Privacy Policy
The OneList app does not collect your data. There is no OneList server, no account to create, and no analytics in the app. This website counts visits; see This website below.
Everything you put into the app — your meals, your plan, your shopping lists, your store layouts — is stored on your device and, if you are signed in to iCloud, in your own iCloud account. It is not sent anywhere else. The developer cannot see it, cannot retrieve it, and has no way to access it.
What OneList stores, and where
On your device
OneList keeps a database on your device containing what you have entered:
- Meals and their ingredients
- Your weekly plan and meal slots
- Shopping lists, including completed trips
- Stores and the aisle order OneList learns from how you shop
- Regular and staple items
Alongside that, OneList stores a small number of settings — which tab opens at launch, whether the iPad side panel is open, and similar interface preferences.
OneList also generates a random identifier the first time it runs. It is used for one purpose: noticing that a single shopping trip received taps from two different devices, so OneList knows not to learn a store's aisle order from two people shopping at once. It is a random value, it is not linked to you or to your device's hardware, and it never leaves your household's own data.
In your iCloud account
If you are signed in to iCloud, OneList synchronises the data above to your private iCloud database so it is available on your other devices. This uses Apple's CloudKit.
This is your iCloud storage, under your Apple Account. Apple's privacy policy and iCloud terms govern it. The developer of OneList is not a party to it and has no access to it.
OneList works fully without iCloud. If you are signed out, everything stays on the device and simply does not sync.
When you share a household
If you invite someone to your household, OneList creates an iCloud share. The people you invite can then see and edit the household's meals, plan, lists and stores.
Two things worth knowing:
- The household's data lives in the iCloud account of whoever created it. If that person deletes the app or their iCloud data, the shared household goes with it. OneList says so in Settings.
- You choose who is invited, and you can remove them, or leave a household you were invited to, from Settings.
Invitations are delivered by Apple, through whichever app you send them with. OneList does not store or transmit the email addresses or phone numbers you invite — Apple's sharing system handles that.
What the OneList app does not do
These are absences, and they are deliberate. They describe the app on your device — this website is covered separately below:
- No tracking. OneList does not track you across apps or websites, and contains no tracking or advertising technology of any kind.
- No analytics. There is no analytics SDK in the app, no crash reporting service, and no telemetry.
- No third-party services. OneList contains no third-party network code. It makes no network requests of its own at all — the only services it contacts are Apple's own CloudKit and the App Store.
- No account. There is nothing to sign up for and no password to create.
- No advertising. OneList shows no ads and shares nothing with advertisers.
- No sale of data. There is no data to sell, and none would be sold if there were.
- No access to your camera, photos, microphone, location or contacts. OneList does not request these permissions because it does not use them.
Purchases
OneList offers optional paid subscriptions and a one-time purchase. These are handled entirely by Apple's App Store.
The developer never receives your payment details, card number, or billing address. Apple tells the app only whether a valid purchase exists for the Apple Account currently signed in — nothing more. That check happens on your device and is not recorded anywhere by OneList.
Apple provides the developer with aggregate, anonymised sales and usage reports through App Store Connect. These do not identify individual users. Apple's own privacy policy covers what Apple collects when you make a purchase.
Diagnostics
OneList writes diagnostic messages to your device's system log, as most apps do. These stay on your device and are not transmitted to the developer.
If you have separately chosen to share analytics and crash reports with app developers in Settings → Privacy & Security → Analytics & Improvements, Apple may include OneList crash reports in what it shares. That is an Apple setting, it is off unless you turned it on, and you can turn it off at any time. Reports delivered this way contain diagnostic information about the crash, not the contents of your meal plan.
This website
onelist.vlkea.dev is separate from the app, and it does count visits. The app on your device is covered above and collects nothing; this section is about the pages you are reading right now.
The site is static files hosted by Cloudflare, with Cloudflare Web Analytics enabled. When you load a page here, a small script records the page address, the address you arrived from, your approximate country, and your browser, operating system and device type, along with how quickly the page loaded.
- No cookies. Nothing is stored in your browser — no cookie, no local storage, no identifier of any kind.
- No profile, and no following you. There is no identifier to connect one visit to the next, or this site to any other. Cloudflare's Web Analytics does not build a profile of you.
- Counts, not people. What the developer sees is aggregate — how many people read a page and roughly where from. There is no way to look up an individual visitor.
- Nothing you type in the app reaches this site. Your meals, plan and lists are not on this website and never pass through it.
Cloudflare processes your IP address in order to serve the page and to derive the country, and does not retain it for analytics. Cloudflare acts as the developer's processor for this; their privacy policy is at cloudflare.com/privacypolicy.
The legal basis is legitimate interest in knowing whether the site is read and working. There is no consent banner because there is nothing stored on your device to ask about — if you would rather not be counted at all, a content blocker or your browser's tracking protection will stop the script, and the site works exactly the same without it.
Exporting and deleting your data
Export. Settings → Export household writes everything OneList holds to a JSON file and hands it to the iOS share sheet, so you decide where it goes. This is your data in a readable, portable form, and it is available whether or not you have a subscription.
Deletion. Deleting the app removes the database from that device. To delete the copy in your iCloud account, use Settings → Apple Account → iCloud → Manage Account Storage. Because the data is in your own iCloud account, you delete it directly rather than asking the developer to do it — the developer has no copy to delete and no ability to reach yours.
If you are a member of someone else's household, leaving it from OneList's Settings removes your access. It does not delete the household, because it is not yours to delete.
Children
OneList is a meal planning app for general audiences. It does not knowingly collect information from anyone, including children, because it does not collect information at all.
Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR gives you rights over your personal data, including access, correction, deletion and portability.
OneList is built so that these rights are exercised directly rather than by request: the data is in your possession, the export gives you portability, and deletion is in your hands as described above. The developer does not hold your household data and therefore cannot produce, correct or delete it on your behalf.
For data Apple holds — your Apple Account, your iCloud storage, your purchase history — Apple is the controller. Apple's privacy policy at apple.com/legal/privacy explains how to exercise your rights with them.
Changes to this policy
If OneList's behaviour changes in a way that affects this policy, the policy will be updated and the effective date above will change. Material changes will be noted in the app's release notes.
Contact
Questions about this policy:
Olli Saastamoinenonelist@vlkea.dev