Listnik

Privacy policy

Last updated 30 September 2026

The short version: Listnik stores your household's list, meals and meal plan on its server so that every phone in the household stays in sync. It isn't used for anything else: there are no ads, no analytics and no tracking, and your data is never sold. A few features send the minimum they need to Apple, Google or Brave, as described below.

This policy covers the Listnik app for iPhone and iPad, the Listnik server it syncs with, and this website. Listnik is made by Ilya Voloshin, who is responsible for it under data protection law ("I" below). Contact: listnik@ilyav.net.

What the server stores

Your accountWhen you sign in with Apple: Apple's identifier for your Apple ID in Listnik, the name your household sees (Apple suggests your first name; you can change it in Settings), and a token from Apple, encrypted, that lets me end the link to your Apple ID when you delete your account. Listnik asks Apple for your name only, never your email address. Older accounts have a user name and a salted hash of the password instead (never the password itself). Also the household you belong to, and your sign-in sessions and API tokens, stored as hashes. Listnik doesn't ask for your email address or phone number.
Your household's contentItems and their notes, amounts, categories and stores; store names, aisle orders and locations you set; meals, their descriptions and recipes; the meal plan; and 90 days of item history (when things went on and off the list). Everyone in the household can see and change all of it.
PhotosPhotos you add to items and meals, re-encoded on the server. Each image is stored once, under an id made from its content, and only signed-in Listnik users can download it, except through the link in a notification (below), which opens that one photo for 2 days.
NotificationsIf you allow notifications: your device's push token from Apple, tied to that sign-in, and which ones it wants (grocery list, meal plan, new recipes). Signing out or deleting your account removes it.
Calendar linksIf you show a calendar on the meal plan, its address; if you publish the meal plan as a calendar, the secret link for it.
Server logsRequests (time, address, path and result) are logged to run and secure the service, and kept for a short time.

The server runs on a virtual private server rented from RackNerd in Atlanta, in the United States, so if you live elsewhere your data is transferred there. The database and photos are backed up every night to a second server I own, also in the United States, and backups are kept for 14 days.

Services that help

Sign in with Apple

When you continue with Apple, Apple confirms it's you and tells Listnik an identifier for your Apple ID, plus, the first time, the name you choose to share. Apple doesn't tell Listnik your password, and Listnik doesn't ask for your email address. See Apple's privacy policy. You can stop using Sign in with Apple for Listnik in your iPhone's Settings → your name → Sign in with Apple.

Apple Push Notification service

When someone in your household puts an item on the list or crosses it off, adds or removes a meal on the plan, or adds a meal or recipe, the server asks Apple to deliver a notification to the others' devices that allowed them. It says who made the change and what it was (the item or meal, its amount or day) and, when the item or meal has a photo, carries a link to it that works for 2 days. Apple delivers it under Apple's privacy policy. You can choose which notifications you get in Settings → Notifications, or turn them off in your iPhone's Settings → Notifications → Listnik.

Apple Intelligence (on your phone)

On iPhones and iPads with Apple Intelligence, Listnik suggests a category for a new item with Apple's on-device model. This happens on the device and nothing is sent anywhere.

Google Gemini (category and collection suggestions, and recipes)

When the phone can't suggest a category (no Apple Intelligence, or the item has a photo it can't read), the server asks Google's Gemini model. It sends the item's name and note, your household's category names with a few example items, and the item's photo if it has one. When you import a recipe from a post or page, the server sends the post's or page's text to Gemini to read the recipe out of it. When you add a meal, the server sends its name and description (the recipe, for an import), with your household's meal collection names and a few example meals, so Gemini can suggest a collection. Nothing that identifies you is sent. The app asks before anything goes to Gemini the first time, and you can turn it off in Settings → Suggestions from Google Gemini; then categories are only suggested on the device, and only recipe pages with their own recipe card can be read. Google's handling is covered by the Gemini API terms and Google's privacy policy.

Brave Search (web image search)

If you search the web for a photo, the server sends your search words to the Brave Search API and caches the results for a day so repeat searches are fast. When you pick an image, the server downloads it from the site it's on and remembers that page and image address, so a copyright complaint about it can be handled. Brave doesn't receive anything about you; see Brave's privacy policy.

Recipe links you share

When you share a post or page to Listnik, the server fetches that address (an Instagram or Facebook post, or a recipe page) to read the recipe and its photo. The site sees an ordinary request from the Listnik server, not from you.

Calendars

If you show a Google or iCal calendar on the meal plan, the server downloads it from the address you enter.

Location

Auto-Select Store is off until you turn it on in Settings. When it's on, the app uses your location only while it's open, and compares it with your stores' locations on the device to pick the store you're at; where you are isn't sent anywhere. The one time your location leaves the phone is when you save it as a store's location (Save Location Here, or on the map in a store's settings): it's then stored as that store's location, with your household's stores.

Camera and photos

The app asks for the camera or your photo library only when you add a photo to an item or meal, and uploads only the photo you choose.

Purchases

Listnik Plus is bought through the App Store. Apple processes the payment; I receive no payment details. So that Plus covers your whole household, the server records which account holds a subscription, its App Store transaction id, product, environment and expiry date, as signed by Apple, and Apple's notices about renewals and refunds. Without Plus, the meal plan keeps the last 3 months of past entries; older ones are deleted 30 days after Plus ends.

No ads, analytics or tracking

The app contains no advertising, analytics or crash-reporting code, and doesn't track you across apps or websites. If you've chosen in iOS to share analytics with app developers, Apple may send me anonymous crash reports, under Apple's terms.

This website

This site has no cookies, no analytics and nothing loaded from other servers. The web server keeps standard access logs (address, time, page) for a short time to keep it running and secure.

How long data is kept

Your household's content is kept while your account exists. Item history is deleted after 90 days. Deleted items, meals and plan entries leave a small marker so every phone learns they're gone. Photos no item or meal uses any more are deleted after a week. Backups roll off after 14 days.

Deleting your account

In the app, go to Settings → Delete Account. It deletes your account, its sessions and API tokens right away, and ends the link to your Apple ID. If you were the last member of your household, its list, meals, meal plan and stores are deleted too, and photos no other household uses within a week; otherwise the others keep the household. The same happens to a household when its last member leaves it. Backups containing your data roll off within 14 days. You can also email listnik@ilyav.net and I'll delete it for you.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your data, and to object to or restrict how it's used. Write to listnik@ilyav.net; I'll answer within 30 days. You can also complain to your data protection authority. The legal basis for storing your data is providing the service you asked for (performance of a contract).

Children

Listnik isn't directed at children under 13, and I don't knowingly collect data from them.

Changes

If this policy changes, the new version will be posted here with a new date. Significant changes will be announced in the app.