Privacy policy
This privacy policy explains how Lofotind AS (“we”, “us”) processes personal data when you use the LiveList mobile application and related backends, websites, and invite links (together, the “Service”).
1. Who is responsible
The data controller is Lofotind AS, Norway. Privacy requests: support@livelist.no.
2. What LiveList is
LiveList is a real-time shared list app. You can create generic lists (for example planning, packing, shopping, or everyday tasks), add items with optional amounts, photos, and links, share lists with friends, see changes sync live, use tags and list history, receive push notifications and reminders, and optionally subscribe to LiveList Plus.
3. Data we process
Depending on how you use the Service, we may process:
- Account and profile — Firebase Auth identifiers from Sign in with Apple or Google (provider user ID; email and name when the provider supplies them). On your LiveList account document we store display name, profile photo URLs, theme and profile colour, locale, onboarding flag, last-online time, membership/subscription status, and optional tag order. Email from the identity provider is held in Firebase Auth; it is not copied into the Firestore account document.
- List content — list names and settings; items (name, description, amount/unit, mark/completion state, assignee, optional item URL and photos); list history entries (who changed what); and tags you apply to lists.
- Images — profile and item photos (and thumbnails) in cloud storage. If you sign in with a provider photo, we may import a copy into our storage so the app can display it consistently.
- Friends and sharing — friend relationships, friend requests, and which account IDs a list is shared with. Signed-in users can look up other users’ basic profile fields needed for friends and sharing (for example name and photo).
- Invites — invite link metadata (who created the link) and invite-click records used for deferred matching after install (platform, user agent, a salted hash of the IP address — not the raw IP — and claim status). Matching is short-lived in the product flow; click records are not currently auto-purged by a scheduled job.
- Notifications and reminders — FCM device token on your account; notification preference settings; reminder schedules (list id, list name, time); and short-lived notification outbox documents. Push content can include list names and other users’ display names.
- Suggestions — item name suggestions tied to your account for autocomplete.
- Subscriptions (Plus) — entitlement and product identifiers, renewal/expiry and billing-period metadata, and store (App Store / Play), synced via RevenueCat. Full payment card details are processed by Apple or Google, not by us.
- Diagnostics — optional client exception logs we store to fix bugs (message, stack trace, platform/OS/app runtime info, and sometimes your user id). We do not currently use Firebase Analytics, Crashlytics, advertising SDKs, or third-party product-analytics platforms.
- Link previews on device — if an item has a URL, your device may fetch that URL to show a title/favicon. That request goes from your device to the third-party site; we do not store the preview payload in our database.
- Support — messages you send to support@livelist.no.
4. Why we process data
- Provide and sync the Service — accounts, real-time lists, images, friends, invites (contract / GDPR Art. 6(1)(b)).
- Notifications and reminders — features you enable (contract / legitimate interests).
- Plus subscriptions — unlock and maintain paid features (contract).
- Reliability and security — exception logs, abuse prevention, invalid push-token cleanup (legitimate interests).
- Legal obligations — where law requires (Art. 6(1)(c)).
- Support — respond to your requests (contract / legitimate interests).
5. Who processes data for us
LiveList runs primarily on Google Firebase / Google Cloud (Authentication, Firestore, Cloud Storage, Cloud Functions, Hosting, FCM). Our backend functions are configured in the us-central1 region, so processing often occurs in the United States as well as elsewhere Google operates. Other parties:
- Apple — Sign in with Apple; App Store billing
- Google — Google Sign-In; Google Play billing
- RevenueCat — subscription entitlement sync between the stores and our backend
People you add as friends or share lists with can see the list content and profile information the app exposes for that purpose. We do not sell personal data. International transfers rely on the safeguards those providers use (for example Standard Contractual Clauses) where required.
6. Retention and account deletion
We keep account and list data while your account exists. Soft-deleted list items are hard-deleted by a scheduled job after about 24 hours. Notification outbox documents are removed after send.
In the app you can delete your account (Settings → Privacy → Delete account). That process removes your account document, lists you own (including items and history), related item suggestions, friendship edges it cleans up, and profile/item images associated with that cleanup, then signs you out.
It does not automatically remove everything everywhere:
- Your Firebase Auth user (Apple/Google sign-in) may remain until further deletion is completed with us or the provider.
- Some related records (for example reminders, list tags, notification settings, invite links/clicks, or diagnostic logs) may remain and can be cleaned up on request.
- Content on lists owned by others may still reference your account id (for example share membership or assignees) until those lists are updated.
- App Store / Play subscriptions must be cancelled with Apple or Google; RevenueCat/store records follow their retention rules.
- Caches on your device are not under our control.
Support emails may be kept as needed to handle your request and for ordinary business records. Contact support@livelist.no if you need help completing deletion.
7. Your rights
Under GDPR (and related rules where applicable), you may have the right to:
- access your personal data
- rectify inaccurate data
- erase data
- restrict or object to certain processing
- data portability
- lodge a complaint with a supervisory authority (in Norway: Datatilsynet)
Use in-app controls where available, or email support@livelist.no.
8. Children
LiveList is not directed at children under 13 (or the higher digital-consent age required where you live). Do not create an account if you are below that age.
9. Changes
We may update this policy. The effective date above will change when we do. Continued use after an update means you acknowledge the revised policy.
10. Contact
Lofotind AS · LiveList
Email:
support@livelist.no