Legal
Privacy policy
Listo is built so that your lists stay yours. This policy explains, in plain language, what information the Listo app and this website handle, why, and the choices you have.
Summary
Listo has no advertising and no cross-app tracking, and we do not sell or share your personal information. You don’t need to give us your name or email to use it.
Your lists, notes and Spaces are saved on your device and synced to a private account so they appear on your other devices and on lists you share. Only you — and the people you choose to share a list with — can see them in the app.
Audio, photos and planning requests leave your device only when you deliberately use an AI feature. They are processed to produce your result and are not stored.
In this policy, “Listo,” “we,” “us” and “our” refer to the operator of the Listo app and heylisto.app. “The app” means the Listo app on any platform. If you have any question about this policy, email support@heylisto.app.
1. Information stored on your device
The app keeps a private database and a small settings store on your device, so it opens instantly and works without a connection. Together they hold:
| Information | Why |
|---|---|
| Lists, items, quantities, prices, categories and budgets | To show you your lists |
| Notes and their contents | To show you your notes |
| Spaces (name, icon, color) | To organize your content |
| Templates, repeat schedules and reminders | To reset lists and remind you |
| Favorite and archived flags, timestamps | Sorting and the archive |
| Item history used for suggestions | To offer things you’ve added before |
| Language, appearance and store-layout preferences | To show the app the way you like it |
| Your account session and sync progress | To keep you signed in and know what still needs to sync |
| Whether you’ve seen the intro, and your privacy choices | So you are not asked again on every launch |
Your content is also synced to your account, as described in Sync across your devices. Reminders are scheduled as local notifications by your device’s operating system and are not sent to us. Item history, and your language, appearance and privacy settings, stay on the device.
2. Your account
The first time the app runs, it quietly creates an anonymous account for you with our account and database provider, Supabase. You are not asked for a name, email address, phone number or password, and there is no sign-up screen. The account gives your content a durable owner, so it can sync between your devices and be shared.
You can choose to link the account to Apple, Google or an email address under Settings → Account to secure it. If you do, Supabase processes the identifier that sign-in method provides (for Apple or Google, an account identifier and, where the provider shares it, an email address; for email, the address you enter). We use it only to sign you in and to send the messages needed to confirm it.
You can also set an optional display name in Settings → Account. It is shown only to people on lists you share, so they can see who added or checked off an item.
For each account, Supabase stores the account identifier, any sign-in method you linked, your display name if you set one, and standard authentication records such as when the account was created and last signed in.
3. Sync across your devices
Listo keeps a copy of your content in our cloud database, hosted by Supabase, so that it is backed up to your account, stays in step on every device signed in to it, and can be shared. The app syncs in the background whenever it has a connection. What is synced:
- Lists and their items — text, quantities, categories, prices, checked state, order, and who checked an item off and when
- Notes — their titles and contents
- Spaces — name, icon, color and order
- List settings — favorite and archived flags, templates, repeat schedules, budgets, amounts spent and currency, and aisle sorting
- Housekeeping fields — when each record was created and changed, which account created or changed it, and whether it has been deleted
Your content is protected by access rules in the database itself: a list can be read only by your account and by people you have approved on that list. It is encrypted in transit and stored by our provider with encryption at rest. It is not end-to-end encrypted, so a small number of people who operate the service could technically access it; we do so only to keep the service running and secure, to help you when you ask us to, or where the law requires it.
We do not read your lists, use them for advertising, sell them, or use them to train AI models. Synced content is never sent to OpenAI; only what you deliberately send to an AI feature is.
When you delete a list, note, item or Space, it is marked as deleted rather than erased straight away, so your other devices and the people you share with remove it too. Deleted records stay in our database, unreadable in the app, until your account is deleted.
5. Shared-list notifications (only if you turn them on)
If you turn on Settings → Shared list updates and allow notifications, the app registers your device’s push-notification token, your platform (iOS or Android) and your app language with your account. When someone else adds an item to, or checks one off, a list you share, our service sends you a notification through Expo’s push service and Apple or Google. The notification shows the list’s name, the person’s display name and the item. You are never notified about your own changes, and at most once per list every 10 minutes — to do that, the service records when it last notified you about each list.
Turn the setting off, or revoke notification permission in your device settings, to stop them. A token that stops working is deleted automatically.
6. Voice and AI features (optional)
The AI features are optional. If you never use them, no audio, photo or planning content ever leaves your device.
Voice lists
When — and only when — you tap the microphone:
- The app records audio only while the voice screen is open and you have started a recording. Recordings are limited to 60 seconds on Free and 5 minutes on Pro.
