Trust

Trust and security

Last updated: October 6, 2026

How ListSpace keeps your boards safe: where your data is stored, who can reach it, what agents may do with it, and how to report a security problem. For what we collect and why, see the Privacy Policy.

Where your data lives

Your account, boards, lists and items are stored in a database on our own server in Germany, rented from Netcup. Sign-in and the website run on the same server. Files you upload are stored in Cloudflare R2 in the European Union. Emails from ListSpace are sent through MXroute, from a server in the United States.

Every provider that handles your data is listed on the sub-processors page.

Encrypted connections

Every connection to ListSpace uses HTTPS. A plain HTTP request is redirected to HTTPS, and the site sends a Strict-Transport-Security header for one year, including subdomains, so browsers refuse an unencrypted connection.

Passwords, sessions and tokens

  • Passwords are stored as bcrypt hashes by the sign-in service. We cannot read them. Passwords on shared board links are stored as bcrypt hashes too.
  • Sign-up, sign-in and password reset are protected by Cloudflare Turnstile and rate limits, which stop bots and password guessing.
  • A sign-in session token is valid for one hour and is then renewed with a refresh token, which is replaced each time it is used.
  • Two-step sign-in is optional: turn it on in Settings with an authenticator app (TOTP). For an account that has it on, the database itself refuses a session that has not passed the second step.
  • You get an email when an authenticator is added to or removed from your account.
  • You can also sign in with a code sent to your email. Asking for a code never creates an account.
  • There is no SMS option and there are no recovery codes yet. If you lose your authenticator, we restore access by hand after checking that the account is yours.
  • Personal API tokens are stored only as a SHA-256 hash. A token can be read-only, and you can revoke it in Settings at any time.

Each account reaches only its own boards

Row-level security is switched on for every table in the ListSpace database. The database itself checks each request against the signed-in account, so a request for someone else's board returns nothing, and a write into another account is refused.

Private files

Attachments are stored in a private bucket. They can only be opened through a signed link that expires within one hour, and a link is only issued for files under your own account.

Images you choose to make public, such as board backgrounds and images on a shared board, are stored separately. Cloudflare checks those public images against known child sexual abuse material. Files on private boards are not scanned.

Backups

The database is dumped every hour on the server, and the last 48 hours of dumps are kept. Every night an encrypted copy is stored off the server, and restores from that copy are tested. When you delete your account, copies in backups disappear in the normal backup cycle.

Agents work within limits you set

AI agents reach your boards only after you connect them, by signing in or with a personal token. For each board you choose a freedom level, from 1 (Read only) to 5 (Full). At the levels in between, changes that need your approval wait in the board's Inbox until you accept or reject them.

At any level, agents never:

  • Delete anything permanently. They archive instead, and you can bring it back.
  • Change freedom levels, or accept or reject suggestions in the Inbox.
  • Make share links, board email addresses, API tokens or webhooks.

Every change is recorded in the board's history with the name of the agent that made it, and you can undo it there for 30 days. Disconnecting an agent in Settings stops its access. The full rules are in What AI agents can do.

No AI models run by ListSpace

ListSpace runs no AI models itself. The assistants you connect, such as Claude or ChatGPT, run with their own provider under that provider's terms. How we handle your data is described in the Privacy Policy.

Analytics without cookies

We count visits to the public pages with Umami, an open-source tool on our own server. It sets no cookies and stores nothing that identifies you. The app itself, where your boards are, loads no analytics. There are no advertising or tracking cookies anywhere on ListSpace.

Report a security problem

If you find a security problem in ListSpace, email security@listspace.app with what you found and the steps to reproduce it. We confirm that we received your report, and we keep you informed while we work on it.

While you look, please:

  • Use only your own accounts and boards. Do not open, change or keep other people's data, beyond the least you need to show the problem
  • Do not run tests that slow the service down or interrupt it for others, and do not send spam
  • Do not use social engineering, such as phishing us or our users, and do not try physical attacks
  • Give us reasonable time to fix the problem before you publish it

If you report in good faith and follow these rules, we will not take legal action against you for your research. We do not run a paid bug bounty yet.

Our contact details for security reports are also in security.txt.

What we are working on

ListSpace has no security certification today, such as SOC 2 or ISO 27001. These are the next steps we have decided on: