Privacy policy
Last updated: 18 September 2026 · Version française
In short
- Your shopping lists stay yours. We do not sell them, we do not mine them for advertising, and we do not share them with anyone outside the members you invite.
- No advertising, no analytics, no crash reporting. The app contains no ad SDK, no usage-statistics tool, and no cross-app tracker.
- We do not ask for your location, contacts, camera, microphone or photos.
- What we actually hold: your Google account email address, your first name, and the contents of your lists.
- Other members of your household can see who added and who ticked off each item. That is the most surprising thing about this app: we spell it out below.
- You can export your lists and delete your account from inside the app, without writing to us.
- One exception to deletion: we keep your subscription records, because tax law requires it.
1. Who is responsible for your data
The data controller, under the General Data Protection Regulation (GDPR), is [OWNER: full legal entity name, legal form, company registration number], [OWNER: registered postal address].
For any question about this policy or your data, write to [OWNER: contact email address].
2. What we collect, and why
Your account
You sign in with your Google account. Firebase Authentication, the Google service we use, then holds your email address and an internal account identifier (a "uid"). The app itself keeps only that uid and your first name.
We never see your password — it is never sent to us; sign-in happens entirely at Google.
Your first name
When you share a list, we publish your first name only to the other members of that list, so they can tell who did what.
You do not type that name: our server derives it from the name on your Google account, keeping only the first word. If that name looks like an email address, we keep only the part before the at-sign. Your full email address is never published to other members, nor is your surname or your profile photo.
One point of honesty: this name is not verified. We show what your Google account declares. Inside a household, one person could in principle appear under another's first name. It is a readability cue, not proof of identity.
Your lists
The content you create: your lists, items, quantities, aisles, and any list snapshots you keep.
What you buy often
The app counts, on your phone only, how many times you add each item. That is how it can offer your usual products first. This count never leaves the device — it is not sent to us or to anyone else.
Notifications
If you turn on notifications for a shared list, we keep your preferences (which lists, your quiet hours, your time zone) and the technical tokens that let a notification reach your devices.
An installation identifier
The Firebase libraries we use generate an identifier specific to your copy of the app (Firebase Installations). It lets Google's services tell one installation from another. It is tied neither to your identity nor to any advertising, and it disappears when you uninstall the app.
3. What we do not collect
This list matters as much as the previous one. The app contains:
- no advertising SDK — no ad kit is built into the app;
- no analytics — no usage statistics are sent to us;
- no crash reporting;
- no cross-app tracking — no advertising identifier, and no tracking prompt on iOS;
- no access to your location, camera, contacts, microphone or photos.
On Android, the app requests exactly two permissions: showing notifications, and restarting after a reboot so your scheduled reminders are not lost.
4. What other members of your household can see
This is the part people discover late, so here it is plainly. As soon as you join a shared list, the other members of that list can see:
- your first name, as described above;
- which items you added, by name;
- which items you ticked off, by name, and how long ago;
- all the content of the list, of course.
In other words: on a shared list, shopping is not anonymous. If you tick off "chocolate" at 10 pm, whoever shares the list can see it.
What other members cannot see: your email address, your surname, your location, your other lists, or what you usually buy.
Invitation links
An invitation link is a key: anyone holding the address can join the list, even if the link was not meant for them. There is no second check. Share it as you would share a key to your home, and revoke it from the app if you have any doubt.
An invitation link stops working 30 days after it is created. If you open a link before installing the app, your phone keeps it for 72 hours to finish joining on first launch, then forgets it.
5. Our legal basis
| What we do | Legal basis (GDPR) |
|---|---|
| Create your account, keep your lists, sync them across your devices | Performance of a contract — Article 6(1)(b) |
| Share a list with your household, publish your first name to its members | Performance of a contract — Article 6(1)(b) |
| Send you shared-list notifications | Your consent — Article 6(1)(a) (you turn them on, you turn them off) |
| Manage and bill your Premium subscription | Performance of a contract — Article 6(1)(b) |
| Keep the accounting records for that subscription | Legal obligation — Article 6(1)(c) (tax and accounting obligations) |
| Protect the service against abuse (rate-limiting invitations, for example) | Legitimate interest — Article 6(1)(f) |
6. Who your data is shared with
We sell no data. We pass none to anyone for advertising. The only third parties that process it are the following technical providers, acting on our behalf:
Google (Firebase)
Google Ireland Limited and Google LLC host the whole service: authentication, the database holding your lists, server-side processing, the hosting of this website, notification delivery, and the installation identifier mentioned above. Google acts as a processor under its data processing terms.
RevenueCat
If you take out a subscription, RevenueCat, Inc. handles validating it with the App Store and Google Play. The only data we send it is your internal account identifier (the uid). We send it neither your email, nor your first name, nor any attribute describing you, nor any of your list content.