- When you stop, that one recording is sent over an encrypted connection to the Listo AI service (api.heylisto.app).
- The service sends the audio to OpenAI for transcription, then sends the resulting text to OpenAI to be organized into a list.
- The draft is returned to your device. You review it, can remove or edit any item, and nothing is added to your library until you tap Save.
The audio is held in the service’s memory only for the duration of the request. It is never written to disk or to a database, and no log contains your audio or transcript. Once the response is returned, it is discarded. There is no background or “always-on” listening.
AI Planner and item suggestions
When you use the AI Planner or “suggest items,” the request you type — and any optional budget, location, dietary or material preferences you add — is sent to the Listo AI service and then to OpenAI to produce a list with quantities, approximate prices, steps and warnings. The request and the response are not written to disk or a database. Prices are estimates and may vary by seller, place and date.
Importing a link
When you paste a link, the web address is sent to the Listo AI service, which downloads that public page, extracts its text or published recipe data, and sends that text to OpenAI to build the list. The service only fetches public web pages — never addresses on private networks — and keeps neither the address nor the page after responding.
Importing a photo
When you take or choose a photo to import, only that one photo is uploaded to the Listo AI service and sent to OpenAI to be read. It is held in memory only for the request and never written to disk. The app does not request the photo’s location (EXIF) data and does not browse your photo library.
How OpenAI handles this content
OpenAI processes this content as our service provider under its API terms. Our list-building and planning requests are sent with OpenAI’s response storage turned off, and under OpenAI’s API data-usage policy, API content is not used to train its models by default. OpenAI may retain API content for a limited period to monitor for abuse, as described in OpenAI’s API data usage policy, which we do not control.
The AI only ever returns a suggestion. It has no access to your lists, and nothing it produces is saved — or synced — unless you review it and tap Save.
7. Network information
Any request to the Listo AI service carries your device’s IP address, as every internet request does. The service uses it to apply rate limits that protect the service from abuse. It is kept in memory and is not stored alongside any content. To limit automated sign-ups, the service also counts how many new installations register from each network per day, keyed by a one-way hash of the IP address — never the address itself — and discards the count the next day.
Our hosting, database and network providers, including Supabase, may keep standard technical logs (such as IP address, time and requested address) for security and reliability. These logs do not contain the contents of your lists, notes, recordings or photos.
8. Your installation ID
The first time the app runs, it also creates a random installation identifier on your device. It is not derived from your hardware, your phone number or any advertising identifier. It is sent with AI requests, and our AI service does not receive your account, your display name or any email address. It does two things only:
- It counts how many voice lists and AI plans this installation has used, so the free trial and the Pro monthly allowances can be applied.
- It is the identifier our subscription provider holds for a Pro subscription, so the service can confirm a subscription is active without knowing who you are. Linking an account does not change it, so signing in never affects your plan.
The first time it is used, the service returns a signed token that proves later requests come from the same installation; the token contains only the identifier and the time it was issued.
Against this identifier the service stores: usage counts, when it was first and last seen, the subscription status last reported for it, and anything our support team sets for it at your request (for example, a support note). It is never attached to the contents of a list, a note, a recording, a photo or a plan.
You can see your installation ID under Settings → Support ID. Deleting the app discards it on your device, and a fresh install creates a new one.
9. Anonymous usage counts (only if you say yes)
The app may ask whether you’re willing to share anonymous usage counts. If you say yes, it sends counts of a few fixed actions — for example “a list was created” or “an AI plan was saved” — together with your platform and app version. It sends no identifier of any kind and none of your content, and the service stores only daily totals, so the counts cannot be connected to you, your account or your device. If you say no, or never answer, nothing is counted. You can change your answer in Settings at any time.
10. Crash reports
If the app crashes, it may send a crash report to our error-monitoring provider, Sentry. A report contains technical details of the failure — the stack trace, app version, operating system, device model and the name of the screen. It never includes the content of a list, note, search or recording, your account or installation ID, screenshots, or a trail of what you tapped, and it does not use your IP address as an identifier. You can turn crash reports off at any time under Settings → Send crash reports.
11. Purchases
If you subscribe to Listo Pro, the payment is handled entirely by Apple (App Store) or Google (Google Play). RevenueCat processes your subscription status on our behalf under your installation ID. We learn whether a subscription is active — never your name, card number or billing address. If you have not purchased anything, no purchase information is processed.
