Last updated: August 2026
When you create a Frontlist account, we collect your email address, a securely hashed version of your password (we never store your actual password), and optionally a pen name. As you use the app, we store the book, format, platform, and vendor information you enter. If you subscribe, Stripe processes your payment; we store a reference to your Stripe customer record, but never your full card number. If you submit the contact form or subscribe to our newsletter, we store the email address and message you provide.
We don't store manuscript files, cover images, or any other creative work. Frontlist only tracks metadata, titles, formats, statuses, and notes, that you type in yourself. We don't use tracking cookies or third-party analytics scripts on the app itself.
We use your data to operate the service: to authenticate your account, to display your titles and platform statuses back to you, to process payments, to respond to support requests, and to send you account-related emails like password resets. If you've opted into the newsletter, we use your email to send occasional product updates.
We share data with the third-party services that make Frontlist work: Stripe for payment processing, and Resend for sending transactional emails like password resets. We don't sell your data, and we don't share it with advertisers. Your titles, formats, and platform data are private to your account; other authors never see them, only the shared list of built-in platform names is common across accounts.
We retain your account data for as long as your account is active. If you'd like your account and associated data deleted, contact us through the contact page and we'll process the request.
You can access, correct, or delete most of your data directly within the app. For anything you can't change yourself, including full account deletion, reach out through the contact page. Depending on where you live, you may have additional rights under laws like the GDPR or CCPA; contact us and we'll do our best to accommodate applicable requests.
Passwords are hashed, not stored in plain text. Data is transmitted over encrypted connections. No system is perfectly secure, but we take reasonable steps to protect your information.
We may update this policy from time to time. If we make material changes, we'll make a reasonable effort to notify active subscribers by email.
Questions about this policy can be sent through the contact page.