Privacy Policy

PantaList · Effective 10 September 2026

PantaList ("the app", "we", "us") is a mobile and web application that lets you view and edit spreadsheets as mobile-friendly lists. PantaList is operated by independent developer Moshe Meiseles. This policy explains what information the app handles, why it is handled, and the choices you have. You can contact us at [email protected].

PantaList does not operate a backend that stores your spreadsheet or workbook content. Cloud file content travels between the app on your device and the provider you connect.

Information PantaList handles

Authentication and storage

For Google sign-in on the web, PantaList uses a limited authentication service hosted on Cloudflare. It stores the Google identity and credentials needed to restore the session in encrypted form. The browser receives short-lived access tokens, not the Google refresh credential. The service does not proxy or store spreadsheet content or file metadata.

Microsoft browser credentials and app data are stored in the browser's local storage. Native credentials are stored using device storage intended for authentication secrets. Removing site data, signing out, or uninstalling the app can remove local information, as described below.

How information is used

Information is used to authenticate you, open and manage the files you select, display and edit lists, save your changes, restore your preferences, and diagnose reliability problems. We do not sell personal information or spreadsheet content, use it for advertising, or use Google or Microsoft user data to train generalized artificial-intelligence or machine-learning models.

Sharing and service providers

We disclose information only as needed to operate the features you use:

Security

PantaList minimizes the data and permissions it requests. Google web identity and credential records are encrypted before storage, session-verification secrets are stored as cryptographic hashes, and network traffic uses HTTPS/TLS. Native credentials use protected device storage where the platform supports it. Diagnostic events are designed not to include spreadsheet content, and production systems are limited to the developer operating PantaList. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

Google API Services User Data Policy

PantaList's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your choices and deletion

Deleting PantaList data does not delete files that you own in Google Drive, OneDrive, or local storage. Delete those files through their storage provider if you also want to remove the source content.

Retention

We do not retain copies of your spreadsheet or workbook content on PantaList servers. Google web sessions expire after 30 days of inactivity and have a maximum lifetime of 180 days. When the final Google web session is signed out or expires, PantaList revokes and deletes the stored credential; unused credentials are retained no longer than 180 days. Microsoft web sessions normally require reauthorization after 24 hours. Local data remains until you clear it, sign out where applicable, or uninstall the app. Sentry retains diagnostic information according to the configured Sentry retention period and only as long as needed to investigate reliability and security issues.

Children

PantaList is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

International processing

Google, Microsoft, Cloudflare, and Sentry may process information in countries other than your own under their respective privacy and data-transfer arrangements.

Changes to this policy

We may update this policy. The effective date above will change when an updated policy is published.

Contact

Email privacy or data-deletion questions to [email protected].