Legal

Privacy Policy

Last updated: April 2026

Summary in plain English

We collect only what we need to run the service — your email if you sign in, your usage count, and your generated listings. We do not sell your data. We do not advertise to you. You can delete your account and data anytime by emailing us.

1. Who We Are

ListingAI (r-n-asistan.vercel.app) is an AI-powered product listing generator. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have. If you have questions, contact us at listingaiapp@gmail.com.

2. Data We Collect — Free Tier (No Signup)

When you use ListingAI without signing up, we collect minimal data: your IP address (used only to enforce the 3-listing lifetime limit and prevent abuse), the product information you type into the generator, and a consent choice for cookies stored in your browser's localStorage. We do not know who you are, we do not store your listings, and we delete IP counters only when technically needed.

3. Data We Collect — Signed-In Users (Free and Paid)

When you sign in with Google, we receive your email address, Google profile ID, and display name from Google OAuth. We store: your account record (email, plan type, signup date), your subscription status if you have one, your monthly usage counter, and the listings you generate (saved to your history). We do not receive your Google password. We do not access your Gmail, Drive, or other Google services.

4. Data We Collect — Etsy Connection (Pro Only)

If you connect your Etsy shop as a Pro user, we receive an OAuth access token from Etsy that allows us to create draft listings on your behalf. We store the token encrypted in our database. We never access: your Etsy orders, customer data, shop earnings, or any information beyond what is required to publish draft listings. You can disconnect your Etsy shop at any time from the settings page, which immediately revokes our access.

5. How We Use Your Data

We use your data to: (a) provide the listing generation service, (b) enforce usage limits for each plan tier, (c) process subscription payments through Paddle, (d) send account-related emails (payment confirmations, important service updates), (e) improve the service through anonymized usage analytics if you have consented. We do not use your data for advertising, we do not sell it to third parties, and we do not share it with anyone except the third-party services listed in section 7 (which are essential to the service).

6. Legal Basis for Processing (GDPR)

For users in the European Union and European Economic Area, we process your data under the following legal bases. Contract performance: processing needed to provide the service you requested (account management, listing generation, subscription billing). Legitimate interests: preventing abuse of free tier limits, improving the service. Consent: analytics cookies (only if you click Accept in the cookie banner). Legal obligations: tax and accounting requirements handled by Paddle.

7. Third-Party Services We Use

We use the following services to provide ListingAI. Each has its own privacy policy. Google (OAuth authentication) — receives your login attempt, returns your profile data. Supabase (database hosting, AWS eu-west-1) — stores your account and generated listings. Anthropic (Claude AI) — receives the product information you type to generate listings; does not store it per Anthropic's zero-retention policy. Groq (LLaMA AI) — receives the same product information for faster generation. Etsy API — receives your OAuth token only when you publish a listing. Paddle (Merchant of Record for payments) — receives your payment information; we never see your card details. Vercel (hosting and analytics) — receives anonymized page view data if you consent.

8. Cookies and Local Storage

We use three types of storage in your browser. Essential cookies (always on): required to keep you signed in (Supabase session) and remember your cookie consent choice. Local storage: used to track your free tier usage count locally before signup, store your cookie consent choice, and cache your Etsy connection state. Analytics cookies (optional, consent required): Vercel Analytics collects anonymized page views only if you click Accept in the cookie banner. You can change your cookie choice at any time by clearing your browser's localStorage for our domain.

9. Data Storage and Security

Your account data is stored in Supabase (PostgreSQL) hosted on AWS servers in the European Union (eu-west-1, Ireland). All data is transmitted over HTTPS/TLS. Passwords are never stored by us — authentication is handled entirely by Google OAuth. Paddle stores payment information separately and we never see your card or bank details. Access to our database is restricted to authorized administrators only.

10. Data Retention

We retain your data as follows. Account data: stored as long as your account is active, deleted within 30 days of account deletion request. Subscription records: retained for 7 years to comply with tax and accounting laws (this is a legal requirement, not our choice). Generated listings: stored with your account until you delete them or close your account. IP-based free tier counters: automatically deleted 90 days after last activity. Cookie consent choice: stored in your browser until you clear it.

11. Your Rights (GDPR)

If you are in the EU, EEA, or UK, you have the following rights under GDPR. Right of access: request a copy of all data we hold about you. Right to rectification: correct inaccurate data. Right to erasure (right to be forgotten): request deletion of your account and associated data. Right to restrict processing: limit how we use your data in specific circumstances. Right to data portability: receive your data in a machine-readable format. Right to object: object to processing based on legitimate interests. Right to withdraw consent: change your analytics cookie choice at any time. To exercise any of these rights, contact us at listingaiapp@gmail.com. We respond within 30 days.

12. International Data Transfers

Our primary database is in the European Union. Some third-party services we use (Anthropic, Groq, Vercel) may process data in the United States or other countries. These transfers are protected by Standard Contractual Clauses approved by the European Commission, which provide an adequate level of data protection.

13. Children's Privacy

ListingAI is not intended for users under 16 years of age. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a child, contact us at listingaiapp@gmail.com and we will delete it promptly.

14. Data Breaches

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify affected users within 72 hours via email, as required by GDPR Article 33-34. We maintain technical and organizational safeguards to prevent breaches.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email at least 14 days before taking effect. The 'Last updated' date at the top of this page reflects the most recent revision.

16. Contact — Data Protection Matters

For privacy questions, data access requests, deletion requests, or any other GDPR-related matter, contact us at listingaiapp@gmail.com. We aim to respond within 1 business day and resolve all requests within 30 days. If you are not satisfied with our response, you have the right to file a complaint with your local data protection authority.

© 2026 ListingAI
TermsPrivacyRefundSupport