Privacy Policy
Last updated: 19 July 2026
ListGuard is a tool for cleaning and verifying email lists. Your email list is one of the most sensitive things you own, so we built ListGuard to hold on to as little of it as possible. This policy explains what we collect, why, where it is processed, and what rights you have.
The short version. We do not store the email addresses inside your lists. Your uploads are processed in Europe and deleted the moment your clean list and report are ready. We keep the counts (how many addresses were cleaned and why), never the contacts. We do not sell your data, and we do not use advertising or tracking cookies.
1. Who we are
ListGuard (listguard.cloud) is operated by Diexar, the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).
2. What we collect, and why
Your account
When you register, we store your email address and a securely hashed version of your password (we never keep your password in readable form). We also keep your plan and subscription status. We need this to give you an account, log you in, and apply the right usage limits. Legal basis: performance of our contract with you.
The email lists you upload
When you upload a list to be cleaned or checked, your file is processed on our servers in a single pass and then deleted right after your clean list and report are generated. The individual email addresses in your list are never written to our database. Download links for your results are temporary. Legal basis: performance of our contract with you; for the contacts inside your list, you act as the controller and we process them on your behalf (see section 6).
Usage statistics
For each cleaning run we keep counts only: how many addresses went in, how many were kept, how many were removed and for which reason, and a health score before and after. These numbers let you see your history and let us enforce fair-use limits. They contain no email addresses. For domain health checks we store the domain name you looked up and the time, so we can apply the daily check limit. Legal basis: performance of our contract and our legitimate interest in running the service reliably.
A custom blacklist you choose to save
If you use the optional custom blacklist / suppression feature, the file you save is kept so it can be reused across runs. This is the one case where address-like data you provide is stored, and it only happens because you deliberately save it. You can replace or delete it at any time. Legal basis: performance of our contract at your request.
Technical logs
Like any website, our servers keep standard technical logs (such as IP address, timestamp and error information) for security, troubleshooting and abuse prevention. These are kept for a short period and are not used to profile you. Legal basis: our legitimate interest in keeping the service secure.
3. What we do not do
We do not sell or rent your data. We do not use it to build advertising profiles. We do not run third-party analytics, advertising or social-media tracking on our site. We do not read your contacts back into our database after a run.
4. Optional third-party verification (your own key)
ListGuard lets you connect your own ZeroBounce or Hunter.io API key to run real mailbox verification on top of our own checks. This is entirely optional and off unless you turn it on:
- Your API key is stored only in your own browser, never on our servers.
- When you run a verification, a limited number of unique addresses from your list are sent to the provider you chose so they can be checked. Those providers are based in the United States and process the data under your own account and their terms.
- This transfer happens because you enabled it with your own key. If you do not connect a key, no addresses ever leave our European servers.
Please review the privacy terms of ZeroBounce and Hunter.io before using this feature.
5. Where your data is processed, and who helps us
Your data is processed and backed up on servers in Europe only. Nothing is copied to servers in other countries by default. A few providers (sub-processors) help us run the service:
- Contabo GmbH (Germany) hosts the application and database.
- Amazon Web Services (AWS) stores encrypted backups in the Frankfurt (eu-central-1) region.
- aMember. For members who reach ListGuard through a partner membership, we check subscription status by email against that membership system.
- ZeroBounce or Hunter.io, only if you connect your own key (see section 4).
When we introduce paid checkout, the payment provider that handles your payment will be added to this list. We do not transfer your personal data outside the European Economic Area, except for the optional third-party verification you trigger yourself with your own key.
6. Your list, your responsibility
You decide which lists to upload. You are responsible for having a lawful basis to process the contacts in your lists (for example, consent or another valid ground), and for honouring their rights. For those contacts, you are the controller and ListGuard acts as a processor on your behalf. Because we delete your uploads right after processing and never store the addresses, we hold no lasting copy of your contacts.
7. How long we keep things
- Uploaded lists: deleted right after processing; results available only through temporary download links.
- Account data: kept while your account is active, and deleted after you close it (unless we must keep something to meet a legal obligation).
- Usage statistics: kept so you can see your history; they contain no addresses.
- Custom blacklist: kept until you replace or delete it, or close your account.
- Technical logs: kept for a short period, then rotated out.
8. How we protect your data
- Every upload and page travels over an encrypted (HTTPS/TLS) connection.
- Passwords are stored only as a strong one-way hash.
- Application, database and backups live on European servers.
- Backups are encrypted and access to them is restricted.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- correct data that is wrong or incomplete;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where processing is based on it.
To exercise any of these, email us at diexar@listguard.cloud. You also have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (aepd.es); you may also contact the authority in your own country.
10. Children
ListGuard is a business tool and is not intended for children. We do not knowingly create accounts for anyone under 16.
11. Changes to this policy
We may update this policy as the service evolves. When we make a material change, we will update the date at the top of this page. Please check back from time to time.
12. Contact
Questions about your privacy or this policy? Email us at diexar@listguard.cloud and we will be glad to help.