1. Information We Collect
ListApp stores your shopping lists, products, store information, and loyalty card codes locally on your device by default. If you never sign in and never join a group/team, this data stays on your device only and is not transmitted to us.
If you sign in (Google Sign-In or email/password) or join a group to use Premium's shared/team features, some data is sent to and stored on our cloud infrastructure (Google Firebase, hosted on Google Cloud). See Section 3 for exactly what that includes.
The free version uses Google AdMob to serve advertisements. AdMob may collect certain data including:
- Device identifiers (Advertising ID)
- IP address and approximate location
- App usage and interaction data
- Cookies and similar tracking technologies
2. Cookies and Tracking Technologies
The free version of ListApp uses Google AdMob, which may use cookies and similar technologies to deliver relevant advertisements, measure ad performance, and prevent fraud.
You can opt out of personalized advertising at any time via your device settings: Settings → Privacy → Ads → Opt out of Ads Personalization.
3. Third-Party Services and Cloud Data
All versions may use:
- Google AdMob (advertising, free plan only) — Privacy Policy
- Google Play Services and Google Play Billing (in-app purchases) — Privacy Policy
- Google Firebase — Authentication, Cloud Firestore (database), Cloud Messaging (push notifications), Cloud Functions, and Analytics — Firebase Privacy and Security
Premium subscribers do not see third-party advertisements.
When you sign in and use account-based features, the following is sent to and stored in Firebase:
- Account info: your email address, display name, and a unique account ID, managed by Firebase Authentication.
- Push notification token: a device-specific messaging token, so we can deliver notifications (e.g. shared list updates) to your device.
- Purchase verification: when you buy a Premium subscription, your Play Store purchase token is sent to our server-side function to confirm the purchase with Google Play — we do not receive your payment details (card number, etc.), which are handled entirely by Google Play.
- Device registration: Premium accounts are limited to 3 devices; we store a device identifier and device model name per registered device to enforce this.
- Group / team data, if you use it: if you create or join a group, the shopping lists, products, and stores associated with that group — plus the email addresses of members you invite or who invite you — are synced to our servers so all members can see shared data. This data remains on our servers as long as the group exists or until a member's data is deleted on request.
If you don't sign in, or sign in but never join or create a group, your shopping data stays local-only as described in Section 1.
4. Permissions
- Storage: required for Export/Import backup functionality only.
- Camera: required only for scanning loyalty card barcodes via the device camera, on user request.
- Photos: we use the system photo picker to let you select an existing barcode image; ListApp does not request broad photo library access and the picker never shares your other photos with us.
- Internet: required for displaying ads (free version), account sign-in, cloud sync for group/team features, and push notifications.
- Notifications: required to show reminders and shared-list update alerts, on user consent.
5. Data Security
The local database on your device is not encrypted at rest. If your device is lost, stolen, or rooted, someone with physical access and the right tools could potentially read locally stored data (including loyalty card codes and store details); we do not currently store payment or password data locally, since sign-in and payments are handled by Google. App backup to Android's system backup is disabled to reduce this risk. The database export/backup feature also produces an unencrypted file — it is your responsibility to secure exported backup files. Data stored in Firebase is encrypted in transit and at rest by Google's infrastructure, and access is restricted by account-based security rules.
6. Children's Privacy
The App is not directed at children under 13. We do not knowingly collect data from children. Ads served comply with Google's policies for families and children.
7. Data Deletion
You can delete all local data by uninstalling the App or by using the backup/restore feature to overwrite with an empty database. If you have an account with us (signed in and/or part of a group), contact us at privacy@listapp.dev to request deletion of your account data from our servers; leaving a group also removes your access to that group's shared data.
8. Your Rights
Depending on your jurisdiction (including GDPR and CCPA), you may have rights to access, correct, or delete your data. Data that stays local to your device is under your full control at all times. For data we hold in Firebase (account info, group/shared data), contact us at privacy@listapp.dev and we will respond within a reasonable time.
9. Changes to This Policy
We will notify you of significant changes through an in-app notice or update notes on the App Store / Google Play.
10. Contact
Savu Ioana-Alina (Individual Developer)
privacy@listapp.dev
https://listapp.dev