Effective date: October 2, 2026
Jackie's List (“the App”, “we”, “us”) is committed to protecting your privacy. This policy explains what data we collect, why, and how we handle it, in accordance with the General Data Protection Regulation (GDPR).
The data controller responsible for your personal data is Jackie's List. For any privacy-related enquiries, contact us at christos@sudo-ezekiel.com.
Account data: Signing in is optional. If you sign in with Google, we receive your name, email, and profile photo from Google. If you sign up with email, Firebase Authentication stores your email address and a protected form of your password, and sends you a verification email. Your account has a user ID. This is used for authentication and for displaying your profile. Firebase Authentication also uses your IP address to secure sign-in and prevent abuse.
Profile name and photo: You can change your display name and upload a profile photo in Profile. An uploaded photo is stored in Firebase Cloud Storage.
Shopping list data: The lists and items you create are stored locally on your device and, if you sign in, synced to Google Cloud Firestore for cross-device access and sharing. People you share a list with see its items, including the name of whoever added each item. Recipes, meal plans, and pantry items are stored only on your device and are never uploaded.
Shopping presence: When you start shopping a shared list, the other members of that list can see that you are shopping, with your display name and profile photo, and get a notification. This marker is removed when you stop shopping.
Community templates: If you publish a template, its name, category, and items are visible to anyone signed in to Jackie's List, together with your display name. Signed-in users can also report a template; we store which account filed each report.
Feedback: If you send feedback from the App, we store your message, the reply email you enter (or your account email if you are signed in and leave it blank), your user ID if you are signed in, the App version, your device model, Android version, and language setting. Feedback is stored in Google Cloud Firestore and emailed to the developer.
Barcode lookups: When you scan a barcode, the App reads it on your device and then looks the product up in the Open Food Facts database. That request sends the barcode number to Open Food Facts, an independent non-profit, and like any internet request it reveals your device's IP address to them. It does not include your account or your lists. Open Food Facts handles this under its own privacy policy.
Preferences: Your app settings (theme, language, currency, AI opt-in) are stored locally on your device only.
AI features (opt-in only): The AI assistant is off until you turn it on, and it requires signing in. When you use it, the App sends your request to our own server function, which forwards it to Google's Gemini API using our project's key. Depending on the feature, a request contains the text you type, a photo you take or choose (sent as a JPEG image), the names of your pantry items, or nothing beyond the current month. While the assistant is on, the App also learns on your device which items you add most often, and sends up to 20 of those item names with each request to tailor the results; you can see and clear them in Settings. Our server function does not store your requests or the answers. Google processes them under the Gemini API Additional Terms of Service. To enforce fair-use limits, we keep a counter per account of how many AI requests you made today and in the last minute; it holds no request content.
Google Assistant (optional): If you use the optional Google Assistant voice shortcuts (for example, “Hey Google, add milk to my list”), your spoken request is processed by Google Assistant under Google's Privacy Policy. The App only receives the resulting action (such as the list name and item) to carry it out; we do not record or store your voice or the audio of your request.
Usage analytics (Google Analytics for Firebase): The App uses Google Analytics for Firebase to understand how the App is used. The App itself reports only these moments: finishing setup (and whether you continued as a guest, with Google, or with email), creating a list (by hand or from a template), adding an item, creating a share link, joining a shared list, answering the notification permission prompt (allowed or not), being offered the home-screen widget, and turning on the weekly reminder. These events never contain the names of your lists or items or anything else you type. Google Analytics also records some events on its own, such as the first time the App is opened, app sessions and time in the App, app and system updates, notifications received or opened, and completed Google Play purchases (see Optional tips). Each event comes with a random app-instance ID, device and app information (such as device model, operating system version, App version, and language), and an approximate location (country, region, or city) that Google derives from your IP address. Advertising ID collection is turned off, and the App does not send your account ID, name, or email address to Google Analytics.
Crash reports (Firebase Crashlytics): If the App crashes, Firebase Crashlytics sends a crash report so we can find and fix the problem. A report contains the stack trace (where in the App's code the crash happened), the state of the App and the device at that moment (such as device model, operating system version, free memory, and disk space), a random Crashlytics installation ID and Firebase installation ID, and a short record of the analytics events that led up to the crash. It does not contain your lists or your account details.
Optional tips: If you choose to leave a tip in the App, the payment is processed by Google Play under Google's Privacy Policy. The App never sees your payment details and does not store or send a record of your tip itself. Google Analytics for Firebase does record completed Google Play purchases automatically, so a tip appears there as a purchase event with the product, price, and currency.
• We do not collect your advertising ID: it is turned off in Google Analytics
• We do not sell your data or use it for advertising
• We do not display ads
• We do not request or use your device's location (GPS). The only location data is the approximate location Google Analytics derives from your IP address, described in section 2
• We do not send your lists, items, recipes, or anything else you type to Google Analytics or Firebase Crashlytics
Under GDPR Article 6, we process your personal data on the following legal bases:
• Contract performance (Article 6(1)(b)): Processing your account data and shopping list data is necessary to provide the app's core functionality — authentication, sync, and list sharing.
