Privacy Policy
This page explains what Asklist stores on behalf of an account holder (the “owner”) and the people they send requests to (the “recipients”), for how long, and who can see it. Asklist is operated by Warren Enterprises.
What we store
Two kinds of data. First, the documents a recipient uploads in response to a request — things like photo ID, bank statements, signed forms, and certificates. Second, the checklist itself: the item labels and notes an owner writes, each item's status, and the recipient's name and email address. We do not ask a recipient to create an account, and we do not collect anything from them beyond what they choose to upload or type into a checklist item.
How long we keep it
Uploaded files are deleted 60 days after the request they belong to is completed or closed, and in any case no more than 90 days after the request was sent. Deletion happens automatically on a daily schedule. An owner can also delete a request and its files at any time, immediately and irreversibly.
Who can see it
The owner who sent the request can see the files and checklist for that request. Warren Enterprises can access data as needed to host the service and provide support. Nobody else — a request's files are never public, and nothing about one owner's requests is visible to another owner.
How it's stored
Files are kept in a private store in Vercel's Dublin region (EU): every read requires authentication, there are no public URLs, and every download is streamed through the owner's signed-in account. Files are encrypted at rest with AES-256 and in transit with TLS. The database — names, email addresses, and checklist text — is hosted by Supabase in London, UK.
Who we share it with
Four providers, each for one job. Vercel hosts the service and stores uploaded files in its Dublin region (EU), and runs cookieless web analytics on every page, including the upload page — no cookies, no cross-site tracking. Supabase hosts the database in London, UK. Stripe handles billing and receives the owner's email address and name. Resend delivers our email and receives recipient addresses, names, and the checklist text in the emails. We do not sell data, and we do not share it with anyone else.
Cookies
Owners receive one session cookie, needed to stay signed in. Recipients receive no cookies from us.
Contact
Questions about this policy, or a request to access, correct, or delete your data: support@warrenworks.dev.