Get them back: 10 AI skills for the list you already own
list-build
collect emails lawfully, without annoying anyone
How the two work together
Claude thinks it through. Paste the Claude prompt into Claude Code, or drop the folder into your skills folder. Claude does the judgement: what to look for, what is worth doing, what is right.
Codex gets it done. At the hand-off point Claude runs Codex on your machine with one command and passes it the Codex prompt. Codex does the mechanical part and hands the result back. Claude checks it before you see it.
No API key to set up: Claude calls the Codex you already have installed. If Codex is not installed, Claude does that half itself and tells you.
Prompt for Claude
--- name: list-build description: Turns the email addresses your business already touches into one list you are lawfully allowed to email, with the route recorded against every address. Use when you want to start emailing customers and are not sure which addresses you may actually use. --- # Build the one list you are allowed to email, without annoying anybody You give this the places your business already collects an email address: the booking system, the till, the wifi login, the gift voucher page, the Christmas enquiry inbox, the box of business cards behind the bar. You get back one file with every address, the lawful route it sits on, the exact words the person saw when they gave it, the date, and a second file of the addresses you must not use and why. It never tells you to buy a list. ## What it does 1. **Sort every address you already hold into one of three routes before you collect a single new one.** Route A is consent: they actively ticked a box or clicked a button to receive your emails. Route B is the soft opt-in, which regulation 22(3) of the Privacy and Electronic Communications Regulations allows where "that person has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient", the marketing is for "that person's similar products and services only", and they were given a simple free way to refuse both at collection and in every message since. Route C is corporate subscribers: a limited company, LLP, Scottish partnership or government body, where the ICO says "You can email or text any corporate body". Everything that fits none of these is route D, do not send. A diner who left a card with the waiter is route D. A supplier's sales rep who emailed you a quote is route D. 2. **Test route B against all five requirements, not the one you remember.** The ICO breaks the products and services soft opt-in into five: you obtained the details directly from that individual subscriber; you did it during a sale or negotiations for a sale, meaning "they must have bought something from you or have actively expressed an interest in buying"; the marketing is for your similar products and services; you gave a clear simple opt-out at the moment you collected the details; and you give an opt-out in every message after. A table booking that was honoured is a sale. A booking enquiry that asked about a private dining price is negotiations for a sale. A wifi login is neither, so wifi addresses are never route B. If you cannot evidence the fourth requirement, the opt-out at collection, the address drops to route D even if the person is a regular. 3. **Check whether each address belongs to a person or to a company, because the answer changes the rule.** The ICO is explicit that "Sole traders and some partnerships are treated as individuals", so the chef who trades as a sole trader has the same protection as a private diner. A named employee at a limited company is a corporate subscriber for the electronic mail rules, and CAP Code rule 10.14 says "Consent is not required when marketing business products by fax or by electronic mail to corporate subscribers (see III j), including to their named employees", but it adds that you must still screen against suppressions and still offer opt-outs. Mark the route on the row, never on the whole list. A hotel's corporate bookings list and its weddings list are two different legal populations sitting in one spreadsheet. 4. **Write the wording that sits next to the box, and keep it out of the terms and conditions.** The ICO requires consent requests to be "prominent, concise, easy to understand and separate from any other information such as general terms and conditions", and says you cannot rely on "silence, inactivity, pre-ticked boxes, opt-out boxes, default settings or a blanket acceptance of your terms and conditions". Draft one line per collection point naming your business, what you will send, and roughly how often: "Yes, email me the monthly menu change and one offer a month from The Fox, Hackney. Unsubscribe any time." A tick box that says "I agree to the terms" is not consent and never was, even where the terms mention marketing. 5. **Name every collection point that actually exists in a hospitality business and say what each one produces.