• Legitimate interest (Article 6(1)(f)): Push notifications for changes to shared lists you participate in.
• Legitimate interest (Article 6(1)(f)): Usage analytics and crash reports, so we can see which features are used and find and fix crashes. They contain no list content and are not linked to your account.
• Legitimate interest (Article 6(1)(f)): Reading and answering feedback you send, and keeping AI use within fair-use limits.
• Consent (Article 6(1)(a)): AI features are strictly opt-in. You may withdraw consent at any time by disabling the AI assistant in settings.
• Authentication: To sign you in and identify your account
• Sync: To sync your lists across devices and enable sharing with people you choose
• Push notifications: To notify you of changes to shared lists (you control this per-list)
• Usage analytics: To understand how the App is used and which features to improve
• Crash reports: To find and fix crashes
• Feedback: To read your feedback and reply if you left an email address
We retain your personal data for as long as your account is active. When you delete your account, we delete your profile, your profile photo, your AI usage counter, and the lists you own (with their items), and remove you from lists others shared with you. Some data stays after deletion: community templates you published (with your display name), items you added to other people's lists (with your name), and feedback you sent. Contact us if you want those removed too. Guest users' lists and other content are stored only on their device and are deleted when the app is uninstalled or its data is cleared.
Usage analytics and crash reports are kept by Google, for all users including guests, and are not removed by deleting your account or uninstalling the App. Google Analytics keeps event data for at most 14 months and then deletes it; reports made only of totals may be kept longer. Firebase Crashlytics keeps crash reports and their installation IDs for 90 days.
Your data is stored in Google Cloud Firestore and Cloud Storage, AI requests are answered by Google's Gemini API, and usage analytics and crash reports are processed by Google Analytics for Firebase and Firebase Crashlytics. These services may process and store data on servers located outside the European Economic Area (EEA), including in the United States. Google LLC participates in and complies with the EU Standard Contractual Clauses (SCCs) as the legal mechanism for these transfers, ensuring your data receives an equivalent level of protection. For more information, see Google's Privacy Policy.
Your data is stored in Google Cloud Firestore and Firebase Cloud Storage, which provide encryption at rest and in transit. Access is controlled by Firebase Security Rules that ensure you can only access your own data, lists shared with you, and published community templates. Feedback and AI usage counters cannot be read by any user of the App.
Guest users' lists and other content are stored only on their device and are never uploaded to any server. Usage analytics, crash reports, feedback, and barcode lookups, described in section 2, work for all users, including guests.
We do not sell your data or share it with third parties for their own use. Google processes data on our behalf as our service provider (data processor): Firebase hosts accounts and synced lists, Google Analytics for Firebase handles usage analytics, and Firebase Crashlytics handles crash reports. Google also runs the Gemini API that answers AI requests. Open Food Facts receives the barcode number and your IP address when you look up a product, as described in section 2. Apart from that, data is only shared when you choose to: when you share a shopping list with another user via a share code, when you shop a shared list (other members see that you are shopping), and when you publish a community template.
As a data subject under GDPR, you have the following rights:
• Right of access (Article 15): Request a copy of the personal data we hold about you.
• Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
• Right to erasure (Article 17): Request deletion of your personal data. You can do this directly from Profile → Delete My Account.
• Right to restriction (Article 18): Request that we limit how we process your data in certain circumstances.
• Right to data portability (Article 20): Request your data in a structured, machine-readable format.
• Right to object (Article 21): Object to processing based on legitimate interest, including push notifications, usage analytics, and crash reports.
• Right to withdraw consent: Where processing is based on consent (AI features), you may withdraw it at any time without affecting the lawfulness of prior processing.
The App does not currently have a setting to turn off usage analytics or crash reports. Push notifications can be turned off per list in the App or in your device settings.
To exercise any of these rights, contact us at christos@sudo-ezekiel.com. We will respond within 30 days.
If you believe we are handling your data unlawfully, you have the right to lodge a complaint with your local supervisory authority. In Greece, this is the Hellenic Data Protection Authority (HDPA):
You can delete your account at any time from Profile → Delete My Account. This permanently removes:
• Your user profile and authentication data
• Your profile photo
• All shopping lists you own and their items
• Your membership in lists others shared with you
• Your AI usage counter
Published community templates, items you added to other people's lists, and feedback you sent are not removed automatically; see section 6. Recipes, meal plans, and pantry items are stored only on your device, so they are removed by clearing the app's data or uninstalling the app.
Guest users can clear all data stored on the device by clearing the app's data or uninstalling the app. Usage analytics and crash reports already sent to Google are kept for the periods in section 6.
To delete your account without the app, see Delete your account.
Jackie's List is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at christos@sudo-ezekiel.com and we will delete it promptly.
We may update this policy from time to time. Changes will be posted on this page with an updated effective date. For significant changes, we will notify signed-in users via the app.
Questions? Reach us at christos@sudo-ezekiel.com.