Privacy Policy
How we protect your privacy and data
Last updated: July 27, 2026
1. Introduction
Welcome to Listub ("we", "our", or "us"), a service provided by Galveo GmbH. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, and share your information when you use the Listub mobile apps (iOS and Android), the Listub web app (app.listub.com), the Listub desktop apps, and our website www.listub.com (together, the "Services"). This Privacy Policy complies with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws.
2. Controller and Contact
The controller responsible for processing your personal data is: Galveo GmbH Aachener Str. 37 50674 Cologne, Germany Email: [email protected] Data protection contact: [email protected]
3. Information You Provide
When you create an account and use the Services, you may provide us with:
- First and last name (required for account creation)
- Email address (required for account creation and communication)
- Password (stored only as a salted hash, never in plain text)
- Country and preferred language (for localization and compliance)
- Phone number (optional)
- Profile picture, username, and profile details such as a bio (optional; stored on our cloud object storage)
- Content you create (lists, notes, tasks, room content, and uploaded files). This is stored on our servers on every plan, including the free plan, and a copy is kept on your device so the app works offline. Paid plans additionally allow access from several devices and sharing rooms with other people.
- Communications with us (support inquiries, feedback)
- Subscription and payment preferences
- Referral and affiliate codes
4. Information Collected Automatically
When you use the Services, we automatically collect certain technical information:
- IP address (for security, fraud prevention, and determining your country)
- Device information (type, operating system, browser, app version), and - if you enable notifications - a push notification token
- Sign-in and security data (login history, known devices, and the sign-in method used), so you can review account activity and we can detect suspicious access
- Usage data (such as a periodic count of how many rooms you have, features used, and session activity)
- Log data (access times, error logs, performance metrics)
- Location data (country-level only, derived from your IP address; we do not collect precise GPS location)
- Cookies and similar local-storage technologies (see below)
5. Payment and Subscription Data
If you purchase a paid plan, we process:
- Subscription plan details (Basic, Premium, Family) and their status
- The payment processor used: Google Play on Android, the Apple App Store on iOS, and Paddle (our Merchant of Record) on the web and desktop. We do not receive or store your full payment card details - payments are handled entirely by these processors.
- Transaction history and subscription logs (including invoices where required)
- Promo codes, discounts, and affiliate tracking data
- Family plan member relationships
6. Legal Bases for Processing (GDPR)
We process your personal data on the following legal grounds:
Contractual necessity (Art. 6(1)(b) GDPR):
Account creation, providing the Services, syncing and storing your content, and subscription management.
Legitimate interests (Art. 6(1)(f) GDPR):
Service improvement, security, fraud and abuse prevention, and basic usage analytics.
Consent (Art. 6(1)(a) GDPR):
Newsletter subscriptions, marketing communications, and website analytics cookies. You can withdraw consent at any time.
Legal obligation (Art. 6(1)(c) GDPR):
Compliance with applicable laws, in particular tax and accounting requirements.
7. How We Use Your Information
We use your information for the following purposes:
Service provision:
Account management, authentication, storing and syncing your content, and core functionality.
Subscription management:
Processing payments, managing plan changes, and billing.
Communication:
Sending service updates, verification codes, support responses, and important notices.
Security:
Fraud prevention, account protection, bot protection, and system security.
Analytics:
Understanding usage patterns to improve the Services.
Legal compliance:
Meeting regulatory requirements and enforcing our policies.
Marketing:
Promotional communications, only with your consent, and always with an opt-out.
8. Lumi AI Assistant
The Services include an optional AI assistant ("Lumi") that can create and modify entries and answer questions based on your requests. When you use Lumi, the text you submit (and, where needed, related entries required for context) is processed on our service infrastructure to generate a response. That processing takes place with the infrastructure providers listed in "Who We Share Data With" below, under the same contractual and security framework as the rest of the Services. Your AI requests are not used by us to train AI models. AI usage is subject to fair-use limits depending on your plan. If you do not use the AI features, no content is processed for AI purposes.
