Privacy policy
Useful without asking for a profile.
Effective September 26, 2026
What we process
ShoppingList.page stores list names, item names, quantities, completion state, and the synchronization history needed to share a list. V1 does not require your name, email, phone number, address, payment information, or account identity.
A random browser device ID helps synchronize changes and diagnose failures. It is not an authentication credential. The share URL contains a high-entropy bearer ID: anyone who obtains that link may read and edit the list.
Infrastructure and metadata
The service runs on Cloudflare Workers and Durable Objects. Cloudflare may process IP addresses, request metadata, and security signals to deliver and protect the service. Application logs use structured redaction and do not intentionally record full request URLs, bearer IDs, device IDs, item names, quantities, or operation payloads.
When enabled for the deployment, the app route loads our self-hosted Umami analytics without an analytics consent prompt. The app sends a stable, random browser device ID as a pseudonymous analytics identifier, along with coarse product events such as list creation, sharing, and sync state. It does not send list contents, item names, quantities, bearer links, access credentials, or raw URLs. Retention follows the Umami server configuration, public information and legal routes do not load the tracker, and Do Not Track is honored. You can opt out by enabling Do Not Track or by blocking the analytics requests in your browser or network.
Households, recent-item autocomplete, and mixed-language lists
A household groups shared lists and the access needed to switch between them. Household and list links, including QR codes, are bearer access: anyone who obtains one may receive the access it represents. Names, list membership, list contents, completion state, and synchronization history are processed to provide the household and list features.
Autocomplete suggestions use recent item history stored in the browser. People can add items in different languages to the same list at the same time; browser language does not limit the words that can be added.
Contact messages
If you use the contact form, we store the message, the name and email address you choose to provide, the submission time, and its delivery status in the service database.
Cloudflare Turnstile checks the submission for abuse. Its verification token is used only for that check and is not stored by ShoppingList.page. Please do not include passwords, payment details, or other sensitive information in a contact message.
Retention and deletion
Active anonymous lists expire after the configured retention period without a server-accepted mutation. Reads do not extend retention. After expiration, the list becomes read-only and its contents are cleaned up according to the lifecycle policy; clients are told that the old bearer link cannot be reactivated. Pending offline changes remain on the device so they can be copied into a new list.
Your choices
You can remove autocomplete history and other local data by clearing this site’s browser storage. Do not share a list or household URL with anyone who should not have edit access. Because the service is anonymous, do not put sensitive personal information in a list.