claude Code, OpenClaw, or ChatGPT) via the Model Context Protocol, those agents can read and write tasks on your behalf using your API key. We do not share your data with AI providers beyond what you explicitly authorize through these connections. Agent activity is logged on your tasks so you always have visibility.

5. Cookies

We use a session cookie to keep you logged in. We do not use tracking cookies or third-party advertising cookies.

6. Data retention

Your data is stored for as long as you have an active account. If you delete your account, all associated data (tasks, subtasks, logs, tags, and personal information) is permanently deleted within 30 days.

7. Your rights

You can export, correct, or delete your data at any time. To delete your account and all associated data, go to Settings. For any other requests, email help@lst.so.

8. Security

All data is transmitted over HTTPS. Passwords are hashed using bcrypt. API keys can be regenerated at any time from your settings.

9. Changes

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice.

10. Contact

Questions? Email help@lst.so.