Like any payment SDK embedded in an app, theirs separately collects technical data about the installation and the transaction for its own operation. We do not choose that data and have no access to it; it falls under RevenueCat's own privacy policy.
To be honest about one point: when you delete your account, that identifier remains at RevenueCat. Our deletion does not currently trigger any erasure on their side. That identifier alone does not name you, but it persists. If you want it erased, write to us and we will make the request.
lesfoodies.com
When you import a recipe, or when the app refreshes its aisle dictionary, it queries lesfoodies.com. What leaves your phone in that case is a recipe identifier or a six-digit code, and nothing else: neither your list content nor your identity.
Apple and Google, as app stores
If you buy a subscription, the transaction happens at Apple or Google. They hold your payment details. We never see your card number.
7. Where your data is stored
Your lists are stored in Belgium, in Google Cloud's
europe-west1 region — that is, inside the European Union.
Our server-side processing, however, runs in the United States
(region us-central1). In concrete terms, operations such as
joining a shared list, creating an invitation, deleting a list or sending a
notification pass through servers located outside the European Union.
That is a transfer under Chapter V of the GDPR. It relies on the European Commission's Standard Contractual Clauses, incorporated into Google Cloud's data processing terms, together with Google's technical measures (encryption in transit and at rest). We would rather say so plainly than leave it in an annex.
Finally, if you use the app without an account, your lists do not leave your phone — with one exception, described next.
Android automatic backup
On Android, the system's automatic backup is enabled for this app. That means the database holding your lists is copied to Google's backup servers, tied to your Google account, even if you use the app without an account. It is what lets you find your lists again after changing phone or reinstalling.
We have deliberately excluded the file holding invitation tokens from that backup, so an access key does not end up in a backup.
You can turn this backup off in Android's settings (System › Backup). We have access to neither its contents nor its management: it happens between your phone and your Google account.
8. How long we keep things
- Your account and your lists: as long as your account exists. You can delete it at any time.
- Deleted lists: their content is erased from our servers within 30 days at most — in practice about fifteen.
- Invitation links: they expire after 30 days. Previews of expired invitations are swept daily.
- Technical notification records (what stops us sending you the same push twice): 14 days at most.
- Subscription records: see below.
The one thing we keep after an account deletion
When you delete your account, we keep your subscription and payment records: the fact that a subscription existed, its dates, and the billing events relating to it, tied to your account identifier.
Why: tax and accounting law requires us to retain the supporting records for our revenue. We cannot erase them on request, and this is the only such case.
Everything else goes: your lists, your first name, your household memberships, and your name on every item you had added or ticked off — including in other members' lists. After an account deletion, your identifier survives on no live shared document.
If you owned a shared list and chose to keep it, it is not destroyed with your account: it is handed to another member, who becomes its owner and can from then on rename it, delete it, or manage its invitations. The household loses neither its list nor control of it. Your name is removed from it, as it is everywhere else. If you were the only member left, the list is deleted with the account.
One technical caveat, for accuracy: erasing your notification preferences (the lists you follow and the delivery tokens) is triggered by the app at the moment of deletion. In rare cases — if the app is interrupted at the wrong moment, for instance — that erasure may not complete, and those preferences may remain on our servers. Write to us and we will delete them by hand.
9. Your rights, and how to exercise them
The GDPR gives you rights over your data. Two of them can be exercised directly in the app, without writing to us:
- Portability and access — Settings › "Download my data (portability)". The app produces a JSON file you can keep or move to another service. It contains the lists you own, with their items: lists you have merely joined are excluded, because they belong to whoever created them. If you also want the data you entered into a joined list, write to us and we will send it to you.
- Erasure — Settings › "Delete my account". Deletion works as described in section 8.
For the other rights, write to us at [OWNER: contact email address]:
- Rectification — correcting inaccurate data. Since your first name comes from your Google account, correcting it at Google corrects it here at your next sign-in.
- Objection — objecting to processing based on our legitimate interest.
- Restriction — asking us to stop using your data without erasing it, during a dispute for example.
- Withdrawing consent — for notifications, simply turn them off in the app.
We answer within one month. If our answer does not satisfy you, you may lodge a complaint with the CNIL, the French data protection authority, at 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at cnil.fr. You may also complain to the supervisory authority of your own country of residence.
10. Children
Mirilio is not intended for children. You must be at least 16 to create an account — see the terms of service. We do not knowingly collect data about a child under 16. If you believe we have, write to us and we will delete the account.
11. Security
Traffic between the app and our servers is encrypted (HTTPS/TLS). Access to your lists is enforced server-side: only members of a list can read or change it, and that rule is applied by the server, not by the app.
No system is perfectly secure. If you find a vulnerability, write to us rather than publishing it, and we will deal with it.
12. Changes
If we change this policy, we update the date at the top of the page. For a significant change to what we collect or who receives it, we will tell you in the app before it takes effect.