Revision dated September 14, 2026.
1. Who processes data
Developer and personal data controller: Лопатка Александр Федорович, an individual operating as Alex STA. Latin-script name: Lopatka Aleksandr.
Address for legal correspondence: apartment 17, 56 Lenina Avenue, Rostov-on-Don, Russia.
Privacy, support and deletion: head.stat@gmail.com
This policy covers the Shopping List STAT app with sign-in, optional synchronization and voice features, and the informational website available at the primary address shoppingliststat.com and the mirror address shoppingliststat.app. It explains data processing and does not constitute blanket consent for all purposes. Optional-feature settings can be managed independently of Terms acceptance; the choice process is described below.
2. Use without an account and local data
Lists, items, prices, quantities, categories, recipes, text notes, selected photos, audio notes and preferences may be stored on your device. Core local features do not require an account. Using the app without an account does not mean that no network requests occur: system speech recognition, update checks, service availability settings and voluntarily enabled telemetry may use the internet.
You can edit and delete app content. Trashed lists and records of deleted items may remain for recovery and synchronization between devices. Clearing app data removes local storage; app uninstallation and restoration of system backups depend on the operating system. Files you share or copy outside the app remain with you or their recipients.
3. Account and sign-in
On registration or sign-in, Google/Firebase processes the email address, account identifier, sign-in provider, session data and technical information including the IP address and client information. The app profile may store a name, email, avatar color, and the date and version of Terms acceptance. Google or Apple sign-in supplies profile information authorized by that provider, including a photo if provided. Loading that photo contacts its provider’s server.
To confirm which Terms were accepted and when, Cloud Firestore stores a separate record: account and acceptance identifiers, the versions and publication dates of the Terms and Privacy Policy, acceptance and server-confirmation times, language, sign-in provider, an app-generated installation identifier, platform, device model, OS version, app version and build number. When the sign-in screen offers a synchronization choice, the record also contains the selected switch position and the synchronization disclosure version. These details support the account and evidence Terms acceptance: they are stored independently of permission for analytics, diagnostics and list synchronization, retained as account data, and deleted with the account. A local acceptance record is stored on the device.
Email and password sign-in is provided by Firebase Authentication. We do not receive your Google or Apple account password and do not ask you to send passwords or verification codes to support. An Apple private relay address may be used as the account email.
4. Optional synchronization
When you explicitly sign in with email, Google or Apple, the Terms screen includes a synchronization switch that is initially on for that sign-in attempt. You can turn it off before accepting the Terms. Acceptance records the selected position; exchange begins after successful sign-in, server confirmation of acceptance, and satisfaction of service-availability and local-data ownership requirements. Cancelling or failing sign-in does not change the saved setting. You can also manage synchronization in Settings. Cloud Firestore receives supported lists, items, prices, quantities, custom categories, note text, and synchronization metadata: record and installation identifiers, timestamps, protocol versions and deletion records. The profile and Terms acceptance records are stored in the cloud independently of list synchronization.
Synchronization is intended for devices using the same account. Note photos and audio files, recipes and system reminders are not uploaded by this feature. Turning synchronization off stops new exchange but does not erase the existing cloud copy. To delete that copy, use account deletion or send a data request.
If, after sign-in, the device contains shopping data from another account, the app requires a choice: transfer it to the current account as separate copies, or delete the local shopping data. This choice is required even when synchronization is off. Transfer creates new identifiers; similar lists are not combined by name and duplicates may remain. Photos, audio notes and reminders are retained locally. Transfer does not itself enable synchronization, but if synchronization is already allowed, supported copies may be uploaded to the current account’s cloud storage. Local deletion requires confirmation and does not delete the previous account’s cloud data. Recipes, their ingredients, the catalog, settings and files needed by retained records remain on the device; links to deleted custom categories may be reset.
5. Speech recognition and audio notes
Speech recognition starts at your request after a disclosure and the required system permissions. Audio is processed by the device’s system speech provider, such as Google, Apple or another installed service. Depending on the device, language and settings, the provider may send audio and technical information to its servers. The app receives recognized text; we do not save a separate audio recording for this feature. Saved text may be synchronized if synchronization is allowed.
