Legal
Privacy Policy
Last updated 20 September 2026
Pawalist ("we") is operated by App Forge Labs LLC. This policy explains what we store, why, who processes it on our behalf, how long we keep it, and how to have it deleted. Questions: [email protected].
What we store and why
- Your work. The captures you submit, including their text, any audio or images you attach, and their transcripts; the tasks, projects, labels, subtasks, dependencies, recurrence rules and schedule placements made from them; the context rules you write; your conversations with the Pawalist agent; the outcomes you record and the memories derived from them; and your completion history. All of it is kept so the product can do its job, and all of it is exportable.
- Account details. With Google sign-in we receive your Google account identifier, email address, name and profile picture; with an email link, only the address you enter. We use them to create and recognise your account.
- Abuse limits. Your IP address and a one-way hash of the email address you ask a sign-in link for, used only to apply rate limits.
- Payments. Stripe processes card payments; we store your Stripe customer and subscription identifiers and status, never card details.
- Technical logs. Records of errors and operations, kept for debugging and security.
Processors
- Stripe handles subscriptions and billing.
- Resend sends sign-in emails.
- Google provides optional sign-in.
- Hetzner hosts our servers and database; Cloudflare provides the network in front of them and backup storage.
- OpenRouter routes our model calls. It receives the text of the capture or conversation being processed, plus the context rules and memories relevant to it, and forwards them to the model provider for that request (currently Google and DeepSeek models). It does not receive your email address, your name or your payment details.
- Axiom receives our server logs, which record what happened rather than what you wrote.
Cookies
We use one sign-in session cookie, which is essential. We do not use advertising or cross-site tracking cookies, and Pawalist carries no analytics.
Sharing
We never sell personal data. Nothing you put into Pawalist is public or shared with other users: there are no shared lists, no shared projects and no public profiles. Your work leaves our systems only when you export it, or when a model call sends the relevant text to a provider to process your request.
If you create an API credential or authorize an MCP connection, whatever you give that credential access to can be read and changed by whoever holds it, within the scopes you chose. You can see when each was last used and revoke it at any time.
Retention and deletion
Your data stays until you delete it, or until your account is deleted. Sessions and sign-in links expire automatically. Items you trash are recoverable for 30 days and then removed. Generated export archives expire after seven days.
You can delete your account from Settings, without emailing anyone. Deleting signs you out immediately, cancels renewal, revokes every API credential and MCP connection and cancels work in progress. Your content then survives for 30 days: signing in again with the same verified identity restores it, with your purchased credits intact. After 30 days the content is permanently deleted and any unused credits are forfeited without a cash refund. We keep only the billing records the law requires us to. Encrypted backups roll off within 30 days after that.
Changes
We will update this page when our practices change and note the date above.