** Walk the building and the software: the booking system's guest record, the deposit or pre-authorisation email, the EPOS emailed receipt, the gift voucher checkout, the function and Christmas enquiry inbox, the online ordering account, the review request, the wifi captive portal, the feedback QR on the table, the tasting or quiz night sign-up sheet. For each one, write down whether it is a sale, a negotiation for a sale, or neither, and whether an opt-out box was shown at the time. Most kitchens find two or three genuine route B sources and four or five route D sources they had assumed were fine. The wifi portal is the one that catches people out most often. 6. **Confirm the address before you count it.** Send one plain confirmation message asking the person to click to confirm, and only move them into the sending list when they do. Yahoo's sender requirements page recommends exactly this: "When users subscribe to your mailing list, send them an email asking them to click to confirm their opt-in. This will improve the experience for users (who won't sign up accidentally or get signed up maliciously) and for your list (which won't contain uninterested people, fake email addresses, or most robots)." Google's sender guidelines say the same in one line: "Confirm each recipient's email address before subscribing them." A typed address on a paper sheet at a quiz night is wrong about one time in ten, and every bounce damages the reputation that decides whether your next email reaches anybody. 7. **If you build the list with a prize draw, run it to the promotions rules or do not run it.** CAP Code rule 8.28 requires prize promotions to specify, clearly before or at the time of entry, any restriction on the number of entries, whether cash may be substituted, how and when winners will be notified, and the date prizewinners will get their prizes if it is more than 30 days after the closing date. Rule 8.15.1 requires prizes to be awarded "normally within 30 days". Rule 8.17.9 requires the promoter's full name and correspondence address. And the entry mechanic must not make marketing consent the price of entry: the ICO says consent must be "freely given", with genuine choice, and warns against "unduly incentivising people to consent". Offer the draw and the marketing tick separately on the same form. 8. **Screen the finished list against your own do-not-contact list before anything is sent.** The ICO tells you to keep a suppression list rather than deleting people who opt out, and gives the reason plainly: a company that deleted a number instead of suppressing it bought the same number back on a screened list months later and called it again, which "has breached PECR". Run every new address against suppressions, including addresses that arrived through a booking platform, and keep the suppression entry to the minimum, usually the address and the date. Deleting someone who opted out is how you email them again next year. 9. **Produce two files and a one-page note.** File one, `email-list.csv`, one row per address with columns: email, first name, route (A, B, C or D), collection point, date collected, exact wording shown, opt-out offered at collection (yes or no), confirmed (yes or no), last transaction date, suppressed (yes or no). File two, `do-not-use.csv`, every route D address with the single reason it cannot be used and what would have to happen for it to become usable. The note names how many addresses you hold, how many are actually sendable today, and the three changes to your collection points that would move the biggest group across. The number of sendable addresses is usually between a third and a half of what the owner thought they had, and the file is worth more than the assumption. ## Then it checks 1. Every row carries a route of A, B, C or D, a named collection point and a date, with no row left blank and no row reading "probably fine" or "from the system". 2. Every route B row can name all five soft opt-in requirements as met, including the opt-out shown at the moment of collection, and any row that cannot is moved to route D rather than kept with a note. 3. No address on the sendable list came from a purchased list, a rented list, a scraped website, a data broker, an appended third-party source or a friend's list, and no address was traced after a bounce. 4. The exact wording column contains the words the person actually saw, copied from the form, the sign-up sheet or the booking flow, and not a description of them. 5. Every address on the sendable list has been screened against the do-not-contact list, and every previously unsubscribed address appears in `do-not-use.csv` rather than being absent. 