Audio notes are a separate feature: at your request, the app records and saves an audio file on the device for playback or deletion. These audio files are not sent to Firestore. The absence of saved recordings during speech recognition does not mean that audio notes are not recorded.
You can use manual entry, stop recording or recognition, and revoke permissions in system settings. Revoking a permission does not delete text or audio notes already saved. The app is not designed for covert continuous listening.
6. Other device features
Microphone access is used for voice features; photo selection for attachments; notifications for local reminders; and system biometrics for unlocking protected lists. The app receives the result of biometric verification, not fingerprints or facial templates. Share-menu imports process the text you send to the app. Export through the system share menu transfers selected data to the app you choose.
Clipboard import suggestions are enabled by default if no different choice has been saved. On launch and return to the app, when the main screen is ready, the app reads clipboard text before import confirmation and may offer to import it. Adding it to lists requires your confirmation. Before import, the app does not persist the text or send it to a server as part of this check. After showing a suggestion, it stores only a hash of the text locally to avoid suggesting it again. A newly shown suggestion replaces the previous hash; detecting an empty clipboard while checks are enabled, or clearing app data, removes it. Dismissing a suggestion, restarting or disabling suggestions does not itself remove the hash. You can turn suggestions off in Settings; a saved refusal is respected. iOS may also request system permission to paste. After a confirmed import, the text becomes list content and may be included in allowed synchronization.
We do not use location, contacts, SMS or call-history access for app features, collect payment card details, or use advertising identifiers for advertising. Do not add passwords or information unnecessary for the purpose of lists or recordings. Sensitive information you choose to add will be processed as part of that content.
7. Analytics, diagnostics and service settings
Google Analytics for Firebase is enabled only after your separate choice. It processes app usage events, app and operating system versions, device information and an installation identifier; the provider uses the technical IP address, including to derive general geography. List, note and recording content is not intended to be sent to analytics. We do not use this analytics for personalized advertising.
Firebase Crashlytics is enabled separately for error diagnosis. It processes crash reports, stack traces, event times, device and app technical information, and installation identifiers. We limit error messages to technical information and do not add list content, passwords, emails or account identifiers to custom report fields.
Analytics and report transmission remain off until a choice is confirmed. If this device has no saved decision, an “Agree” / “Configure” prompt appears before the tutorial, including for signed-out users. “Agree” allows both telemetry categories. Both switches are preselected in the expanded settings, but collection starts only after “Save choices”; you can turn off either or both options and continue. Declining does not restrict core features. The choices, disclosure version, time, language and decision source are stored on the device and do not change on sign-in or sign-out. Saved refusals do not trigger further automatic prompts. Both options remain available in Settings: disabling one stops new transmission of the relevant telemetry, and locally stored unsent Crashlytics reports are deleted. Reports accumulated without permission are also deleted before Crashlytics is first enabled. Data already transmitted remains subject to provider retention periods and applicable deletion rules.
Firebase Remote Config receives an installation identifier and technical information to deliver feature availability and security settings. This exchange is separate from optional analytics. Update checks may contact Google Play or Apple services. Remote Config does not replace your choice to enable synchronization or telemetry.
8. Purposes and legal bases
- Providing the requested account, synchronization and support: performance of a contract or steps you request before entering a contract, where this basis applies.
- Optional analytics, diagnostics and processing requiring consent: separate consent. Operating system permissions and Terms acceptance do not replace required separate consents.
- Service security, abuse prevention and delivery of technical settings: legitimate interests in secure service operation, where permitted by applicable law and not overridden by your rights.
- Responding to binding lawful requests and fulfilling controller obligations: applicable legal obligations.
9. Recipients
Recipients may include Google/Firebase (Authentication, Firestore, Remote Config and telemetry you select), your sign-in and speech-recognition providers, the website hosting and network delivery providers (Yandex Cloud for shoppingliststat.com and Cloudflare for shoppingliststat.app), and the support email provider. Access is limited to what is needed for the stated purposes. We use applicable data processing terms and require processors to protect data consistently with our obligations and platform rules. Independent processing by a selected system provider is also governed by that provider’s policy.
We do not sell personal data or share it for cross-context behavioral advertising. When you export content, the apps or people you select become recipients. We may disclose the minimum necessary information in response to a binding lawful request or to protect legal rights.
