Privacy policy

Last updated: 8 October 2026

listula is a free shared shopping list. Here, in plain words: what we store, why, who we pass it to and how to delete it.

In short

  • There are no accounts: no e-mail, no password, no phone number. A list is created anonymously, and what lets you in is a key kept in your browser.
  • We store what you and the other members typed into the list, and the names you joined under.
  • Everything on a list is seen by all its members.
  • To sort products into categories, their names, brands, quantities and units are read by an AI model through OpenRouter (USA).
  • There are no ads and no visit counters, and we do not sell data.
  • Questions: .

Who is responsible for the data

listula is run by its owner (“we”), who is the controller of your data. For anything about your data, write to .

What we store, why and for how long

The legal basis is either a contract (GDPR art. 6(1)(b): the service cannot work without the data) or our legitimate interest (GDPR art. 6(1)(f)).

  • A list: its name, shop and note; products with their quantity, brand, shop, notes and prices; and who marked a product bought or skipped, and when, and who removed it — so that you can shop together and see the total (contract). For as long as the list exists (see “Archiving and deleting a list”); a product removed from a list is erased from the database after 30 days.
  • Members: the name each person chose when joining, and the order they joined in — to show who is on the list and who bought what (contract). For as long as the list exists (see “Archiving and deleting a list”); the name of a member who was removed or who left stays on the list.
  • The list’s history: which member added, changed, bought, skipped or removed a product, joined, left or removed someone, and when, with the product’s or person’s name at the time — so that members can see who changed what (contract). 30 days.
  • Requests to join: the name a request was sent under, and the decision on it — so that whoever created the list can let you in (contract). A request waits 24 hours for a decision; once decided, its record is deleted after 90 days, and a request nobody decided on may stay for as long as the list exists.
  • Access keys and the codes for restoring an archived list — only their hashes are on the server; an invitation — a hash and an encrypted (AES-GCM) copy, so that the current link can be shown again (contract). An invitation works for 24 hours, and a new one cancels the previous one.
  • A problem report: its type, your text, a contact for the reply (if you gave one), the page it was sent from (with an invitation code in its address masked), the list, the language and the browser — to look into it and answer (legitimate interest). The same reaches our mailbox as an e-mail — up to 50 a day; the rest are only stored. There is no automatic time limit yet: we delete a report when you ask — from the database and from the mailbox.
  • Technical records: the web server’s log — the IP address, the time, the address requested, the page you came from and the browser, with invitation codes masked — to protect against abuse and find faults (legitimate interest). 14 days. Request limits are counted per IP address in the server’s memory only, and the address is forgotten once the limit’s window has passed (an hour at most).
  • Backups of the database (legitimate interest) — up to 30 days: what is changed or erased leaves the backups within 30 days.

You can object at any time to processing based on legitimate interest — write to .

We ask for no e-mail, no phone number and no real name: the name on a list can be anything. We do not rely on consent. We make no automated decisions about you and build no profiles.

Archiving and deleting a list

The list’s organizer (at first whoever created it; when they leave, the role passes to the member who joined earliest) can archive it: every member’s access and every invitation close at once. The list can be restored from the same device within the time the app names before archiving (by default 24 hours); after that it cannot.

An archived list no longer opens for its members or through a link. Once the restore time is over, the list with everything in it is erased from the database within a day, and from the backups within 30 days. To have a list erased sooner, write to .

When the last member leaves a list, the list with all its products, members and requests is erased from the database at once, and from the backups within 30 days. A list nobody has opened for 180 days is archived automatically — and then as above: its organizer can restore it within the restore time, after which it is erased.

Artificial intelligence and categories

  • When a product is added or changed, the server sends its name, brand, quantity, unit and the interface language to an AI model through an intermediary, OpenRouter (USA). We choose the model, and it may change.
  • We require the request to go only to providers that do not use what is sent to train their models and do not keep it for their own purposes.
  • Notes on products and on the list, the list’s name, prices, the members’ names and anything about your device are not sent to the model.
  • The model returns a category and a generic name for the product — without brand, quantity or packaging — and, when the interface is not in Polish, that name in your language as well. Such names may join the shared catalogue (the one in your language as a translation) from which listula suggests product names to everyone — with no link to your list.

What happens to a request after that is also governed by the terms of OpenRouter and of the model’s provider. So do not write anything personal in a product’s name or brand.

If you add products by voice, your browser turns speech into text: in Chrome, the recording is sent to Google for this, and we receive only the text.

Shopping notifications

When a member ticks items off as bought, the others see “🛒 Name is at the shop” on the list. For this the server remembers who last ticked something off and when — in memory only, for at most half an hour; none of it is written to the database.

