Privacy Policy
Effective date: September 22, 2026
The short version. The {List} app has no analytics, no advertising, no tracking, and no server run by us. Your data lives on your iPhone first; if you choose to sign in with Apple, your lists, categories, items, profile, and settings also sync to your own private iCloud — never to us, and we have no way to see it. Nothing you enter is sold or shared. This website separately uses cookieless, aggregate-only visit counting (section 6) — unrelated to the app, and not personally identifying.
This policy explains how the {List} iPhone app and the website at list.shahyari.com handle information. Both are operated by Hossein Shahyari (“we”, “us”), Südostallee 122, 12487 Berlin, Germany — the “controller” for the purposes of the EU General Data Protection Regulation (GDPR). Full contact details are in the Impressum.
1. Information the app stores on your device
Everything you create in {List} is written to your iPhone’s own storage first, always — the app works fully offline whether or not you ever sign in:
- Your shopping lists, categories, and items — including names, icons, quantities, units, and prices.
- Your history log: which lists, categories, and items were added, edited, or deleted, together with the time and the profile name attached to the change.
- Your profile: the name and email address you choose to type in, and your profile photo.
- Your settings: language, currency, and appearance.
Technically, this data is kept in the app’s standard local storage (iOS UserDefaults) and, for your profile photo, in a file inside the app’s private Application Support folder. Both live inside the app’s sandbox on your device.
2. Optional iCloud sync (Sign in with Apple)
Signing in is optional and the app works fully without it — nothing below happens unless you choose Sign in with Apple yourself, from the Profile tab.
If you do sign in:
- The app receives a stable identifier issued by Apple for your account.
- Apple provides your name and email address only on the very first sign-in. That is how Sign in with Apple works; the app does not ask for them again afterwards. If you use Apple’s “Hide My Email” option, we would only ever see the relay address Apple generates.
- Your lists, categories, items, profile (name and photo), and settings sync to your own private iCloud database, via Apple’s CloudKit — automatically when you open the app, when you return to it, and on demand with a “Sync Now” button. This is your private database, tied to your Apple ID; it is not a database we run, and we have no access to it, the same as before you signed in.
- Your activity history log and lifetime statistics (like totals of items checked or money spent) do not sync — they stay local to each device, by design, so one device can’t silently overwrite another’s.
Signing out again only affects this device: it stops that device from syncing, but does not delete what’s already in your iCloud — signing back in (on this device or another) picks it back up. See section 9 for what happens if you delete your account entirely, which is different.
3. Information we collect
None. There is no backend service run by us behind {List} — no accounts on our side, no database of ours, no log of what you do in the app. When you sign in and sync, your data goes to your own private iCloud database, governed by Apple, not to any server of ours. Because there is nowhere for your data to come to us, we do not receive it.
4. What the app does not do
- No analytics or crash-reporting SDKs of any kind.
- No advertising, ad networks, or ad identifiers.
- No tracking, and no sharing of data with data brokers or any other third party.
- No third-party SDKs at all — iCloud sync (section 2) is Apple’s own first-party framework, not a third party.
- No selling of personal information, under any definition of “sell”.
- No cookies — {List} is a native app, not a web page.
The app ships with Apple’s required privacy manifest, declaring no tracking and no data collected by the developer — which stays accurate even with iCloud sync, since that data goes to your own Apple-governed private database rather than to us. See the note at the top of this document for the one related App Store Connect step this still requires.
5. Apple’s role
{List} is distributed through the App Store, and, if you sign in, syncs through Apple’s CloudKit to your own private iCloud database. Apple handles the download, any purchase, the account you use to do it, and the iCloud storage itself, and Apple collects its own information as part of providing these services — for example purchase records, aggregate App Store statistics, and whatever Apple’s own iCloud/CloudKit infrastructure needs to operate. That is governed by Apple’s Privacy Policy, not this one. We may see anonymous, aggregated App Store figures such as download counts; those cannot identify you, and we never see the contents of your private iCloud database.
