Privacy policy
Core features work offline, while the connection to the external app update provider is used to check for and download updates.
Last updated: August 23, 2026
Effective from: August 5, 2026
Data controller
The controller of personal data processed in connection with the ShopSquirrel app and shopsquirrel.app website is Grzegorz Kniażuk, a sole trader operating under the business name Grzegorz Kniażuk Software Development, ul. Garbarska 18A/98, 20-340 Lublin, Poland (the “Controller”).
You can contact the Controller at kontakt@kniazuk.dev. The Controller has not appointed a data protection officer, as it is not required to do so under applicable law.
Locally stored data
The data you enter in the app — shopping lists, products, categories, and notes — is stored locally on your device in a local database by default. The Controller has no remote access to data stored only locally.
Access to that data depends on your device security and on the apps or services to which you choose to send a list or backup. You can permanently delete the data at any time from the app settings (Settings → Clear app data).
After you accept the Terms, the app stores a local record containing the Terms version, Privacy policy version, date and time, and selected language. The record is not sent to the Controller. You can remove it by clearing all app data in system settings, uninstalling the app or, on the web version, clearing site data, subject to system backup and restore mechanisms.
Sharing and backups
ShopSquirrel does not transmit the content of your lists to the app update provider. Using list sharing or backup export transfers the selected content outside the app’s local database.
Export creates an unencrypted JSON file containing all shopping data covered by the backup: list names and statuses, reminder dates, items with quantities, categories and notes, and the product and category catalogues. Anyone who gains access to the file can read its contents.
In the mobile app, the file is created temporarily in the cache and passed to the system share sheet; on the web, it is downloaded by the browser. You choose the app, person or service that receives the file and where it is saved. The Controller does not receive a copy, choose the destination or have the ability to delete the file from the selected service.
An imported file is selected through the system document picker or browser and is then read and validated locally. Its data replaces the current app data only after confirmation; the file contents are not sent to the Controller. ShopSquirrel attempts to remove its own temporary cache copies after the operation, but it does not delete the source file or copies stored by the selected recipient.
Sharing a list and exporting a backup occur only at your request. Your chosen app or service receives the transferred content and processes it under its own privacy rules; it may also store the file in the cloud, disclose it further or transfer it outside the EEA under its own terms.
When you share a list using a ShopSquirrel link, the list content is Base64URL-encoded in the URL fragment after the “#” sign. The fragment is not sent in the HTTP request to the ShopSquirrel website server. Base64URL encoding is not encryption, and the content is received by the people and apps or services with whom you share the link.
Before creating a link, you can exclude purchased items and notes. If you enable an access code, the list content is encrypted locally with AES-GCM before it is placed in the link; the code is not part of the link and must be sent separately. Link expiry is checked locally, can be bypassed, and cannot revoke a link that has already been sent without a server-side service.
Updates and website
The app’s core features work without internet access. When the device is online, the app automatically connects to Expo / EAS to check for and download updates. An update request may include the IP address, operating system and platform, Expo project ID, runtime version, channel and protocol version, and a randomized token used to determine whether an installation downloaded an update. Expo states that this token is not a unique device identifier. Under Expo’s privacy policy, the provider may also collect error, performance and app interaction data and project usage statistics. The connection does not include the content of your lists, products, categories, or notes.
ShopSquirrel does not use any external push notification service or the update provider’s analytics service. Notifications are scheduled locally and do not send a push token or notification content to the Controller or the update provider.
When you visit shopsquirrel.app, the hosting provider Vercel Inc. may receive technical request data, in particular your IP address, approximate location derived from it, browser type and settings, device and operating system information, language, requested address, date and time, referring page, and diagnostic and error log data.
Vercel creates platform-level Observability events for requests made to the website. The Controller has not implemented Vercel Web Analytics, Speed Insights or other advertising tools and does not use this data to profile or track users for marketing purposes.
List content placed after the “#” sign is read on your device and is not sent in the HTTP request to Vercel or the Controller. Vercel receives the part of the address before the “#” sign, but not the fragment containing the list.
Cookies and browser storage
The ShopSquirrel website stores the functional “shopsquirrel-theme” cookie only when you use the theme switch yourself. The cookie is used to remember your chosen theme and apply it on your next visit.
The cookie applies on shopsquirrel.app and expires 12 months after the last theme change. Vercel may technically process it as the hosting provider. It is not used for analytics, advertising, profiling or cross-site tracking.
