← DinnerList

Privacy Policy

Last updated: September 19, 2026

This policy explains how DinnerList — the grocery list and recipe app (the “app”), the websites at dinnerlist.me including the share companion at dinnerlist.me/share (the “website”), and the sync service at api.dinnerlist.me (the “sync service”) — collects, uses, stores, and deletes data.

Who is responsible: Anton Khanabeev (“we”, “us”). You can reach us at support@dinnerlist.me.

The short version: no account is required — by default we know you only by a random device identifier. The app has no ads and no third-party analytics or tracking. We collect anonymous, first-party usage statistics under a random ID that is never linked to your lists, account, or sync data — you can turn this off in the app's Settings. Shopping lists sync to our servers; your dishes, recipes, purchase history, and product photos never leave your device. If you optionally create an account, we store your email and a hashed password. You can delete everything at any time in Settings → Delete My Data.

What we collect

Device identifier

On first launch, the app generates a random identifier stored in your device’s Keychain. It is sent to the sync service with sync requests so we can recognize your lists across app launches and devices. It is random — not derived from your name, Apple ID, email, or anything else about you. If you create an account, your lists (and the identifier they sync under) become associated with that account.

Account data (optional)

If you use the optional account feature (Settings → Sync & Protect Your Data), we store your email address and a password so you can restore your lists after reinstalling the app or switching devices. Your password is stored only as a bcrypt hash — never in plain text, and we cannot see or recover it. Signing in issues a session token that we revoke immediately on logout and account deletion.

Your shopping lists

List names, item names, quantities, units, purchased state, and item categories are stored on our servers so lists survive restarts, sync across your devices, and can be shared. Dishes and recipes are never synced and never leave your device. People you share a link with can view and edit the shared shopping list; their changes become part of that list.

Share links

When you share a list, we generate a random token and include it in the link (dinnerlist.me/share/...). Anyone with the link can view and edit that one shopping list in a browser — no app and no account needed. Only the shopping list is exposed this way; dishes and recipes stay private.

A share link is protected only by being hard to guess. Treat it like a house key: share it only with people you trust and don’t post it publicly. Don’t put sensitive personal information (health details, codes, passwords) into item names — anyone with the link can read them. In the current version, individual links cannot be revoked separately; all of your share links are removed when you use Delete My Data. Individual link revocation is coming in a future update.

Technical server logs

Our servers keep technical logs that include the IP address, time, requested path, and browser type of requests. We use them only to keep the service secure, to prevent abuse (for example, rate limiting), and to troubleshoot problems. This includes requests from people you share a link with, who use the website anonymously in their browser. Logs are kept only as long as needed for these purposes.

Usage data (anonymous analytics)

To understand which features are useful and where people get stuck, the app sends anonymous usage events (for example “app opened”, “first item added”, “list shared from the app”) to our own first-party analytics service. These events are fully anonymous: they are keyed only by a random analytics identifier generated on your device, used solely for analytics, separate from the sync device identifier, and never linked to your account, email, lists, or sessions. They contain no personal data and no list contents.

Usage analytics are on by default — anonymous first-party usage data is not “tracking” under Apple’s rules, and the app never shows a tracking prompt. You can turn analytics off at any time in the app's Settings → “Anonymous Analytics”; when off, nothing is collected or sent, and turning them off (or back on) deletes nothing — there is nothing tied to you to delete.

What never leaves your device

The following data is stored only on your device and never uploaded to our servers. Deleting the app permanently removes it:

  • Product photos — taken with the camera, resized on-device, stored locally.
  • Dishes and recipes, including ingredients and cooking instructions.
  • Purchase history (“Already bought”).
  • Reminder schedule and app settings, including your language choice.

What we don’t collect

  • No name, phone number, precise location, or contacts.
  • No advertising identifiers — the app shows no ads.
  • No third-party analytics or crash-reporting SDKs in the app — the only analytics we run is our own: anonymous, first-party, opt-out (see “Usage data” above). No analytics cookies or third-party trackers on this website.
  • No tracking across other companies’ apps or websites.

Permissions

  • Camera — only to take product photos. Photos are processed and stored on your device and never uploaded.
  • Notifications — only to schedule the local shopping reminders you create yourself. Reminders run entirely on your device; there are no push notifications and no server involvement.

Both permissions are requested when you first use the related feature and can be denied or revoked at any time in iOS Settings.

How we use data

We use your data solely to provide the features you request — syncing your lists, sharing them, and the optional account backup and restore — to keep the service secure (technical logs and rate limiting), and to improve the service: anonymous usage statistics show which features are useful and where people get stuck. We do not sell or rent your data, we do not share it for advertising, and we do not build profiles or use automated decision-making.

If personal data is transferred outside the European Economic Area, we ensure appropriate safeguards in accordance with applicable law, such as the European Commission’s standard contractual clauses.

Sharing with third parties

  • Infrastructure providers — hosting and log-storage providers that process data strictly on our behalf and under our instructions.
  • People you choose — anyone you give a share link to can view and edit the shared shopping list.
  • Legal obligations — if we are legally required to disclose data, we do so only to the extent necessary.

How long we keep data

Shopping lists and share links are kept until you delete them in the app or use Delete My Data. Account data (email, password hash, sessions) is kept until you delete your account. Anonymous usage events are kept as long as they are useful for product decisions — they are not linked to your identity and cannot be tied back to you; you can stop all collection with the in-app analytics toggle. Technical logs are kept only as long as needed for security and troubleshooting.

Data deletion

You can delete all of your data at any time, for free, directly in the app: Settings → Delete My Data. This immediately deletes your server-side account if you created one (email address, password hash, and active sessions), removes your shopping lists and their share links from our servers, wipes all data stored on your device — including dishes, recipes, purchase history, and product photos — and resets the anonymous device identifier. It works even if you never created an account.

Simply deleting the app does not delete server-side data — iOS gives us no way to detect an uninstall, so we can’t trigger this automatically. Use the in-app button first, or contact us using the details below and we’ll remove it for you. One exception: anonymous usage events are keyed by an unlinked random identifier, so we cannot tie them to your account or lists and there is nothing of yours to delete — stop all collection with the in-app analytics toggle.

Your rights

Depending on where you live, you have the right to access the personal data we hold about you, have it corrected or deleted, restrict or object to its processing, receive it in a portable format, and lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman. To exercise any of these rights, email us; we respond within a month (up to two additional months for complex requests, and we will tell you if we do). The fastest way to delete everything is the in-app Delete My Data button described above.

Children

The app is rated 4+ and aimed at a general audience. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy — for example, when we add features. The current version is always available at this address together with its “Last updated” date. If a change is material, we will inform you in advance where reasonably possible (for example, in the app, or by email if you have an account).

Contact

Questions about this policy or your data can be sent to support@dinnerlist.me.