Unlocalized Original Legal Document

Privacy Policy

Last updated: August 16, 2026

This Privacy Policy applies to the Listumi mobile application (herein referred to as the "App") and its associated website located at listumi.com (herein referred to as the "Website"). We are committed to protecting your privacy and ensuring you have a positive experience using our App.

1. Information We Collect

1.1. Information You Provide to Us

  • Profile Information: We do not require you to create an account using an email address, phone number, or social media login. The App uses anonymous authentication. However, you may choose to provide a "Display Name" within the App to identify yourself to other users when collaborating on shared lists.
  • User Content (Local-First): By default, the shopping lists you create and the products you add are stored exclusively on your device's internal storage. We collect and synchronize this data with our cloud servers only when you explicitly choose to share a list with other users. Unshared, private lists remain strictly on your device.
  • Loyalty Cards: Your loyalty card data (numbers, barcode types) is stored exclusively locally on your device. It is not synchronized with our servers and cannot be shared with other users via the "Shared Lists" feature.

1.2. Device Permissions

  • Camera and Photo Library: For the "Loyalty Cards" feature, the App may request permission to use your device's camera or access your photo library to scan barcodes and QR codes. Image processing and code recognition occur exclusively locally on your device. We do not store card photos or transmit them to our servers or third parties.

1.3. Information Automatically Collected

  • Usage Data & Analytics: We use third-party analytics tools (Google Firebase Analytics) to collect data about how you interact with the App. This includes pages viewed, features used, and device information (such as operating system, device model, and unique device identifiers). This data is not linked to your personal shopping lists or loyalty cards.
  • Crash and Diagnostic Data: We use Google Firebase Crashlytics to collect crash reports. If the App crashes, this tool collects data such as the device state, OS version, and stack traces to help us fix bugs.
  • Push Notification Tokens & Technical Data: If you choose to enable push notifications, we collect your device's unique Push Token (such as Apple APNs or Google FCM token), operating system (iOS or Android), and your anonymous user ID. We securely store these technical identifiers in our database (Supabase) strictly for the purpose of delivering real-time service notifications. We never use push tokens for advertising, marketing, or tracking across other apps.

Note: We do not request access to your device's microphone, precise geolocation, or contact book.

2. How We Use Your Information

We use the collected information for the following purposes:

  • To provide, maintain, and improve the App's core functionality (e.g., scanning loyalty cards or real-time syncing of shared shopping lists).
  • To deliver real-time service notifications and collaborative alerts when you interact with shared shopping lists.
  • To monitor and analyze trends, usage, and activities to improve user experience.
  • To detect, investigate, and prevent technical issues and bugs.

3. How We Share Your Information

We do not sell your personal data. We may share your information only in the following situations:

  • With Other Users: If you share a shopping list, your Display Name and the content of that specific list will be synchronized to the cloud and visible to other participants you invited. Private lists and loyalty cards are never shared or synced.
    • Shared Lists and Notification Triggers: When you participate in a shared shopping list, your collaborative actions (such as adding, editing, checking off, or deleting items) may automatically trigger service-related push notifications sent to other participants of that specific list. Similarly, you may receive notifications initiated by other members' actions within shared lists.
  • With Service Providers: We share data with third-party vendors who provide cloud infrastructure and analytics services, including:
    • Supabase: For database hosting, real-time data synchronization of shared lists, and secure storage of Push Notification tokens.
    • Google (Firebase): For analytics and crash reporting.
  • For Legal Reasons: We may disclose your information if required to do so by law or in response to valid requests by public authorities.

4. GDPR Compliance (European Union)

If you are a resident of the European Economic Area (EEA), under the General Data Protection Regulation (GDPR), you have specific rights regarding your personal data.

Legal Basis for Processing:

  • Consent (Art. 6(1)(a) GDPR): We rely on your explicit, voluntary consent (opt-in) to request system permission on iOS/Android, store your device Push Token, and deliver mobile push alerts to your device. You can withdraw your consent at any time in your device settings without affecting core offline functionalities.
  • Performance of Contract (Art. 6(1)(b) GDPR): Cloud data processing, storage, and transmitting collaborative activity events (such as adding or modifying shopping list items) between participants of shared shopping lists are necessary for providing the core list-sharing service you requested.
  • Legitimate Interest: We process technical telemetry (via Firebase) to maintain the security and stability of the App.

5. CCPA, CPRA & CalOPPA (California Rights)

This section applies to residents of California.

  • Categories of Personal Information Collected (Identifiers): We collect technical device identifiers, specifically Push Notification Tokens (APNs/FCM tokens) and anonymous User IDs, strictly for operational business purposes (service delivery and real-time collaboration).
  • "Do Not Sell or Share": We do not sell your personal information or device identifiers. We do not share your Push Tokens or personal information with third parties for cross-context behavioral advertising.
  • Sensitive Personal Information: We do not collect or process "Sensitive Personal Information" (such as geolocation, racial origin, or biometric data) as defined by CPRA.
  • Do Not Track Signals (CalOPPA): We do not track our customers over time and across third-party websites to provide targeted advertising and therefore do not respond to Do Not Track (DNT) signals.

6. Your Data Rights and Data Deletion

You have the right to manage your information. Because Listumi uses anonymous authentication, we do not link your data to an email address or other personal identifiers. The data deletion process works as follows:

  • Local Deletion (Instant): You can delete lists and loyalty cards directly within the App. Uninstalling the App itself or clearing its data in your device settings will result in the permanent deletion of all local data (including loyalty cards) and the loss of access to your current anonymous profile.
  • Push Token Deletion: You can disable push notifications at any time in your device system settings, which immediately stops alert delivery. From a technical standpoint, your Push Token stored in our Supabase database is automatically and permanently deleted when the push notification service (Apple APNs or Google FCM) reports the token as invalid (for example, after the App is uninstalled) or after 6 months of profile inactivity, whichever occurs first.
  • Cloud Deletion (Automatic): To protect your privacy and minimize data, all your shared lists and profile data stored on our cloud servers are automatically and permanently deleted after 6 months of inactivity (no activity in the App).
  • Manual Deletion Requests: Because your anonymous User ID is hidden for security reasons, we do not have the technical ability to identify your data on our servers via an email request. Therefore, we apply a strict automatic deletion policy (after 6 months), and to immediately stop using the service, simply uninstall the App from your device.

7. Children's Privacy (COPPA Compliance)

Our App is not intended for children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we will be able to verify and take necessary actions.

8. Governing Law

This Privacy Policy shall be governed and construed in accordance with the laws of Ukraine, without regard to its conflict of law provisions.

9. Changes to this Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us at: listumi.app@gmail.com