This policy covers the Shopping List Android app (“the app”).
The app works without an account. Your lists, items and autocomplete suggestions live in a local database on your device — we operate no servers, hold no copy of your lists, and cannot access or restore them. Data leaves your device only in these cases: when you actively share a list with another app; through Android’s own device backup to your Google account (controlled in your Android settings; we have no access to it); and, with your consent, individual item or list names inside the analytics events described in section 3 — single names attached to usage events, not a copy of your lists.
Legal basis: your consent (Art. 6(1)(a) GDPR), collected through the consent dialog shown at first start where required.
When ads are shown, Google AdMob processes your device’s IP address, device and app information, and your consent choices (IAB TCF string). Depending on those choices, ads are personalized (using your device’s advertising ID), non-personalized, or served without use of the advertising ID (“limited ads”). See Google’s privacy policy.
Legal basis: your consent (Art. 6(1)(a) GDPR). Analytics is off by default; if you decline, no analytics events are recorded.
With consent, we collect usage events (screens viewed, features used, ads shown) and aggregate statistics (such as list and item counts), together with a per-installation app-instance ID, device model, OS version, app version and language. Some events include the name of the item, list or suggestion involved; we use this to understand how the app is used and to improve the suggestions. The app is not intended for the collection of personal information — please do not enter personal details into item or list names.
Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in detecting and fixing crashes. Crash reports contain the technical state of the app at the time of the crash, device model, OS version, app version and a Firebase installation ID — never your list content. You can object at any time by disabling crash reporting in the app’s settings.
Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in operating and safely rolling out the app. The app fetches configuration values (feature switches, layout parameters) from Google; the request carries a Firebase installation ID, app version, language and device type.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The “Remove ads” purchase is processed entirely by Google Play; we never receive your payment details.
Where the consent dialog applies, you can change or withdraw your consent at any time in the app’s settings. Withdrawal does not affect the lawfulness of processing before it.
The only recipient of the data described above is Google (Google Ireland Limited / Google LLC, USA), acting as our processor for analytics, crash reporting and remote configuration, and under its own policies for advertising and billing. We disclose data beyond this only if legally required. Transfers to Google LLC in the United States are protected by the EU-U.S. Data Privacy Framework and its Swiss-U.S. extension (Google LLC is certified).
Under the GDPR (and, in Switzerland, the Federal Act on Data Protection) you have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest (sections 4 and 5), and to withdraw consent (section 7). You may also lodge a complaint with a supervisory authority — in the EU, your national data protection authority; in Switzerland, the FDPIC.
To exercise your rights, contact [email protected]. Note that the data above is keyed to technical identifiers, not your name — we may be unable to locate records belonging to you unless you can provide those identifiers (Art. 11 GDPR).
Updates will be published at this address with a new effective date; where a change concerns consent-based processing, you will be asked for consent again in the app.