6. Sole traders and partnerships are marked as individuals and not as corporate subscribers, and no row is marked route C on the strength of the email address looking like a business one. Any check fails: name it, redo that step once. Failed twice: say what is wrong and stop. ## Rules - Public information only. - Never invent a fact, a number or a quote. - Anything sent in someone's name says whose name it is. - Never buy, rent, scrape or append an address, and never trace a new address for someone whose old one bounced. The ICO says you "should not seek out new contact details from other sources or use the tracing services of other organisations for direct marketing", and a bought list also puts every address you own at risk, because one spam report from a stranger is scored against the same sending domain your real customers receive. - Never put a marketing tick box behind a prize, a discount or a wifi login in a way that makes it the price of the thing. Consent taken that way is not freely given, so the address it produced cannot be used, and you will have annoyed the person as well as wasted the sign-up. - Never carry an address from one business to another, even where the same owner runs both. A guest who gave their address to the hotel did not give it to the sister restaurant, and the ICO requires the consent request to name "the name of your organisation and the names of any other controllers who will rely on the consent". - This output is a working document prepared for the owner's solicitor or data protection adviser to check before the list is used. It sorts addresses against published guidance and states what was recorded; it is not legal advice on your own compliance. ## Built from - The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22, https://www.legislation.gov.uk/uksi/2003/2426/regulation/22, in force text showing amendments made 5 February 2026, read 14 September 2026: the statutory wording of the consent rule and the three-part exception, which is the whole of steps 1 and 2. - Information Commissioner's Office, "Electronic mail marketing", Guide to PECR, https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/electronic-and-telephone-marketing/electronic-mail-marketing/, no publication date shown on the page, read 14 September 2026: the corporate subscriber position and the sole trader trap in step 3, and the checklist behind step 8. - Information Commissioner's Office, "Plan direct marketing", Direct marketing and PECR guidance, https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/plan-direct-marketing/, latest update shown 20 August 2025, read 14 September 2026: the five requirements of the products and services soft opt-in used in step 2, and the freely given test in step 7. - Information Commissioner's Office, "Collect information and generate leads", https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/collect-information-and-generate-leads/, no publication date shown on the page, read 14 September 2026: the due diligence list that makes bought lists impractical, and the ban on tracing new details after a bounce, which is why step 5 and the rules are written as they are. - Committee of Advertising Practice, CAP Code (Edition 12), Section 10 "Use of data for marketing" and Section 8 "Promotional marketing", https://www.asa.org.uk/type/non_broadcast/code_section/10.html and https://www.asa.org.uk/type/non_broadcast/code_section/08.html, no publication date shown on the pages, read 14 September 2026: rule 10.14 on corporate subscribers in step 3, and rules 8.15.1, 8.17.9 and 8.28 in step 7. - Yahoo, "Sender Best Practices", Sender Hub, https://senders.yahooinc.com/best-practices/, no publication date shown on the page, read 14 September 2026, and Google, "Email sender guidelines", https://support.google.com/a/answer/81126, no publication date shown on the page, read 14 September 2026: the confirmation step in step 6, in the mailbox providers' own words.
Prompt for Codex
# list-build ## You are given A folder from one UK hospitality business holding every place an email address has ever been collected: a booking system export, an EPOS or till export, a wifi portal log, a gift voucher checkout export, the Christmas and function enquiry inbox, an online ordering export, a review request list, photographs of paper sign-up sheets from a quiz night, and a spreadsheet somebody keeps behind the bar. Plus screenshots or copies of the sign-up wording at each collection point, the existing suppression or do-not-contact list, and a plain-text note from the owner saying, for each collection point, whether it was a sale, a negotiation for a sale or neither, and whether an opt-out was shown at the moment of collection. Column names differ between every file and dates are in mixed formats. ## Produce Write into a `./list-build-output/` folder. Every file whose name carries `PERSONAL-DATA` holds contact details and is stored, moved and deleted as personal data. 1. `email-list-PERSONAL-DATA.csv` with these columns in this order: `email_lower`, `first_name`, `route`, `subscriber_type`, `collection_point`, `date_collected`, `exact_wording_shown_verbatim`, `opt_out_offered_at_collection`, `confirmed`, `last_transaction_date`, `suppressed`, `source_file`, `source_row`. `route` is exactly one of `A-consent`, `B-soft-opt-in-PECR-22(3)`, `C-corporate-subscriber`. `subscriber_type` is exactly one of `individual`, `sole trader or partnership treated as individual`, `corporate subscriber`. `opt_out_offered_at_collection`, `confirmed` and `suppressed` are `yes` or `no`. 