Firebase privacy and processing periods
10. International processing
The developer is based in Russia. Providers may process data in other countries, including the United States; locations vary by service. We do not promise that all data remains in the user’s country. Applicable localization and international transfer requirements must be met independently of your consent to a feature. Transfers from the EEA, the United Kingdom and Switzerland use applicable provider terms and legally permitted transfer mechanisms; details of specific recipients and safeguards can be requested by email.
11. Retention and deletion periods
- Local data: until deleted in the app, app data is cleared or the app is uninstalled, subject to trash and system backup behavior. The app cannot remotely erase offline devices or copies made outside the app.
- Account and cloud content: while you use the account; after a verified request, we complete deletion from active systems under our control within 30 calendar days. Synchronization deletion records are removed with the account.
- Support requests and correspondence used to verify a request: until resolution and then for no more than 90 days, unless a specific legal requirement or dispute requires limited further retention. A technical deletion receipt without UID or email is retained for up to 30 days after completion.
Solely to prevent writes through a previously issued session after deletion, a technical block keyed by UID, without email or content, is retained for no more than 2 days after completion. It cannot restore the account. Once the request is completed, its operational record containing contact information is deleted; correspondence and the separate receipt follow the periods above.
- Provider periods differ from our request-handling deadline: Firebase Authentication states that deletion from live and backup systems occurs within 180 days after deletion is initiated; Crashlytics retains traces and associated identifiers for 90 days before starting removal from live and backup systems. These are not universal retention periods for all app data.
- Analytics events and identifiers are subject to the retention period configured in the Google Analytics project; provider technical logs and backups are subject to their applicable retention and deletion procedures. We do not treat disabling collection as immediate deletion of previously transmitted data. Contact us for current configuration details and deletion requests.
If a binding legal obligation requires retention of specific information, we limit its scope, access and use to that purpose and delete it when the basis ends. We explain the applicable exception and period when handling the request unless notice is prohibited by law. A technical error does not in itself justify indefinite delay.
12. Account deletion
In the app, open the menu → Account → Delete account. After checking the current session and receiving your confirmation, the app submits a request and waits for server acknowledgement. It then attempts to delete the account and associated cloud data immediately. Reauthentication is requested when needed to verify your identity. When deletion succeeds, the app confirms that the account and cloud data have been deleted; if all steps cannot be completed, it confirms that the request has been accepted for further processing. Closing the screen or declining additional identity verification after acceptance does not cancel the request. An operator processes unfinished requests within the stated deadline. A separate choice deletes local shopping data belonging to this account and associated files on this device; otherwise they are retained. An external route is available on the deletion page without installing the app. Signing out, disabling synchronization and uninstalling the app do not themselves delete the cloud account.
13. Security
Transfers use secure connections, and cloud data uses authentication and account-based access rules. Administrative request processing is separate from the user app. A local list lock does not promise separate database encryption or end-to-end cloud encryption. Protect your device with a system lock. Absolute security cannot be guaranteed.
14. Your rights
Depending on applicable law, you may request access and a copy of your data, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent. Send requests to head.stat@gmail.com. We verify identity proportionately and respond within the deadlines required by applicable law. Contacting us does not limit your right to complain to a competent data protection authority or seek a judicial remedy.
Where California privacy laws apply, their applicable rights to information, correction, deletion and non-discrimination are provided within the scope of those laws. We do not claim that the CCPA applies to every user and do not engage in sale of data or cross-context behavioral advertising.
15. Age
The service is intended for users aged 16 and above and is not directed at children under 16. Any applicable requirement for a legal representative’s involvement in entering a contract still applies. We do not collect a date of birth for ordinary use. If we learn that a child’s data has been processed contrary to applicable requirements, we will investigate and take necessary action, including deletion.
16. Website and policy changes
The website is available at the primary address shoppingliststat.com and the mirror address shoppingliststat.app. It stores your selected theme and language in localStorage. Technical requests to shoppingliststat.com are processed by Yandex Cloud, while requests to shoppingliststat.app are processed by Cloudflare. The website does not use optional advertising or analytics technologies.
Website cookies and local storage policy
We publish a revised policy when data processing changes. We notify you of material changes appropriately; where new consent is required, the relevant processing does not begin before your choice. Continued use is not consent to new optional purposes. You may request a copy of a previous revision by email.