12. Service providers
We use a small number of service providers to run Listo. Each processes information only to provide its service to us:
| Provider | Purpose | When |
|---|---|---|
| Supabase | Accounts, sign-in, sync and shared lists | Whenever the app is online |
| OpenAI | Transcription and AI list planning | Only when you use an AI feature |
| Expo | Delivering shared-list notifications | Only if you turn on shared-list updates |
| RevenueCat | Subscription status | Only if you subscribe to Pro |
| Apple, Google | App distribution, payments, notifications, and sign-in if you link it | Under their own terms |
| Sentry | Crash reports | Only if the app crashes and reports are on |
| Cloud hosting providers | Running the Listo AI service and this website | When you use the AI service or visit this site |
13. This website
heylisto.app uses no cookies, no analytics, no advertising and no third-party scripts. Fonts and images are served from this site, so visiting it does not contact any other company. Our hosting provider may keep standard server logs as described in Network information. If you email us, we use your message and email address only to respond and to keep a record of the conversation.
14. Children
Listo is a general-audience productivity app and is not directed to children under 13 (or the minimum age of digital consent in your country). We do not ask for a date of birth and do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it.
15. Your choices and rights
- Delete individual items: archive a list or note, then delete it permanently from the Archive screen. The deletion syncs to your other devices and to anyone you share it with.
- Export your data: Settings → Account → Export my data creates a file with every Space, list, note and item.
- Delete your account: Settings → Account → Delete account and data permanently deletes your account from our servers — along with every list, note, item and Space it owns, your memberships, invites and notification registrations — and erases the content on that device. Items you added to someone else’s shared list stay on their list.
- Uninstalling removes the data on that device but does not delete your account or its synced content. Delete your account in the app first if you want those removed, or contact us.
- Sharing: leave a shared list, or remove members and revoke invites from a list you own, at any time.
- Avoid AI uploads: don’t use the microphone, the AI Planner, or link and photo imports. Everything else works without them.
- Usage counts, crash reports and shared-list notifications: switch any of them off in Settings at any time.
- Permissions: microphone, camera, photos and notifications can be granted or revoked in your device settings.
- Records tied to your Support ID: email us your Support ID and we will tell you what we hold for it, or delete it.
Depending on where you live — including under the GDPR in the EU and UK and the CCPA/CPRA in California — you may have rights to access, correct, delete or port your personal information, and to object to or restrict its processing. Most of these you can exercise directly in the app with the export, edit and delete tools above. For anything else, email support@heylisto.app. We will not discriminate against you for exercising your rights, and you may also complain to your local data-protection authority.
Where the GDPR applies, we process your account, synced content and shared lists, and content you send to an AI feature, to provide the service you asked for (performance of a contract); installation records and network information to apply allowances and keep the service secure (our legitimate interests); and usage counts, crash reports and shared-list notifications on the basis of your choice in Settings.
We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined under California law.
16. Retention
- Recordings, photos, links, plans and transcripts: not retained by us; discarded as soon as your result is returned.
- Your account and synced content: kept for as long as your account exists, including records marked as deleted, and deleted from our database when you delete your account. Copies in our provider’s backups expire on its backup schedule.
- Content on your device: kept until you delete it, delete your account, or delete the app.
- Invites: kept until the list or your account is deleted; a link stops working when it expires, is used up or is revoked.
- Notification registrations: kept until you turn notifications off, the token stops working, or you delete your account.
- Installation records: kept while the installation is in use so allowances and subscriptions work, and deleted on request.
- Network counts used for abuse prevention: discarded daily.
- Crash reports: kept by Sentry for a limited period under its standard retention.
- Support emails: kept as long as needed to help you and for our records.
17. Security
All traffic between the app and our services is encrypted with HTTPS. Access to synced content is enforced by rules in the database, so one account cannot read another account’s lists unless it has been approved on them, and removing someone takes effect immediately. Invite codes are stored only as one-way hashes. Secret keys for the database, AI and subscription providers are kept on our servers and are never shipped inside the app. Your on-device data is protected by your device’s own storage protections, such as your passcode and device encryption. No system is perfectly secure, but we design Listo to hold as little about you as possible.
18. International transfers
Our service providers may process and store information, including your synced content, in the United States and other countries. Where we transfer personal information internationally, we rely on appropriate safeguards, such as the providers’ standard contractual clauses.
19. Changes to this policy
If we change this policy, we will update the effective date at the top of this page. If a change is material — for example, if content would start leaving your device in a new way — we will tell you in the app before the change applies to you.
20. Contact us
Questions, requests or concerns about privacy? We’re happy to help.