Grocelo — Privacy Policy
Last updated: August 23, 2026
Grocelo is an app for keeping shared grocery lists. This page explains, as plainly as possible, what data is collected, where it is stored, and how it can be deleted.
Account: anonymous by default
Grocelo has no sign-up screen. On first launch the app creates an anonymous account for you — no email address, phone number, or password is required or collected at that point. You may optionally enter a display name on the profile screen; it is visible only to the other members of lists you share.
Optionally, you can link your account with Sign in with Apple (profile screen), so you can recover your lists on a new device with the same Apple ID. The app asks Apple for your name only; it does not request or store your email address — you don't even need to decide about "Hide My Email". We never see your Apple ID password.
Data stored on our servers
For the app to work, the following is stored on Google Firebase infrastructure (data centers in Europe):
- Your lists and their items — list name, member list, added products, and details like quantity and notes. On shared lists, this data is visible in real time to all members of the list.
- Your profile — your display name (if you entered one) and the avatar emoji you picked.
- Invite codes — short-lived join codes generated when you share a list.
- Unmatched search terms — when you type a product name we can't find in the catalog, we log the term you typed, associated with your account ID, so we can grow the product catalog. It is used only to improve the catalog.
Data that stays on your device only
The following is never sent to a server and is stored only on your phone:
- Your favorite products
- Your purchase history
- Your pinned lists
If you delete the app, this data is deleted with it.
Usage analytics (Firebase Analytics)
To understand which features are used and improve the app, we collect anonymous usage events — for example "a list was created" or "the search screen was opened". These events carry no list names, no product names, and no personal content, and they are not linked to your identity. They are processed by Google Firebase Analytics and Amplitude, and used only to improve Grocelo — never for advertising.
What we do not collect
- No ads, no advertising identifiers (no IDFA), no cross-app tracking
- No access to location, contacts, or photos
- No personal content in analytics — what you write in your lists stays out of usage events
Subscriptions (Grocelo Gold)
Grocelo offers an optional subscription. Payment is handled entirely by Apple — we never see or store your card or bank details. To know whether your subscription is active, purchase records (product, purchase and renewal dates) are processed by our service provider RevenueCat under your account identifier, so your subscription can follow your account across devices. This information is used only to unlock subscription features and is never used for advertising.
Crash reports (Crashlytics)
If the app crashes, Firebase Crashlytics sends a technical report so we can fix the bug: information such as the code lines where the crash happened, your device model, and OS version. These reports carry no personal content (no list names, no products).
Deleting your data
- Permanent deletion from inside the app: whether your account is anonymous or linked with Apple, the "Delete Account" button at the bottom of the profile screen deletes your account and all of your server-side data yourself. Lists you own and every item in them are deleted, you are removed from lists you joined, and your profile and notification records are erased; your favorites and purchase history are cleared from the device too. It is irreversible and needs no approval from us.
- If you have not linked Sign in with Apple, your account is anonymous and lives only on your device: the session is kept in the device's secure storage (Keychain), so reinstalling the app on the same device may restore it. Once you reset or replace the device, nobody can access the account again (including us). Deleting the app does not delete your server-side data — use "Delete Account" inside the app first if you want that erased too.
- For any question or problem you can reach us at egegirsen.dev@gmail.com.
- When you leave a list, your membership is removed; when you delete a list you own, the list and all of its items are deleted.
Changes
If we add a feature that changes how data is handled (for example, optional account linking or a subscription), we will update this page beforehand. The current version of this policy is always published at this address.
Contact
Questions: egegirsen.dev@gmail.com