Privacy Policy

Last updated: 2026-09-12

This document is provided in English; the English version governs.

1. Who we are

Just List (mobile apps and justlistapp.com) is operated by Cluberr ("we", "us"). This policy explains what data we collect, why, who processes it for us, and the choices and rights you have. Contact us any time at friends@justlistapp.com.

2. Data we collect

  • Account data — when you sign in with Google or Apple we receive your email address, display name, and profile picture URL from the sign-in provider (via Firebase Authentication).
  • Content you create — your lists and items, photos you attach (covers, avatars), takes, suggestions, and event lists. Public lists you publish to the Feed are visible to everyone.
  • Scanned documents (Papers) — receipts, coupons, warranties, and other papers you scan into a PDF with the app. By default a scan stays on your device only; we learn a document exists only once you share the list it's attached to, choose Keep in cloud, or use auto-file (see "Document scanning (Papers)" below).
  • Location — with your permission, the app uses your device's location to power location-based reminders (for example, alerting you when you arrive at a store) and "leave" reminders like Park Here. When you save a reminder location or a place (Home, Work, or a favorite), its coordinates and label are stored on our servers so the reminder survives a reinstall or works across your devices. Checking whether you've entered or left a saved area happens on your device via your OS's geofencing APIs and is not itself transmitted to us — only the saved place you created is. You can revoke location permission at any time in your device settings, which turns off location-based reminders.
  • Social activity — follows, hearts, clones, reactions, and takes, used to power the social features and your For-You feed.
  • Gamification state — XP, level, coins, badges, streaks, and cosmetic items you own or equip.
  • Device and push data — a push-notification token (Firebase Cloud Messaging) if you enable notifications, and your approximate timezone offset so reminders and nudges arrive at sensible local times.
  • Usage analytics — product analytics events (PostHog, EU-hosted; consent-gated on the web) and Firebase Analytics in the mobile apps, plus server logs.
  • Messages you send us — contact-form submissions are stored so we can respond.
  • Event guest email (optional) — if you claim an item on someone's event list, you can optionally leave an email address so we can send you the event link and a reminder before the event. This is never required — you can claim items with no account and no email at all. We only store it if you explicitly opt in, and every email we send includes a one-click unsubscribe link.

3. List scanning

When you scan a photo, screenshot, or pasted text to create a list, it is uploaded over an encrypted connection to our servers, read to extract your list items — occasionally a second, more careful read of the same content when the first pass isn't confident about everything it saw — and deleted from our storage — typically within seconds, and in all cases within 24 hours by automatic cleanup. Extraction is performed by Google's Gemini API acting as our data processor; under Google's paid-services API terms, submitted content is not used to improve or train Google's products. We never keep your scanned photos, and nothing is saved to your account unless you review the extracted items and choose to create the list.

4. Document scanning (Papers)

When you scan a receipt, coupon, warranty, or other paper with the app's Papers feature, the scan is turned into a PDF and stored on your device by default — nothing is uploaded. A copy is uploaded to Google Cloud Storage only when you share the list the document is attached to, or choose Keep in cloud. Separately, a temporary copy is uploaded only when you tap File it for me; it is read by Google's Gemini API to suggest a title, date, and amount, and is deleted within 24 hours — the same paid-services terms described above apply, so that content is not used to improve or train Google's products. We never read a document without that tap.

Cloud copies of documents are removed 7 days after the last list that references them is deleted or unshared (90 days after a Plus subscription lapses, for copies beyond the free allowance) — always after at least one warning and a working Download all option to save them first. Deleting your account deletes them immediately.

5. Why we process it (purposes and legal bases)

  • To provide and sync the service (your lists, sharing, realtime collaboration) — performance of our contract with you.
  • Social features (the Feed, follows, parties) — performance of contract.
  • Notifications you control (reminders, social notifications, nudges) — consent, revocable in your device or in-app settings.
  • Location-based reminders (arrival/leave alerts, saved places) — consent, revocable via your device's location permission settings.
  • Product improvement and safety (analytics, abuse prevention, debugging) — our legitimate interest in running a working, safe product; analytics cookies on the web additionally require your consent.
  • Payments — performance of contract, handled by our payment processors (we never see full card details).

6. Who processes data for us

ProcessorWhat it does
Google FirebaseSign-in (authentication), push notifications, mobile app analytics
Google CloudDatabase and media storage (covers, avatars, saved location-reminder coordinates)
RenderServer hosting
PusherRealtime list sync (transport only)
PaddleWeb payments — merchant of record; we never see full card data
Apple / GoogleMobile subscription billing (managed in your store account)
Google AdMobAds shown in the free mobile app, with its own consent management flow
PostHogProduct analytics, hosted in the EU; consent-gated on the web
ResendDelivery of transactional emails you've opted into (event links, event reminders) — never marketing or bulk email
CloudflareCDN / reverse proxy that protects and accelerates traffic to justlistapp.com
Google Gemini APIExtracts list items from a photo, screenshot, or pasted text you submit to scan a list — content is deleted after extraction and is not used to improve or train Google's products under Google's paid-services API terms
Google Cloud StorageDocument storage — holds a scanned document (Papers) only once you share the list it is attached to, choose Keep in cloud, or tap File it for me
Google Gemini API (document reading)On-demand document reading — reads a document only when you tap File it for me, to suggest its title, date, and amount; the temporary copy is deleted within 24 hours and is not used to improve or train Google's products under Google's paid-services API terms

7. Cookies

The complete inventory of browser storage we use on justlistapp.com:

NamePurposeType
sessionKeeps you signed inStrictly necessary
loggedInRemembers UI state for signed-in visitorsStrictly necessary
PostHog analytics storageProduct analytics (event tracking)Consent-gated — only set if you choose "Accept all"

The cookie banner is your control: choose "Essentials only" and no analytics storage is ever set. You can change your choice any time via "Cookie preferences" in the footer. Strictly-necessary cookies are exempt from consent under ePrivacy rules — without them you cannot stay signed in.

8. Retention

Account data and content are kept for as long as your account exists. Backups and server logs are retained for bounded periods and then deleted or anonymized. When you delete your account, associated personal data is removed as described below.

Scanned documents follow the schedule in "Document scanning (Papers)" above: cloud copies are removed 7 days after the list that references them is deleted or unshared, and 90 days after a Plus subscription lapses for documents beyond the free allowance — always after at least one warning and a chance to download them first.

9. Deleting your account

You can delete your account in-app (Settings → Delete My Account). This removes your account, your owned lists, and your sign-in identity — signing in again with the same credential afterward creates a brand-new, empty account. You can also email us at friends@justlistapp.com to request deletion.

10. Your rights

Depending on where you live (including the EU/EEA under GDPR and Israel under the Protection of Privacy Law), you may have the right to access, correct, delete, or receive a portable copy of your personal data, and to object to or restrict certain processing. Contact us to exercise any of these; you also have the right to lodge a complaint with your local supervisory authority.

11. Children

Just List is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has an account, contact us and we will remove it.

12. International transfers

Our analytics are EU-hosted; other processors (listed above) may process data in the US or EU under standard contractual safeguards recognized by applicable law.

13. Security

Data is encrypted in transit; access to production systems is scoped and credentialed. No system is perfectly secure — if we learn of a breach affecting your personal data we will notify you as required by law.

14. Changes

We may update this policy from time to time. For material changes we will give notice (for example in-app or by email) before they take effect. The "Last updated" date at the top reflects the latest revision.

15. Contact

Privacy questions or requests: friends@justlistapp.com

This page is provided for transparency and does not constitute legal advice to users.