Privacy
Deutsche Fassung: Datenschutzerklärung. Where the two differ, the German version prevails.
1. Who is responsible
Abdelhalim Ahmed - tropicalthink
Gisselberger Str. 2
35037 Marburg
Germany
Email: hi@tropicalthink.com
We have not appointed a data protection officer because the legal thresholds for one are not met. Send any privacy question to the address above.
2. What this policy covers
This policy applies to
- the website mitlist.me,
- the web app at app.mitlist.me and the mitlist apps for iOS and Android when they are connected to the official service,
- the API at api.mitlist.me that the apps and integrations talk to,
- the feedback board at feedback.mitlist.me.
mitlist is free software (AGPL-3.0). Anyone who runs it on their own server is responsible for that instance; we receive no data from it. See section 15.
3. Our principles
- No ads, and no selling of data.
- The apps and the web app contain no analytics or advertising trackers and build no usage profiles.
- Your household data lives on a server we run in the European Union.
- You can export your data and delete your account from inside the app at any time.
- We only process what is needed to run the service, bill Premium, and keep the service secure.
4. The website mitlist.me
Hosting. The website is a static site served through Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; for the EEA: Cloudflare Germany GmbH, Rosental 7, 80331 Munich). When you open it, Cloudflare processes the connection data needed to deliver the page and protect it from attacks: IP address, time, requested URL, referrer, and browser type. Legal basis: Art. 6(1)(f) GDPR (a secure, reachable site). Fonts and images are served by the site itself; no connection is made to Google Fonts or any other font service.
Cookieless page counts. On the website (not in the app) we use Cloudflare Web Analytics to see how often each page is read. It sets no cookies, stores nothing on your device, and does not fingerprint you; the result is aggregated and not tied to individual people. Legal basis: Art. 6(1)(f) GDPR (understanding which content is read). Because nothing is stored on or read from your device, no consent is required for it.
Mobile testing signup
When you join the testing list, we store your email, chosen platform (Android or iOS), signup time, and the version of the consent you gave. We use these details to arrange testing access and email you about the test, not for a newsletter. The list is private and does not create a mitlist account or a feature-board post. To invite you, we may add your email to Google Play testing or Apple TestFlight. We remove the signup when testing ends or when you withdraw. To withdraw or ask us to delete your signup, email hi@tropicalthink.com from the address you registered.
5. Accounts and sign-in
Email registration. When you create an account we process your email address, the name you choose, and a password that is stored only as a hash. We email you codes to confirm the address and to reset the password. Legal basis: Art. 6(1)(b) GDPR.
Sign in with Google or Apple. You can sign in with a Google or Apple account instead. Google (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) or Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland) then gives us your email address, your name, and an identifier for the account. We never see your password with that provider. The provider learns that you sign in to mitlist; its own privacy policy governs that. Legal basis: Art. 6(1)(b) GDPR.
Guest accounts. You can use mitlist without an email address as a guest. A guest account is tied to the device it was created on. A guest account that is unused for 30 days is locked; after another 180 days without a sign-in it is permanently anonymised. Legal basis: Art. 6(1)(b) and (f) GDPR (cleaning up abandoned accounts).
Sessions. After signing in, the app keeps an access token and a refresh token on your device or in your browser's storage. They are technically necessary to keep you signed in and are invalidated when you sign out or change your password.
6. Household data
mitlist exists to organise a household together. To do that we store what you and the other members of your household create: lists and items, chores and their completions, expenses, shares, and settlements, recipes and meal plans, pinwall notes, calendar entries, invitations, and uploaded photos and receipts, along with metadata such as timestamps and who created or changed each entry. Legal basis: Art. 6(1)(b) GDPR.
Visibility. Everything in a household is visible to every member of that household. If you enter data about other people, such as a flatmate's name on an expense, you do so on your own responsibility; enter only what those people would expect in a shared household.
Money. Expenses, amounts, and settlements are figures you type in yourself. mitlist does not connect to bank accounts and receives no payment data through the expenses feature.
Attachments. Uploaded files are stored in Cloudflare's R2 object storage and served only through the service to authorised household members. Abandoned uploads are cleaned up automatically. Each household has 1 GB of storage and each file may be up to 10 MB.
7. Features that send data somewhere or deserve a note
Receipt, list, and recipe scanner. Text recognition runs entirely on your device. A photo you scan leaves the device only if you then save it as an attachment yourself. No external AI service is involved.
Recipe import from a link. When you import a recipe from a web address, our server fetches that address and extracts the title, ingredients, and steps. The recipe site sees our server's address, not yours. Legal basis: Art. 6(1)(b) GDPR.
Invite links. Household invitations and shared recipes are links containing a random token. Anyone who has the link can open its target, so share invite links only with people you want in your household.
Home Assistant integration. If you connect your own Home Assistant installation, it reads your household data with an access key you generate. You can revoke the key in the app at any time. You are responsible for the Home Assistant installation itself.
8. Notifications and email
Push notifications. Push is optional and can be turned off in the settings. On iOS and Android we use Firebase Cloud Messaging (Google Ireland Ltd.) and Apple's notification service, which requires us to store a device token that is deleted when you sign out. In the web app we use your browser's Web Push service (with VAPID). The text of each notification, such as "chore due" or "new expense", passes through these services. Legal basis: Art. 6(1)(a) GDPR (your permission in the operating system or browser) and Art. 6(1)(b).
