Effective date: July 12, 2026
Allowist ("Allowist," "we," "us") is operated by Default Deny LLC, an Oregon limited liability company. Allowist is a network access management service that keeps firewall IP allow lists current automatically. This policy explains what information we collect, why we collect it, how we protect it, and the choices you have.
Because Allowist's entire purpose is managing IP addresses, this policy is unusually specific about IP address handling. We believe a security product owes you that specificity.
For information about your account, our website, and billing, Default Deny LLC acts as the data controller.
For the information your organization stores in the service — the IP addresses, device names, allow list entries, and recipient details your administrators manage — we act as a processor on your organization's behalf. Your organization's administrators control that data, decide who may access it, and can delete it.
Account information. Name, email address, and profile image (when you sign in with Google or Microsoft, provided by them); a password hash if you use email sign-in (we never store plaintext passwords); multi-factor authentication enrollment data; and single sign-on identifiers if your organization uses SAML.
Organization information. Organization name, plan tier, subscription status, and configuration such as feed settings, security policies, and email template customizations.
Service data — IP addresses by design. The core function of Allowist is recording public IP addresses so your firewalls can allow them. This includes: addresses reported by agents you install on your devices (with the device hostname and agent version); addresses your administrators enter manually; and addresses submitted by recipients of Allow Links, together with the recipient email address or reference label your administrator attached to the link. Allow Link pages display the detected address to the recipient and add it only after the recipient explicitly confirms.
Feed access logs. When a firewall or other client fetches one of your allow list feeds, we log the source IP address, requested format, result, timestamp, and user agent. These logs exist so your administrators can verify which systems consume their feeds and detect misuse of feed tokens.
Audit logs. Administrative actions in the service (adding or removing entries, revealing tokens, changing settings, redeeming Allow Links, and similar events) are recorded with the acting user, the affected resource, the change made, a timestamp, and the administrator's source IP address. Audit logging is a security feature and cannot be disabled by end users.
Payment information. Payments are processed by PayPal. We never receive or store card numbers or bank details. We store your subscription identifier, plan, and payment status as reported to us by PayPal.
Support communications. Messages you send through the in-app support form or the website contact form, including the email address you provide so we can respond.
Website analytics. Our public website uses a cookieless, aggregate page-view counter. It does not build visitor profiles, does not use advertising trackers, and does not follow you across other sites.
Cookies. The application uses an essential session cookie to keep you signed in. We do not use advertising cookies.
We use the information above to operate the service (publishing your allow lists to your firewalls is the product); to authenticate users and enforce your organization's security policies such as required MFA; to maintain security through audit logs, rate limiting, and abuse detection; to process subscriptions and trials; to respond to support requests; to send transactional email such as verification links, invitations, Allow Links, and security notices; and to improve reliability. We do not sell personal information, and we do not use your data for advertising.
We use a small set of infrastructure providers, each for a specific purpose:
We share information with these providers only as needed for the purposes described, and with authorities only where required by law.
Security is the product, and we hold our own infrastructure to the standard we help you enforce.
No system is impenetrable, and we do not promise perfect security. We do promise honest engineering: if an incident affects your data, we will notify affected organizations without undue delay.
Account and organization data is retained while your account is active. Audit log retention follows your organization's plan tier. Feed access logs are retained on a rolling window for operational and security review. When an organization is deleted by its administrator, its allow lists, entries, agents, audit records, and Allow Links are deleted; residual copies in encrypted backups expire on the backup rotation schedule. Expired allow list entries and expired or used Allow Links become non-functional immediately upon expiry.
You can view and update your account information in the application. Organization administrators can export data, remove members, and permanently delete the organization from Organization Settings. Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of your personal information, or to object to certain processing; to exercise them, contact us at [email protected] and we will respond as required by applicable law (including, where applicable, the GDPR and the CCPA). If you interact with Allowist because an organization sent you an Allow Link, that organization controls the associated record; we will direct requests to them or assist as processor.
Allowist is a business service and is not directed to anyone under 16. We do not knowingly collect personal information from children.
Allowist is operated from the United States, and information is processed and stored in the United States.
If we make material changes, we will post the updated policy here, update the effective date, and notify signed-in administrators through the application. Continued use of the service after changes take effect constitutes acceptance.
Default Deny LLC — Allowist Portland, Oregon, United States [email protected]