Introduction
This privacy policy governs your use of the mobile application Shopping List & Notes (also known as Kauppalista & Muistiinpanot).
Summary
- Most app features work without creating an account.
- Your local shopping lists and notes are primarily stored on your own device.
- AI features and shared list collaboration are optional.
- Google Sign-In is only required when using shared collaborative lists.
- Push notifications are optional and can be disabled from device/app settings.
- Limited technical and collaboration-related data may be processed to provide shared list features and protect the service from abuse.
Data Collection and Usage
The application is designed with an offline-first and privacy-first approach. Most everyday usage does not require creating an account.
Local shopping lists, notes, favorites, preferences, and similar personal content are primarily stored locally on your device.
If you choose to use optional shared list collaboration features, certain shared list data is stored securely using Firebase services to enable realtime synchronization between members.
Shared Lists & Collaboration
The application offers optional shared shopping lists and shared task lists. These features allow multiple users to collaborate in realtime.
Shared collaboration features require optional Google Sign-In authentication. When using shared lists, the following information may be processed:
- Google account identifier
- Display name
- Email address
- Google profile photo URL, if available
- Shared list content and item updates
- Member roles and permissions
- Notification preferences related to shared lists
This data is used solely to provide collaboration functionality, realtime synchronization, member display, invitations, and notifications between shared list members. The app does not upload profile image files; if a profile photo is shown, it uses the profile photo URL provided by Google/Firebase authentication.
AI Features (Meal Suggestions & Weekly Meal Plans)
The application includes optional AI-powered features, such as meal/recipe suggestions and weekly meal plans.
When you use these features, the text you provide (for example: preferences, allergies/restrictions, servings, meal wishes, or planning details) may be transmitted to a secure backend service solely for generating the requested AI response.
AI request content is not used for advertising or cross-app tracking.
Push Notifications
If enabled, the application may use Firebase Cloud Messaging (FCM) to deliver shared list notifications such as:
- Shared list invitations
- Item additions or edits
- Shared list updates
- Member activity notifications
Notification settings can be managed from your device settings and from within the application where applicable.
Security & Anti-Abuse (App Check, Play Integrity, Rate Limiting)
To protect the application and backend infrastructure from abuse, fraud, spam, or unauthorized access, technical verification systems may be used.
- Firebase App Check token (to verify requests originate from a legitimate app instance).
- Google Play Integrity token + nonce (to help detect tampered or untrusted environments).
- Technical client identifiers (used for abuse prevention and usage limits).
- Request counters and timestamps (used for security monitoring and rate limiting).
These systems are used solely for security, reliability, and abuse prevention purposes. They are not used for advertising profiling or third-party tracking.
Voice Input (Speech-to-Text)
The app may offer voice input for adding items. Speech recognition is provided by your device’s speech recognition service (for example Google Speech-to-Text on Android). Depending on your device settings and language packs, speech recognition may require an internet connection and may be processed by the provider of the speech recognition service.
Third-Party Services
The application may use third-party services including:
- Firebase Authentication
- Firebase Firestore
- Firebase Cloud Messaging (FCM)
- Firebase App Check
- Google Play Integrity
- AI service providers used to generate requested AI results
These services are used only for the functionality, security, and operation of the application.
Data Retention
Most local app data remains stored on your device unless you use optional cloud or collaboration features.
Shared collaboration data may remain stored while shared lists are active in order to provide synchronization and collaboration between members.
Limited technical and anti-abuse records (such as technical identifiers, request counters, timestamps, and notification tokens) may be stored temporarily for security and service protection purposes.
What We Do NOT Collect
- The app does not sell your personal data.
- The app does not use third-party advertising SDKs.
- The app does not perform cross-app behavioral tracking.
- The app does not build advertising profiles about users.
AI Content Disclaimer
AI-generated suggestions are intended for informational and inspirational purposes only.
AI-generated content may occasionally be incomplete, inaccurate, or contain mistakes. Users should apply their own judgment and verify important information independently where appropriate.
AI-generated content does not constitute medical, nutritional, legal, or professional advice.
Changes
This Privacy Policy may be updated from time to time. Any changes will be published on this page.
Contact
If you have any questions regarding privacy or data protection, please contact: janstech.apps@gmail.com