9. Cookies and Website Analytics
The Listub app itself does not use third-party advertising or analytics trackers. It only uses essential cookies and similar local-storage technologies that are required for core functionality: keeping you signed in, remembering your settings, protecting against bots and abuse, and basic performance and error monitoring. Fonts and static assets are bundled with the app or served from our own infrastructure. Our website www.listub.com additionally uses the following services, which may set cookies and process your IP address and usage data:
Google Analytics:
Helps us understand how visitors interact with our website (pages visited, time spent, traffic sources). Loaded only after you give consent via our cookie banner.
Google Tag Manager:
Manages and deploys the analytics tools above. Loaded only after consent.
Google Fonts:
Displays custom fonts on the website. Your browser may download font files from Google's servers.
Analytics cookies are set only after you consent via the cookie banner on www.listub.com. Your choice (acceptance or refusal) is stored for 12 months; after that we ask again. You can change or withdraw your consent at any time using the "Cookie Settings" link in the website footer. You can also control cookies through your browser or device settings; disabling essential cookies may limit functionality.
10. On-Device Storage and Offline Copy
To make the app fast and usable offline, Listub stores a copy of some of your own data directly on your device. This is strictly necessary for the Services to work and is never shared with third parties:
Your content cache (IndexedDB):
A copy of the rooms, tasks, notes, and other entries you have created or been invited to, so they open instantly and still work when you are offline. This on-device copy mirrors content that is stored on our servers on every plan, including the free plan.
App shell and media cache (service worker):
Static files such as the app itself, fonts, and images you have already seen are cached by your browser or the installed app so they do not need to be downloaded again. These caches contain no personal data beyond what you have already loaded.
Session tokens:
A small authentication token is stored so you do not have to log in on every visit. Depending on your choice of "Keep me signed in", this token lives in your browser's localStorage (until logout) or sessionStorage (until you close the browser). Turning "Keep me signed in" off is recommended on shared or public devices.
App preferences:
Small UI settings such as theme, language, and onboarding state. These are not linked to any personal data and exist only on the device.
When you log out, we always clear your session tokens and reset the in-memory state of the app. On a mobile device your locally stored content is kept on the device by default so it is ready when you sign back in; on the web you can additionally choose "delete local data" to erase the cached content and image caches. Your device-level preferences (theme, language) are preserved, and if a different account signs in on the same device, the previous account's content is wiped automatically. If you share your device with others, keep in mind that a signed-in session makes your locally cached content visible to anyone using that device or browser profile. We recommend logging out on shared devices.
11. Sharing, Community, and Public Content
Some parts of Listub are social. What you share, and with whom, is always your choice:
Shared rooms:
Content you put in a shared room is visible to the other members of that room. Activity in shared rooms is recorded in the room's activity log, visible to its members.
Family plans:
The plan owner can see member email addresses; members can see each other's names. Individual room content remains private unless explicitly shared. Subscription activity logs are visible to the plan owner.
Public profile and community:
If you enable a public profile, your username, display name, profile picture, profile details, and the content you choose to share (such as posts or shared tracker lists) are publicly visible to anyone, including people without a Listub account, and may be cached by our content delivery network. Community suggestions (such as people with similar interests) are computed on our servers from the content you have chosen to share and are shown as percentages only. You can edit your profile's visibility or disable sharing at any time in the app's privacy settings.
Share links:
If you create a public share link (for example for a wishlist or a tracker list), anyone who has the link can view the shared content without an account. You can revoke a share link at any time, after which the content stops being publicly available (caches may take a short time to expire).
12. Who We Share Data With
We do not sell your personal data. We share information only with the service providers that help us operate the Services (each receives only what it needs for its task), and in the limited circumstances below:
- Cloudflare, Inc. (application hosting, content delivery, object and file storage, bot protection, email delivery infrastructure, and AI inference)
- MongoDB Atlas (managed database hosting)
- Google (Google Play billing on Android, Firebase Cloud Messaging for push notifications, and Google sign-in if you use it)
- Apple (App Store billing on iOS, and Apple sign-in if you use it)
- Microsoft (Microsoft sign-in, if you use it)
- Paddle (payment processing and Merchant of Record for web and desktop purchases)
- Catalogue data providers for the tracker modules (The Movie Database (TMDB) for films and series, Google Books and Open Library for books). Your catalogue searches are proxied through our servers; only the search query itself is forwarded, never your identity or account data.
