CollabList Home Effective Date: September 22, 2026
Privacy & Data Governance

Privacy Policy

Your privacy is fundamental to how Collaborative Checklists is engineered. We minimize data collection and do not require user accounts.

1. Information We Collect

  • Checklist & Task Data: Titles, notes, priorities, deadlines, and completion statuses submitted by collaborators.
  • Self-Reported Collaborator Names: Optional display names provided locally in browser storage to attribute activity edits.
  • Private Contact Information: Optional recipient email addresses and mobile telephone numbers entered by the checklist creator to deliver automated deadline reminders.
  • Provider API Credentials: Brevo API keys, Twilio Account SIDs, Auth Tokens, and Sender numbers stored exclusively in Cloudflare D1 to authenticate reminder requests.

2. How Contact Data is Isolated & Protected

Strict Scope Isolation: Private notification emails and mobile phone numbers entered by the checklist creator are never returned in API responses to general collaborators using the shared Editor link. Public editor feeds and activity logs strictly sanitize contact records.

Cryptographic Token Security: Capability tokens are generated with 256 bits of entropy and stored in the database exclusively as SHA-256 hashes. Plaintext tokens cannot be derived from stored hashes.

3. Recipient Consent, Preferences & Unsubscribes

Entering an email address or mobile number does not automatically opt that recipient into recurring notifications. In accordance with anti-spam principles:

  • Recipients can verify ownership and manage delivery preferences via dedicated recipient links without creating an account.
  • Recipients can set quiet hours (e.g. 22:00–08:00), restrict delivery to weekdays only, or unsubscribe completely.
  • Once an address or phone number is unsubscribed or flagged with a bounce/complaint, future delivery is automatically suppressed.

4. Third-Party Subprocessors

To provide global edge hosting and notification delivery, data may be processed through:

  • Cloudflare: Edge Workers, Pages hosting, and D1 SQLite database storage.
  • Brevo: Transactional email delivery when configured by the checklist creator.
  • Twilio: Programmable SMS delivery when configured by the checklist creator.

5. Data Retention & Deletion

Checklist creators have the ability to permanently delete their checklists, tasks, tokens, contact records, and notification logs at any time from the Management Console. Permanent deletion immediately removes all associated data from Cloudflare D1 storage.