2. `do-not-use-PERSONAL-DATA.csv` with the same columns in the same order, plus `reason` and `what_would_have_to_change`. Holds every route D address. `reason` is exactly one of `no lawful route recorded`, `soft opt-in limb not met`, `no opt-out shown at collection`, `wording not supplied`, `date of collection not recorded`, `on the suppression list`, `address not confirmed`, `address malformed`, `duplicate with conflicting route`, `source is a purchased, rented, scraped or appended list`. 3. `soft-opt-in-test.csv` with columns: `email_lower`, `obtained_directly_from_this_individual`, `during_a_sale_or_negotiation_for_a_sale`, `marketing_is_similar_products_and_services`, `opt_out_given_at_collection`, `opt_out_given_in_every_message_since`, `all_five_met`, `limb_that_failed`, `source_file`. One row per address considered for route B. Every row where `all_five_met` is `no` appears in `do-not-use-PERSONAL-DATA.csv`. 4. `collection-points.csv` with columns: `collection_point`, `what_it_produces`, `sale_negotiation_or_neither`, `opt_out_shown_at_collection`, `exact_wording_shown_verbatim`, `wording_source_file`, `addresses_read`, `addresses_to_route_A`, `addresses_to_route_B`, `addresses_to_route_C`, `addresses_to_route_D`. 5. `exceptions.csv` with columns: `source_file`, `source_row`, `field_missing_or_unreadable`, `raw_value`, `reason`. Holds every row that could not be placed at all, and every field that could not be read. 6. `counts.txt` - rows read per source file, distinct addresses after deduplication, the count on each of routes A, B, C and D, the suppression matches removed as its own number, the addresses sendable today, and a line stating whether the four route counts sum to the distinct address count. ## Rules - Codex writes files only. Never send an email. Never connect to an email platform, a marketing API, a booking system API or any sending service to send, schedule, queue or import. Never add anybody to a list, an audience or a segment anywhere. - Never scrape, guess, construct, correct or complete an email address. Never derive an address from a name and a company domain. Never look up a new address for anybody whose old one bounced. - Never buy, rent, append or accept a purchased or brokered list. An address from such a source goes to `do-not-use-PERSONAL-DATA.csv` with the reason set, and never onto the send list. - Never infer a route. A route is assigned only where the supplied note or the supplied wording evidences it. Anything else is route D. An address that looks like a business one is not route C without the subscriber type being evidenced, and a sole trader or partnership is `individual`. - `exact_wording_shown_verbatim` carries the words the person actually saw, copied from the form, sheet or booking flow. Never write a description of the wording, never paraphrase it, and never reconstruct it. Missing wording sends the row to route D. - Deduplicate on lowercase trimmed email address. Where duplicates disagree on route, collection point or date, keep neither: send both to `do-not-use-PERSONAL-DATA.csv` with the reason `duplicate with conflicting route`. - Screen every address against the supplied suppression list on lowercase trimmed address before counting. Never delete a suppressed address, and never leave it out of the output. - Never carry an address from one business, site or brand to another, even where the same owner runs both. - Every date, route and wording must trace to a supplied input file named in the row. Never fill a gap from what is likely. - Use British English, £ where money appears and DD Month YYYY dates in `counts.txt`. No em dashes. - Every file ends with this line: this is a working document prepared for the owner's solicitor or data protection adviser to check before the list is used. It sorts addresses against what was recorded and is not legal advice or a finding of compliance. ## Return The absolute path of each file written, the row count of each CSV, rows read per source file, the distinct address count, the count on each of routes A, B, C and D with the sum check stated explicitly, the suppression matches removed as a separate number, the addresses sendable today, the breakdown of `do-not-use-PERSONAL-DATA.csv` by reason, and the three collection points producing the most route D rows. Name any input file you could not parse and why rather than skipping it silently.
Built from the best public work on this
Sources for list-build
Everything below was opened and read on 14 September 2026. Nothing is cited that could not be loaded.
1. The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22
https://www.legislation.gov.uk/uksi/2003/2426/regulation/22, the in-force text as shown on legislation.gov.uk, carrying amendments commenced 5 February 2026 by the Data (Use and Access) Act 2025, read 14 September 2026.
