Privacy
Last updated: October 2, 2026
Shortlist (shortlist.guide) is operated by Shortlist LLC, a Washington limited liability company. This page explains what data Shortlist collects, what it’s used for, and what is never shared. The shorter answer: Shortlist collects as little as possible to run the site, and never sells what it does collect.
What Shortlist collects
- Email address — collected only when you sign in to save programs. Used to sign you in and to keep your saved programs on any device. You can use the site fully without signing in. What is kept is listed under Your shortlist.
- Program alerts — if you ask Shortlist to watch a program, the details below under Program alerts.
- Provider requests — if you submit a provider for Shortlist to research, your request and email are stored so the team can reply when the listing is added.
- First-party analytics — aggregated page views, link clicks, and feature usage are recorded so Shortlist can see which tools parents actually use, along with how long each page stayed open, your browser’s user-agent string, and approximate location. The last two are used to tell real visitors apart from automated crawlers. These events do not include your email, do not link back to your account, and are not shared with third parties.
What Shortlist doesn’t do
- Your email address and any data tied to it are never sold, rented, or disclosed to third parties.
- No third-party ad networks. No tracking pixels from advertisers, brokers, or social platforms embedded in the site.
- No analytics products that monetize visitor data. No Facebook Pixel, no ad-platform retargeting, no data-broker integrations.
- No tracking cookies beyond what’s required to keep you signed in.
Provider data
Provider information shown on Shortlist comes from public sources — state licensing databases, accreditation directories, provider websites, public job postings, and IRS Form 990 filings for nonprofits — or from data the provider has submitted directly through the Shortlist provider dashboard. See the methodology page for source-by-source detail.
Program alerts
If you ask Shortlist to watch a program, Shortlist keeps:
- your email address;
- the program;
- whether you are still looking or your child goes there;
- your child’s birth month and year, if you give it (never a day);
- when you asked, when you confirmed, and when you stopped.
To run the emails, it also keeps a random code that makes your confirm and stop links work, the list of state reports already on file for the program when you confirmed (so you hear only about new ones), how many confirmation emails and which alert emails have gone out, and which kinds of note you turned off. Each email Shortlist sends is logged with your address, its subject and the time it went, and a copy stays in Shortlist’s Gmail sent mail. The request’s IP address and browser details are not stored with it. Your address is used only for the emails you asked for.
The first email is a confirmation. Alerts start only after you confirm the address, and an unconfirmed request stops working after a week. Diana reads each batch of alerts before it goes out. Emails go out through Google’s Gmail service from diana@shortlist.guide. To check that an address can receive mail, Shortlist looks up its domain (the part after the @) with Cloudflare’s DNS service; the rest of the address is not sent.
Every email has a stop link, and alert emails also work with your mail app’s own Unsubscribe button, which does the same as the stop link in that email. Stopping a program also deletes the birth month kept with it, and “Stop all Shortlist email” stops every program you watch, every question you asked a program, and the newsletter. The age email has a link that deletes the birth month on its own. A stopped request keeps the email address and program, with the date you stopped, so nothing restarts without a new confirmation. To have it removed entirely, email diana@shortlist.guide.
Questions for a program
If you tap “I want to know” on a program’s page and leave your email, Shortlist keeps:
- your email address, once per inbox (Gmail treats dots and anything after a plus as the same inbox, so Shortlist does too);
- the program;
- which questions you asked it;
- when you asked, when you confirmed, and when you stopped.
To run the emails it also keeps random codes that make your confirm and stop links work, how many confirmation emails have gone out, and when the program’s monthly note and your answer email went. The program is told how many parents asked, never who: your email is not passed to it. Each email Shortlist sends is logged with your address, its subject and the time it went, and a copy stays in Shortlist’s Gmail sent mail. The request’s IP address and browser details are not stored with it. Your address is used only for the emails you asked for. Diana reads each month’s program notes and answer emails before they go out.
Your question counts only after you confirm the address from the one email Shortlist sends when you ask. An unconfirmed question stops working after a week. Confirming also confirms a watch of the same program you asked for from the same address, and confirming that watch confirms these questions: one address, one confirmation. Every email has a stop link: “this program” stops your questions and any watch of it, and “Stop all Shortlist email” stops everything, the same as the link in a watch email. A stopped question keeps the email address, program and question, with the date you stopped, so nothing restarts without a new confirmation. To have it removed entirely, email diana@shortlist.guide.
Your shortlist
If you tap Save on a program and sign in, Shortlist keeps:
- your email address, which is your account;
- the programs you save, and when you saved each one;
- if you make a link for your partner, a random code that makes the link work, when you made it, and when you turned it off;
- if you tick “Email me when the state files a new report on a program I save,” when you ticked or unticked it, and for each program on your list what the program alerts below keep: a random code for the stop links, the state reports already on file when you ticked it (so you hear only about new ones), and which alert emails have gone out.
Signing in is run by Supabase, the database service Shortlist uses. To sign you in and keep you signed in, Supabase also keeps when your account was made, when you last signed in, and for each sign-in its time and the device’s IP address and browser details. If you use Continue with Google, it also keeps what Google sends with the sign-in: your name, email address and profile picture link. The Continue with Google button is loaded from Google when the sign-in box opens, so Google receives your device’s IP address and browser details then, along with Google’s own cookies if you are signed in to Google in this browser. The sign-in email goes out through Google’s Gmail service from diana@shortlist.guide, is logged with your address, its subject and the time it went, and a copy stays in Shortlist’s Gmail sent mail. Signing in to save does not add you to any newsletter or email list. If you tick the alert box, Shortlist emails you when the state posts a new report on a program on your list, and on any program you save later. Every one of those emails has a stop link, “Stop all Shortlist email” also unticks the box, and you can untick it on Your shortlist at any time. Removing a program from your list stops its alerts.
Anyone with the link for your partner sees the names of the programs on your list and what each program’s page shows. They see nothing about you: not your email, and nothing that identifies you. They can’t change the list. You can turn the link off from Your shortlist at any time, and anyone who opens it afterwards is told it was turned off. Open in ChatGPT, Claude or Gemini uses the same link: it opens your assistant with a question pointing at a plain-text copy of your list, which carries the same things (the programs and what each program’s page shows) and nothing about you. The assistant’s company receives the question and what it reads, under its own privacy terms. For Gemini, the question is put on your clipboard for you to paste. Turning the link off stops the plain-text copy too. To have your account and list deleted, email diana@shortlist.guide.
Cookies and local storage
Shortlist uses local storage to remember which programs you’ve saved, a program you tapped Save on before signing in, your last-viewed neighborhood, which questions you asked a program from this browser (so its page does not offer them again), and similar preferences. Signing in keeps a sign-in token in this browser’s local storage until you sign out; Shortlist sets no sign-in cookie. There are no advertising cookies and no cross-site trackers.
Data retention
If you sign in and later want your account and saved data removed, email diana@shortlist.guide. Account data and saved-shortlist data are deleted on request. Aggregate analytics events that were never linked to your account are retained as long as they’re useful for product decisions.
Children
Shortlist is built for parents researching childcare; it is not directed at children. Shortlist does not knowingly collect personal information from children under 13.
Changes
If this policy changes, the “Last updated” date at the top of the page changes with it. Material changes will be flagged on the homepage.
Questions
If anything here is unclear, or if you want a copy of any data Shortlist holds about you, email diana@shortlist.guide.
See also: Terms & Disclaimer and Methodology.