Business transfers: in connection with a merger, acquisition, or asset sale, your data may be transferred with appropriate notice and data protection measures. Legal requirements: we disclose data when required by law, court order, or to protect rights, safety, and security. Affiliate program: if you signed up through an affiliate, limited information (such as the first letters of your name and your subscription status) may be shared with that affiliate for commission tracking.
13. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Data is stored with reputable cloud providers (Cloudflare, MongoDB Atlas) using industry-standard security, with encryption in transit (HTTPS/TLS) and encryption at rest where supported by our providers
- Passwords are stored only as salted hashes using industry-standard algorithms
- Optional email-based two-factor authentication, free for every account, plus support for passkeys
- App Lock can protect the app with your device's biometrics; biometric data is processed by your device only and never reaches our servers
- Infrastructure protected by Cloudflare's security tooling, with automated monitoring and threat detection
- Role-based access controls for internal systems and regular security reviews
Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.
14. Data Retention and Deletion
We keep your data only as long as needed:
Active account:
Your account data and content are retained while your account is active, with a copy kept on your device.
Deleted rooms:
A room you move to trash is scheduled for permanent deletion about 30 days later; until then you can restore it.
Archived content:
When you downgrade to the free plan or leave a family plan, server-side rooms beyond your plan's limits are archived rather than deleted. Archived rooms (and their uploaded files) are permanently deleted about 180 days after archiving if not restored.
Account deletion:
When you delete your account it is deactivated immediately (you are logged out everywhere, nobody can see you, and any paid subscription is cancelled so you are not charged again) and enters a 30-day recovery window during which you can restore it by logging in. After the window, your account and all associated data - rooms you own, entries, uploaded files, notifications, devices, and other user-scoped data - are permanently and irreversibly erased, and your participation in shared rooms is removed. On your device, deletion also wipes the app caches.
Records we must keep:
Payment and subscription records (which include the name and email associated with a purchase) are retained for the period required by tax and accounting law as proof of the transaction, stored so they are no longer linked to an active account. All other personal data is deleted.
The 30-day window covers ordinary self-delete requests. If you need immediate erasure under GDPR Article 17, contact us at [email protected] or through the contact form at listub.com/contact and we will honor it without the recovery delay.
15. Your Rights Under GDPR
You have the following rights regarding your personal data:
Access:
Request information about the personal data we process about you.
Data portability:
Receive your data in a structured, machine-readable format (the app includes export and backup functions).
Rectification:
Correct inaccurate or incomplete personal data, directly in the app or by contacting us.
Erasure:
Request deletion of your personal data ("right to be forgotten"), subject to records we must keep by law.
Restriction:
Limit how we process your data.
Objection:
Object to processing based on legitimate interests.
Withdraw consent:
Revoke consent for consent-based processing at any time.
Opt-out:
Unsubscribe from marketing communications via the link in each email or in the app's notification settings.
To exercise these rights, contact us at [email protected] or use the account settings in the app. We respond within 30 days. You also have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated data protection law.
16. International Data Transfers
We and our service providers (including Cloudflare, MongoDB Atlas, Google, Apple, Microsoft, and Paddle) may store and process your data in countries outside your own, including outside the European Economic Area (EEA), such as the United States. We rely on appropriate safeguards for any such transfers, including our providers' certifications under the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses (SCCs), and technical and organizational security measures.
17. Children's Privacy
The Services are not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country, if higher) to create an account. We do not knowingly collect personal data from children below that age; if we discover that we have, we will delete it promptly. If you are a parent or guardian and believe a child has provided us personal information, please contact us at [email protected].
18. Third-Party Links
The Services may contain links to external websites and services that are not operated by us (including links inside content that other users share with you). We have no control over, and assume no responsibility for, the content or privacy practices of any third-party site. We advise you to review the privacy policy of every site you visit.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services. We will notify you of material changes via email or an in-app notice, and updated versions are posted on this page with a new "Last updated" date. We recommend reviewing this policy periodically. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
20. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: Galveo GmbH Aachener Str. 37 50674 Cologne, Germany Email: [email protected] Data protection contact: [email protected] Contact form: listub.com/contact