This is the statute itself and it is short enough to read in full, which matters, because almost everything written about email marketing law is a paraphrase of these six sentences. Regulation 22(2) says a person "shall neither transmit, nor instigate the transmission of, unsolicited communications for the purposes of direct marketing by means of electronic mail unless the recipient of the electronic mail has previously notified the sender that he consents for the time being to such communications being sent". Regulation 22(3) then sets out the exception in three limbs: the sender "has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient"; "the direct marketing is in respect of that person's similar products and services only"; and the recipient "has been given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) the use of his contact details for the purposes of such direct marketing, at the time that the details were initially collected, and, where he did not initially refuse the use of the details, at the time of each subsequent communication".
Three things in the skill come straight from that text. The route sort in step 1 exists because the statute offers exactly two lawful positions for an individual subscriber and nothing in between. The words "at the time that the details were initially collected" are why step 2 treats the opt-out at collection as a hard requirement rather than a nicety. And "similar products and services only" is why a restaurant may email its diners about the new menu but not about the owner's letting agency.
Where the skill departs: regulation 22 applies only to "individual subscribers", which is why it says nothing about companies, and a reader who stops here concludes wrongly that business addresses are ungoverned. They are not, because the UK GDPR still applies to a named person at a company. The skill therefore never treats a corporate route as a free pass, and step 3 keeps corporate rows marked rather than merged.
2. Information Commissioner's Office, "Electronic mail marketing" (Guide to PECR)
https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/electronic-and-telephone-marketing/electronic-mail-marketing/, no publication date shown on the page, which carries a notice that the guidance "is under review and may be subject to change" following the Data (Use and Access) Act, read 14 September 2026.
The regulator's plain-English version of regulation 22, and the source of the distinction that trips up most owners. On companies it says "You can email or text any corporate body (a company, Scottish partnership, limited liability partnership or government body)", but immediately before that it warns "Sole traders and some partnerships are treated as individuals". In a hospitality supplier or trade list, sole traders are a large minority and their addresses look identical to a company's, so step 3 makes the route a per-row judgement rather than a list-level one.
The page also supplies the framing for step 8. Its checklist includes "We keep a 'do not contact' list of anyone who opts out or unsubscribes from our electronic mail" and "We screen against our 'do not contact' list". And it closes off two ideas an owner might otherwise think are clever: "We don't ask or encourage people to forward our electronic mail marketing to their friends or family" and "We don't ask people to give us the contact details of their friends and family to use for electronic mail marketing". Refer-a-friend, in other words, is not a list-building route, and the skill does not offer it as one.
Where the skill deliberately departs: the ICO's page says it is "good practice" to keep a do-not-email list for companies that object. The skill treats that as mandatory rather than optional, because the practical consequence of ignoring a company's objection is a spam complaint scored against your sending domain, and the mailbox providers do not care whether the complainant was a corporate subscriber.
3. Information Commissioner's Office, "Plan direct marketing"
https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/plan-direct-marketing/, part of the direct marketing guidance whose sibling pages show a latest update of 20 August 2025, read 14 September 2026.
This is where the soft opt-in is taken apart properly. The ICO writes that "The term 'soft opt-in' is not used in PECR, but is commonly used to describe two exceptions", and then lists the five requirements of the products and services exception, including the one that step 2 leans on: the sale-or-negotiation limb means "they must have bought something from you or have actively expressed an interest in buying your products or services (eg by asking for a quote or more details of what you offer)". That sentence is what lets a Christmas party enquiry count and stops a wifi login counting.
The page also carries the worked example the skill copies in shape if not in words: a retailer with an opt-out box reading "I do not want to receive marketing emails about your clothing ranges", an unsubscribe line in every email, and the ICO's conclusion that "The retailer is complying with the products and services soft opt-in requirements of PECR."
On consent it adds the test used in step 7: consent must be "freely given", people "must be able to refuse consent without detriment", and while "there's usually some benefit of consenting to direct marketing, such as access to special offers, it is important to avoid unduly incentivising people to consent". Where the skill goes further than the source: the ICO does not say a prize draw entry cannot be conditional on marketing consent, it says over-incentivising is a risk. The skill takes the harder line and separates the two ticks, because an owner cannot easily judge where incentive becomes undue, and the separated version costs nothing.
