Privacy at Listo

Last updated: August 2026 · Listo is currently in beta

The short version

What Listo is

Listo is operated by Proxima Consulting LLC. It is a homework assistant for high school students, licensed directly to families. The student, with their parent, opts in. Listo is not deployed by schools onto students. It is designed for students 14 and older.

Data we collect

From the school's system (with the student's authorization)

Listo connects to Canvas through its official API, using the standard Canvas consent flow the student authorizes. Listo never changes grades, assignment definitions, or anything teachers control. The only writes it makes happen at the student's explicit direction: marking the student's own planner item complete, or submitting work the student has prepared, through Canvas's normal student-submission process, as the student.

From the student's use of Listo

Homework helper conversations

Conversations with the homework helper are stored under the student's own account so a conversation can continue across the student's devices. They are private to the student: not visible to parents, not visible to schools, and never written into analytics. Parent and student threads are stored separately and never cross.

Data we don't collect

How we align with student-privacy law

Listo is licensed directly to families and built to align with FERPA, COPPA, and SOPIPA.

California student rights

California's Student Online Personal Information Protection Act (SOPIPA) sets out what a service like Listo may and may not do with student data. What that means in practice:

Children's privacy

Listo is designed for students 14 and older, and we do not knowingly collect data from children under 13. If we find out that we have, we delete it promptly. That is a straight deletion, not the 30-day grace period described under Account deletion, which applies only to deletions you ask for. If you believe a child under 13 has given us data, write to hello@studywithlisto.com and we'll take care of it.

The AI provider

Listo's AI is Claude, by Anthropic. Listo sends only the data needed to produce the requested output: current grades, assignment names and due dates, and the student's question. It deliberately minimizes personal identifiers in those requests. Anthropic does not use this data to train AI models, and keeps its own copy of the conversation for up to 30 days before automatically deleting it. That default covers essentially all Listo traffic. Two exceptions: a conversation Anthropic's automated systems flag as violating its usage policies may be kept for up to two years (and that conversation's safety-classification scores, not its content, for up to seven), and conversations required to be kept longer by law have no fixed limit. These windows are set by Anthropic's policy, not Listo's. See Anthropic's data retention policy. Deleting your Listo account removes our copy of the conversation, but does not shorten Anthropic's retention window for its own copy. Listo does not have a zero-data-retention arrangement with Anthropic.

Who can see a student's data

Where data lives

Google Cloud Platform, US region. Data is encrypted at rest and in transit. Each student's data is isolated: separate credentials, separate state, no cross-student analytics.

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and controlled, and we review our security practices regularly. Honest caveat: no method of transmitting or storing data electronically is 100% secure, and anyone who tells you otherwise is overselling. What we can commit to is using industry-standard protections and not cutting corners on them.

Sub-processors

Listo uses three: Google Cloud Platform (hosting and storage), Anthropic (Claude API), and Formspree, which handles the beta signup form on this website. Formspree receives only what you type into that form: your name, your email address, whether you are a parent, student or educator, and a school name if you give one. It never receives student data from Listo itself. A current sub-processor list and data-processing terms are available on request.

Account deletion

Deleting your account in the app

You can delete your account yourself, without contacting us. In any Listo app, open Settings, scroll to the bottom, and choose Delete my account. Listo shows you what will be deleted and what is kept, and asks you to type a confirmation word before the request is accepted.

When you confirm, your Canvas connection is disconnected right away and you are signed out on every device. Apart from that, nothing is erased for 30 days. Logging back in during those 30 days cancels the deletion. Your account comes back as it was, and you reconnect Canvas. After the 30 days, your account and its contents are permanently deleted: grade history, completion record, goals, streak, study materials, notes, homework helper conversations, notifications, and your ability to sign in. This cannot be undone.

Deleting your Listo account does not affect your Canvas account or your schoolwork. Your grades and assignments stay in Canvas.

Requesting deletion another way

You or your parent/guardian can also request deletion by emailing hello@studywithlisto.com instead of using the in-app option. Schools and districts may request deletion of student data in accordance with applicable law. We respond to deletion requests within 30 days.

What is kept

We keep the data-access audit trail on purpose. It records when an account read school data through Listo: the date and time, the account that made the request, what kind of request it was, and, for a course-specific request, which course it concerned. It contains no grades, no assignment content, and no conversations. Schools are required to be able to audit access to education records, so these entries are not deleted along with the account. They are retained for up to three years, then deleted automatically.

Pseudonymized usage data also outlives the account. It carries no name, email address, grades, or assignment content. The email address is replaced with a one-way hash before the data is stored. That hash is stable rather than random, which is why we describe this data as pseudonymized rather than fully anonymous. Access to it is limited to Listo staff.

Changes to this policy

If we make material changes to this policy, we'll tell you in the app or by email rather than quietly updating the page. The date at the top always reflects the current version.

Questions

We're happy to walk through any of this in more depth: architecture, compliance, or a specific concern. Write to hello@studywithlisto.com.

Listo is currently in beta. Our Terms of Service govern your use of Listo alongside this policy.