This page explains what data ListGen's sign-in service (auth.listgen.com) collects when you log in, refresh your session, or reset your password, and how that data is used. It covers only this sign-in service - it is separate from, and does not replace or modify, any Agent Agreement you have signed with ListGen.
Information we collect
Login credentials. The email and password you enter are sent directly to ListGen's authentication servers to verify your identity. This sign-in service does not store your password at any point.
Session data. Once you're signed in, we store a session record - a session identifier, your ListGen access and refresh tokens, and their expiration times - so you can stay signed in and move between ListGen products without logging in again.
Cookies. We set two cookies in your browser: one identifying your session, and one holding your current access token. Both are httpOnly (not readable by page scripts), transmitted only over HTTPS, and scoped to listgen.com and its subdomains.
Network and device signals. We record the IP address of failed login attempts, temporarily, to detect automated or abusive login activity. We also use Google reCAPTCHA, which independently assesses device and behavior signals to help distinguish real users from bots.
Password reset requests. If you request a password reset, the email address you provide is sent directly to ListGen's servers to send the reset email.
How we use this information
To authenticate you and keep you signed in across ListGen products.
To detect and block automated or bot-driven login attempts.
To process password reset requests.
We do not use this information for advertising, and we do not sell or share it with data brokers or advertising networks.
Third-party services
This site is protected by Google reCAPTCHA, and the Google
Privacy Policy and
Terms of Service apply to reCAPTCHA's own data collection. Aside from reCAPTCHA, this sign-in service does not share your data with any other third party.
Data retention
Session data is retained until you log out or your session expires, whichever comes first.
Failed-login records are kept temporarily (a rolling window of a few minutes) solely to detect abusive activity, and are cleared automatically after that window or on your next successful login.
Your password is never retained - it is forwarded once, for verification, and then discarded.
Security
Credentials are transmitted only over HTTPS. Session cookies are httpOnly and Secure, meaning they cannot be read by page scripts and are only sent over encrypted connections.