4. Information Commissioner's Office, "Collect information and generate leads"
https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/collect-information-and-generate-leads/, no publication date shown on the page, read 14 September 2026.
The chapter that makes bought lists and data appending look, in writing, like what they are. It sets out nine questions you must answer before using a third party's list, including "What records of the consent are there (if it is 'consented' information) - what did people consent to, what were they told, were you named, when and how did they consent?" and states that "It is not enough to simply accept a third party's assurances". A restaurant owner cannot answer those questions about a broker's list, which is why the skill's rule against bought lists is written as a practical impossibility rather than a moral position.
It is also the source of the bounce rule. The ICO writes that "You should not seek out new contact details from other sources or use the tracing services of other organisations for direct marketing", and that even where someone previously consented at an old address, "this consent is not transferrable to a new address that they didn't give you". Its university example, where mailings come back undelivered and the university marks the address do-not-use rather than tracing, is the model for what the skill does with a bounced row.
Where the skill departs: the ICO allows a disproportionate effort exception to some transparency duties. The skill does not offer it. A business with a few thousand addresses cannot credibly claim disproportionate effort, and offering the exception to an owner who would misuse it is worse than not mentioning it.
5. Committee of Advertising Practice, CAP Code (Edition 12), Sections 8 and 10
https://www.asa.org.uk/type/non_broadcast/code_section/08.html and https://www.asa.org.uk/type/non_broadcast/code_section/10.html, no publication date shown on either page; Section 10 carries a note that the data rules are "presently under review" in light of the Data (Use and Access) Act 2025, read 14 September 2026.
Section 10 restates the electronic mail position in advertising-code form at rule 10.6 and then adds the corporate carve-out at 10.14: "Consent is not required when marketing business products by fax or by electronic mail to corporate subscribers (see III j), including to their named employees. Marketers must nevertheless comply with rule 10.10 and offer opt-outs in line with rules 10.6 and 10.7." That second sentence is the half people quote less often and it is the half that shapes step 3.
Section 8 is what makes a prize draw a workable list-building tool rather than a complaint. Rule 8.15.1 requires promoters to "award the prizes as described in their marketing communications or reasonable equivalents, normally within 30 days", rule 8.17.9 requires the promoter's full name and correspondence address, and rule 8.28 lists what must be stated clearly before or at the time of entry. Section 8's own background note also warns that promoters "should take legal advice before embarking on promotions with prizes... to ensure that the mechanisms involved do not make them unlawful lotteries (see the Gambling Act 2005 for Great Britain)", which is why the skill's final rule hands the draw mechanics to the owner's adviser rather than ruling on them.
Best public prompt we found for this job
The closest useful public artefact is not a prompt but a working system: `knadh/listmonk`, the self-hosted newsletter and mailing list manager, at https://github.com/knadh/listmonk. The repository has 23,410 stars, read from api.github.com on 14 September 2026. Its concepts documentation, fetched raw at https://raw.githubusercontent.com/knadh/listmonk/master/docs/docs/content/concepts.md, models a subscriber's relationship to a list as exactly three states, and the line worth copying is the definition of the first:
`unconfirmed` | The subscriber was added to the list directly without their explicit confirmation.
That is the right data model and almost nobody keeps it. Most owners hold one column called "email" and treat every row in it as equivalent, which is how a wifi address and a consented subscriber end up in the same send. listmonk forces the distinction into the database, and the skill's route column is the same idea done in a spreadsheet.
What we did not copy: listmonk's states describe what the subscriber did with the confirmation email, not what they were lawfully collected under, so a bought list imported into listmonk produces thousands of perfectly tidy `unconfirmed` rows and tells you nothing about whether you may send to them. The route column therefore records the legal basis and the collection point, which listmonk has no field for. We also did not copy its single opt-in mode, which will happily send to `unconfirmed` subscribers. Under regulation 22 that mode is only safe on a route B or route C population, and the software cannot tell which one you have loaded.
Want this running in your business?
I optimise how businesses run — your sales, your visibility, your social media — and build bespoke software where nothing off the shelf fits. The first conversation is free. Work starts from £150 a day.
Foxera