You can remove or block the cookie in your browser settings or by clearing site data. If it is removed or blocked, the website uses your system setting and does not remember your manual choice. The cookie is necessary to provide the theme preference feature you requested and falls within the exception in Article 399(3)(2) of the Polish Electronic Communications Law, so separate consent is not required.
Summary of purposes, recipients, transfers and retention
App updates (Expo / EAS): when your device is online, 650 Industries, Inc. receives the technical data needed to check for and download updates, in particular the IP address, operating system and platform details, Expo project ID, runtime version, channel, protocol version, and a randomised update token. This data is processed to provide the ShopSquirrel service and deliver updates under Article 6(1)(b) GDPR, and for security, error diagnosis and the establishment, exercise or defence of legal claims under Article 6(1)(f) GDPR. Expo acts here as the Controller’s processor, may use further providers in line with its documentation, and for transfers outside the EEA applies the safeguards described there, in particular the EU–U.S. Data Privacy Framework or Standard Contractual Clauses where required. The data is retained for the period needed to deliver the service, ensure security, diagnose errors and meet legal obligations, and is then deleted or anonymised in line with Expo’s policy.
Website (Vercel): when you visit shopsquirrel.app, Vercel Inc. receives technical request data, in particular the IP address, approximate location derived from it, browser type and settings, device and operating system information, language, requested address, date and time, referring page, and diagnostic and error log data. This data is processed to provide the ShopSquirrel service under Article 6(1)(b) GDPR and for security, abuse prevention, error diagnosis and the establishment, exercise or defence of legal claims under Article 6(1)(f) GDPR. Vercel acts as the hosting provider and a separate controller of service-generated data, may use further providers in line with its documentation, and for transfers outside the EEA applies the safeguards described there, in particular the EU–U.S. Data Privacy Framework or Standard Contractual Clauses where required. The data is retained for the period needed to provide the service, ensure security, meet legal obligations and pursue legitimate interests, and is then deleted or anonymised in line with Vercel’s policy.
Email contact (Hostinger): when you write to kontakt@kniazuk.dev, the Controller processes your email address, name or business name if provided, message content and attachments, and correspondence metadata such as sender and recipient addresses and the sending date and time. This data is processed to respond and handle the matter under Article 6(1)(b) GDPR where the message concerns entering into or performing a contract, Article 6(1)(f) GDPR where the legitimate interest is handling enquiries and protecting against claims, and Article 6(1)(c) GDPR where required by a legal obligation. Hostinger is the processor of email correspondence, and the sender’s email provider and transmission infrastructure also participate in delivering the message under their own rules; for transfers outside the EEA, the safeguards described in those providers’ documentation apply, in particular Standard Contractual Clauses where required. Ordinary correspondence is retained for up to 12 months after the matter is closed, while data required for claims or by law may be retained longer in line with those criteria.
Sharing and export with an app or service you choose: when you share a list or save a backup outside ShopSquirrel, the app, service, or app store you choose receives the transferred data and processes it under its own rules. The Controller does not choose that recipient, does not determine how that provider later uses the data, and does not retain a copy of list content shared through the URL fragment. Any transfer outside the EEA and any retention period for that data depend on the rules of the provider you selected.
Irrespective of the above, data may be disclosed to public authorities where required by law.
Your rights
You manage locally stored content directly through the app features, including deletion, export, and import.
For data processed by the Controller, you may request access, rectification, erasure, restriction of processing and, where the statutory conditions are met, data portability. You may object to processing based on Article 6(1)(f) GDPR for reasons relating to your particular situation. These rights may be limited where provided by law.
You can send a request to kontakt@kniazuk.dev. If you believe that your data is processed unlawfully, you have the right to lodge a complaint with the President of the Polish Personal Data Protection Office; information on filing a complaint is available at uodo.gov.pl.
Voluntary provision and automated decisions
Using the app’s core features does not require an account or providing the Controller with your name, email address or list content. Providing data in a message is voluntary, but without contact details the Controller may be unable to respond. Technical data is transmitted automatically and is required to display the website or check for updates; blocking it may prevent those operations.
The Controller does not make decisions about users based solely on automated processing that produce legal or similarly significant effects, and does not conduct profiling or direct marketing.
Changes to this privacy policy
This privacy policy may be updated together with new app versions. The current version is always available from the app side menu.