Privacy Policy

ListAlert  ·  Effective date: June 1, 2026  ·  Last updated: August 30, 2026

This Privacy Policy describes how ListAlert ("we," "us," or "our") collects, uses, shares, and protects information when you use the ListAlert mobile application and associated services (the "Service"). We are committed to handling your information with transparency and minimal footprint.

The short version. ListAlert stores your grocery list and recipes on your device, and — when you join a household — also syncs them (including recipe photos) to our secure Supabase database so everyone in your household shares one list. We use anonymous authentication — no name or email required. Background location for GPS store alerts is processed on your device and not sent to us; when you search for a store, your location is sent through our server to Google to find nearby results. We do not sell your data. When you tap "Add to Kroger" (or send your list to another supported retailer), only the ingredient names you selected are transmitted to that retailer's platform; we never see your retailer credentials, payment info, or order history.

1. Who We Are

ListAlert is an independent mobile application. For questions about this policy, contact us at info@listalert.app.

2. Information We Collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Information we do NOT collect

3. How We Use Your Information

Purpose Data used Legal basis
Provide the core list, cookbook, and household sync features List items, recipes, household data, anonymous session ID Performance of contract (your use of the app)
Send GPS proximity alerts when you are near a saved store Device location (background), saved store coordinates Your explicit opt-in consent (per-store toggle)
Extract ingredients from photos, URLs, and text via AI Submitted photo or text; no account identity is sent Performance of contract
Hand off a selected ingredient list to a delivery provider Selected ingredient names only Performance of contract / your explicit action
Restore household access (account recovery via magic-link sign-in) Email address (only if you add a recovery email) Your explicit action / performance of contract
Send product updates (waitlist) Email address (only if provided) Your explicit opt-in consent
Diagnose crashes and improve stability Crash reports (no list or location data) Legitimate interest / your OS-level consent

4. Data Storage and Where It Lives

4.1 On your device

The following data is stored on your device in React Native AsyncStorage. Note that your grocery list and saved recipes (including photos) are also synced to our Supabase database when you belong to a household — see Section 4.2:

Your Supabase session token (the JWT used to authenticate requests to our backend) is also stored on your device, in the operating system's encrypted secure storage (iOS Keychain / Android Keystore via expo-secure-store) — the same protection used for Kroger OAuth tokens.

On-device data that is not part of household sync (for example, trip history, allergy and exclusion lists, and store preferences) is not backed up to our servers; if you uninstall the app or clear app data, that local data is deleted. Data that was synced to your household (your list, recipes, and recipe photos) remains in Supabase until removed as described in Section 7.

4.2 In our cloud database (Supabase)

The following data is stored in our Supabase database to enable household sync. It is protected by Row Level Security (RLS), meaning each user can only access data belonging to their own household:

Supabase servers are hosted in the United States. See Supabase's Privacy Policy.

5. How We Share Your Information

We do not sell, rent, or trade your personal information. We share data only as described below:

5.1 Retailer delivery providers — when you initiate a handoff

When you tap a delivery handoff button, only the ingredient names you selected for that specific action are transmitted. No account identity, location, email, or other personal data is included in these transmissions.

Provider What is transmitted How it works What we never send
Kroger Selected ingredient names (up to 50); Kroger OAuth access token (to authorize the cart write) OAuth 2.0 PKCE flow. Your Kroger credentials go directly to Kroger — never to ListAlert. We receive a time-limited access token only, stored encrypted on your device. Kroger username or password, payment info, order history
Instacart (pending IDP approval — not yet available) When enabled: selected ingredient names only, passed via Instacart's IDP handoff Handoff per Instacart's IDP specification. You complete checkout on Instacart's platform. This feature will be enabled only after IDP approval and a subsequent app update. Instacart account credentials, payment info, order or delivery history
Walmart Ingredient names appended to a Walmart.com search URL (browser redirect only) Your browser opens Walmart.com with a search query. ListAlert servers are not involved. Walmart account credentials, payment info, any account data

5.2 AI recipe extraction — Anthropic

When you extract a recipe, the photo or text you submit is sent through our Cloudflare Worker (which verifies your session token and holds our Anthropic API key server-side) to Anthropic's Claude API. Only the submitted content is transmitted — your name, email, user ID, location, and grocery list are not included. Anthropic's use of this data is governed by Anthropic's Privacy Policy. Per Anthropic's API terms, inputs submitted via the API are not used to train models. We do not independently process or use your submitted recipe content for any purpose other than returning the extracted ingredient list to you.

AI recipe images. If you choose to generate an illustrative image for a recipe, the recipe name and prompt are sent through our Cloudflare Worker to Cloudflare's Workers AI image model. The generated image is saved with your recipe (in Supabase Storage and/or on your device). No account identity, email, or location is included in this request.

5.3 Store search — Google Places (via our Worker)

When you search for a grocery store, your search query and your current device coordinates (latitude and longitude) are sent to our Cloudflare Worker, which forwards them to the Google Places API to bias results toward stores near you. Because the request is proxied server-side, Google receives our Worker's IP address rather than your device's IP. See Google's Privacy Policy.

5.4 Infrastructure providers

5.5 Legal requirements

We may disclose your information if required to do so by law or in response to a valid legal process (e.g., a court order or subpoena), or if we believe disclosure is necessary to protect the rights, property, or safety of ListAlert, our users, or the public.

6. Location Data

Location is the most sensitive data type ListAlert touches. Here is exactly how it works:

Apple App Store privacy nutrition label declarations:

7. Data Retention and Deletion

How to delete your data

The fastest way to delete everything is directly inside the app — no request or waiting period required:

  1. Open Stores & Household → Household and tap "Delete my account and data." This immediately and permanently deletes your account and all associated Supabase records — your list, recipes, recipe photos, and household membership. This cannot be undone.
  2. Uninstall the app to remove any remaining on-device data.

If you cannot use the in-app option — for example, you have already uninstalled the app — you can request deletion by email instead:

8. Security

We take reasonable technical and organizational measures to protect your information:

No method of transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.

9. Children's Privacy

ListAlert is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal data. These include:

To exercise any of these rights, email us at info@listalert.app. We will respond within 30 days.

California residents (CCPA / CPRA)

California residents have the right to know what personal information is collected, to delete personal information, to opt out of the sale of personal information (we do not sell personal information), and to non-discrimination for exercising these rights. To submit a CCPA request, use the contact information in Section 12.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where required by law, seek your consent. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

12. Contact

For questions, requests, or complaints about this Privacy Policy or our data practices:

ListAlert
Email: info@listalert.app

We aim to respond to all privacy inquiries within 30 days.