6. This website
list.shahyari.com is a plain static site and embeds no third-party scripts or fonts. It uses Vercel Web Analytics to see how many people visit and which pages they read. This is cookieless — it does not set a cookie, does not use a persistent identifier, and does not track you across other websites — and only produces aggregate figures (page views, referring site, rough location, device type). We cannot see who any individual visitor is. There is nothing else here to consent to. Our hosting provider also keeps standard server logs (such as IP address and requested page) for security and reliability, as essentially all web hosts do. If you email us, we receive whatever you put in that email and keep it only as long as needed to answer you.
The legal basis for this processing is our legitimate interest (GDPR Art. 6(1)(f)) in understanding how the site is used, weighed against your privacy — which is why it is cookieless and aggregate-only rather than individually identifying.
7. Hosting and international data transfers
The website and its analytics are hosted by Vercel Inc., a company based in the United States. This means the limited data described in section 6 (server logs, aggregate analytics) is processed on infrastructure outside the European Economic Area. Vercel is bound by the EU Standard Contractual Clauses and its own data processing agreement as the safeguard for this transfer. We do not otherwise send any personal data to servers outside the EEA — the app itself, as described above, has no backend at all.
8. Children
{List} is not directed at children, and we do not knowingly collect information from anyone — see section 3. Consenting to information-society services under GDPR requires being at least 16 in Germany (or having a parent/guardian consent below that age); the App Store's own age rating for {List} is a separate, App Store-specific requirement. If you believe a child has sent us personal information by email, contact us and it will be deleted.
9. Retention and deletion
You are the one who controls your data either way — but how you delete it depends on whether you’ve signed in:
- If you’ve never signed in, your data lives only on your device. Deleting an item, a category, or a list removes it from the app. Deleting the app from your iPhone removes everything, including your profile photo. There is nothing on our side to request the deletion of.
- If you’ve signed in and synced, deleting individual items/categories/lists in the app removes them everywhere they’ve synced to, same as any other edit. To delete everything — your account, your local data, and your synced iCloud data together — use “Delete Account” in Profile settings. This wipes your local data immediately and also deletes your private iCloud database (best-effort; if it fails, e.g. no connection at that moment, your local data is still gone, and you can contact us if anything seems to persist).
Note that a full device backup made by iCloud or a computer may include the app’s local data, in line with how iOS backs up apps generally. Those backups, and your private iCloud database described in section 2, are managed by Apple and by you, not by us — we have no ability to access or delete either on your behalf, which is why account deletion has to happen from inside the app.
10. Your rights under the GDPR
Because we (the developer) hold essentially no personal data about you — see section 3, and note that your synced iCloud data in section 2 sits in your own Apple-governed database, not ours — most of these rights are already satisfied by design. They still formally apply, and cover anything we might hold, such as a support email you've sent us:
- Access (Art. 15) — ask what data we hold about you.
- Rectification (Art. 16) — ask us to correct inaccurate data.
- Erasure (Art. 17) — ask us to delete data, e.g. an email exchange.
- Restriction of processing (Art. 18).
- Data portability (Art. 20) — ask for a copy of data you provided, in a portable format.
- Objection (Art. 21) — object to processing based on our legitimate interest, including the website analytics in section 6.
- Lodge a complaint (Art. 77) with a supervisory authority. As we're based in Berlin, that's the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Friedrichstraße 219, 10969 Berlin) — though you may also contact the supervisory authority in your own EU member state.
For anything held in your own private iCloud database (section 2), Apple is the one to contact — see Apple’s Privacy Policy — though in practice the in-app controls (editing, deleting, or “Delete Account”) cover everything most people need.
To exercise any of these against us, use the contact details below or in the Impressum.
11. Changes to this policy
This policy may be updated from time to time. The effective date at the top will change, and material changes will be described in the app’s release notes.
12. Contact
Questions about privacy: hossein.shahyari@gmail.com