If you want (the “Notify me when someone goes shopping” switch in the list menu), your device can also get a push notification about it. Your browser asks for permission only when you turn the switch on.

  • What we store: your browser’s push subscription — an address at your browser maker’s notification service and encryption keys — together with the member and the list it was turned on for, the app’s language and when it was created (contract: you turn the feature on yourself). At most 5 subscriptions per member.
  • How a notification travels: through your browser maker’s notification service — Google (Chrome, Opera, Samsung Internet and others), Apple (Safari on Mac, iPhone and iPad), Mozilla (Firefox) or Microsoft (Edge on Windows). Its content (the member’s name and the list’s title) is encrypted for your device: the service only sees when a message goes to which device, and our server’s IP address.
  • When a subscription is deleted: when you turn the switch off, when you leave the list or are removed from it, when the list is archived or erased, and when the notification service tells us the subscription no longer works (for instance, notifications were blocked or the browser’s data cleared).

On iPhone and iPad, notifications work only once listula has been added to the Home Screen. Your browser also keeps the list of lists you turned notifications on for.

Who sees the data

The members of a list see everything on it: products, prices, notes, the names of all members and who marked what, and in “History”, who changed what over the last 30 days.

The prices paid for catalogue products are also used to show everyone a typical price (“usually about 4.50 zł”) — only aggregated and anonymously: the median over the last 90 days, and only once a product has been bought on at least 5 different lists. Nothing that identifies a list or a person is shared.

Someone holding a valid invitation sees, even before being approved, the list’s name, its shop, and how many products and members it has.

Whoever created the list sees requests to join, with their names, and decides whom to let in. Every member can remove from the list those who joined after them.

On a complaint or at your request we can close a list. All traffic with the site goes over HTTPS; access keys and restore codes are kept on the server only as hashes, and invitations as a hash and an encrypted copy.

Who we pass data to

For the service to work, some data reaches other companies:

  • A hosting provider in the EU — the server holding the database and its backups.
  • Cloudflare — the network all traffic with the site passes through (protection against attacks); it sees your IP address, the addresses of the pages and what you send.
  • OpenRouter and the model’s provider — a product’s details, to sort it into a category (see above).
  • Google (Gmail) — our mailbox: your problem reports arrive there as e-mails, with everything attached to them, and so do the e-mails you write to us.
  • Your browser maker’s notification service (Google, Apple, Mozilla or Microsoft) — only if you turned shopping notifications on: a notification encrypted for your device (see “Shopping notifications”).

We do not sell data; we disclose it to other third parties only where the law requires it.

What is kept in your browser

Your browser’s storage holds the access keys to your lists with their names, the restore code of an archived list and your settings (theme, language, whether to ask for a price when buying). On every visit the site sets a cookie, “listula-locale”, with the language — detected or chosen by you — so that the page opens in it straight away; it lasts a year and is sent over HTTPS only. There are no advertising or analytics cookies.

The access key is your way in: whoever has your browser has your lists. “Forget” on the start page erases the key from this device only, and your name stays on the list; to leave the list, use “Leave list”.

List templates (“Save as template”) live only in this browser’s storage: the template’s name, the currency and the items with their quantity and category — no prices and nothing about who bought what. They are not sent to the server; when you create a list from a template, its items are added to the new list just as if you had typed them. You can delete a template in the create-list window, and clearing the site’s data in your browser erases them all.

Your name — the one you gave when joining a list, creating one or changing your name among the members — is remembered by your browser (in this browser only) so that it can be filled in for you next time. It is not sent anywhere by itself: it reaches a list only when you use it there. Clearing the site’s data in your browser erases it.

Your rights and how to use them

  • Get a copy: everything on a list is on its page; a copy of the rest — on request.
  • Correct: products, quantities, prices and notes are edited on the list; a member’s name — on request.
  • Delete: a product — on the list; a list — by whoever created it, with “Archive”, or by all its members leaving it; complete erasure of a list, your name or a report — on request.
  • Leave a list: “Leave list” in the list’s menu. Your name stays on it among the former members; if you are the last to leave, the list is erased completely. The organizer or a member who joined before you can also remove you.
  • Object to processing, restrict it or ask for anything the interface does not offer — write to . We will answer within 14 days.

There are no accounts, so in your request give the list’s link (or its name and shop) and the name you are on it under — that is how we find your data. We may ask you to confirm that the list is yours.

Changes to this text

If what we store or whom we pass it to changes, we will update this text and the date at the top.

Terms of use