Email. Confirmation, password, and invitation emails, and the weekly household summary if you enable it, are sent through Amazon SES (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg), sending from the Frankfurt region. Amazon receives your email address and the content of the message, and processes them inside the EU. We send no marketing email. Legal basis: Art. 6(1)(b) GDPR.
9. Premium and payments
Households with more than four members need a Premium subscription. When you subscribe we record which account holds the subscription, which household it is assigned to, its term, its status, and the amount paid. Legal basis: Art. 6(1)(b) GDPR; billing records are kept under Art. 6(1)(c) GDPR for the statutory commercial and tax retention periods (up to ten years).
Buying on the web. Web payments are handled by Polar (Polar Software Inc., 2261 Market Street #4941, San Francisco, CA 94114, USA) as the merchant of record. Polar and its payment processors handle your payment details, billing address, and tax information; we never see full payment details. So that we can link the subscription to your account, we pass your account identifier and email address to Polar. Polar's privacy policy applies.
Buying in the app. In the iOS and Android apps the purchase runs through Apple or Google Play under their own terms. We receive a purchase receipt with a transaction identifier, the product, and the term, which we use to unlock Premium and to track renewals and cancellations.
10. Security and abuse prevention
Cloudflare. The web app and the API are reached through Cloudflare, which forwards requests to our server, blocks attacks, and processes IP addresses and connection data to do so. Legal basis: Art. 6(1)(f) GDPR.
Turnstile. Creating a guest account in the browser runs an invisible Cloudflare Turnstile check so that automated sign-ups do not overwhelm the service. Cloudflare receives the technical browser signals it needs; we receive only the pass or fail. The token is checked once and never stored against your account. Cloudflare's Turnstile Privacy Addendum applies. Legal basis: Art. 6(1)(f) GDPR.
App Check. The iOS and Android apps prove to our server that they are genuine installations using Firebase App Check (Google Ireland Ltd.), which verifies device attestations from Apple or Google. Household data is not involved. Legal basis: Art. 6(1)(f) GDPR.
Server logs. Our server logs errors and security-relevant events such as failed sign-ins, with IP address and time. Addresses that repeatedly misbehave are blocked temporarily. Logs are deleted after a short period unless they are needed to investigate an incident. Legal basis: Art. 6(1)(f) GDPR.
11. Crash reports
When the app crashes or hits an unexpected error, the web app, the apps, and the server send an error report to a GlitchTip instance we operate. A report contains the technical trace of the error (stack trace), app and operating system version, device type, and environment. Household content, names, and email addresses are deliberately excluded, and no performance or usage data is collected. Reports are kept only as long as they are needed to fix the error. Legal basis: Art. 6(1)(f) GDPR (a stable service).
12. Feedback
In the app. The feedback area in the app lets you report wishes and bugs. We receive your text, the screen you were on, the app version, platform, and language, and store them in our request tracker, which runs on Cloudflare Workers and Cloudflare D1.
Feedback board. The public board at feedback.mitlist.me can be read without signing in. To vote, post, or comment you sign in with your mitlist account, and the board then sets a strictly necessary session cookie. Posts and comments store your account identifier and show your first name. Legal basis: Art. 6(1)(b) GDPR.
13. Hosting, recipients, and international transfers
The service (web app, API, and database) runs on a server we manage in a data centre in Heerlen, the Netherlands. Database backups are encrypted and overwritten after a limited period. The following providers process data on our behalf or as independent controllers:
| Recipient | Purpose | Location / transfer basis |
|---|---|---|
| Server provider (Heerlen data centre) | Runs the web app, API, and database | Netherlands (EU) |
| Cloudflare, Inc. | Website, network and protection, Turnstile, R2 object storage, feedback tracker (Workers, D1) | USA; EU standard contractual clauses, certified under the EU-US Data Privacy Framework |
| Google Ireland Ltd. (Firebase) | Push notifications, App Check, Sign in with Google | Ireland; transfers to Google LLC (USA) under the EU-US Data Privacy Framework and standard contractual clauses |
| Apple Distribution International Ltd. | Sign in with Apple, push on iOS, in-app purchase | Ireland; transfers to Apple Inc. (USA) under the EU-US Data Privacy Framework |
| Amazon Web Services EMEA SARL | Transactional email (Amazon SES) | EU (Frankfurt); Luxembourg contracting entity |
| Polar Software Inc. | Payment processing for Premium on the web (merchant of record) | USA; independent controller for payment processing |
| Google Play / Apple App Store | App distribution, in-app purchase | See the privacy policy of the respective store |
Where data leaves the EEA we rely on adequacy decisions of the European Commission (Art. 45 GDPR, in particular the EU-US Data Privacy Framework) or on the EU standard contractual clauses (Art. 46(2)(c) GDPR). The current technical setup is published on the transparency page.
14. Retention and deletion
- Account and household content stay as long as your account exists.
- Account deletion. When you delete your account in the app, your email address, name, password, and avatar are removed immediately, every session is ended, and the account is permanently anonymised. Content you added to a shared household stays in that household for the remaining members but is no longer linked to your account. Delete the content or the household first if you do not want that.
- Households and their content are deleted when the household is deleted.
- Guest accounts are locked after 30 days of inactivity and anonymised after another 180 days.
- Billing records for Premium are kept for the statutory periods of up to ten years.
- Push tokens are deleted when you sign out; logs and crash reports after a short period.
- Backups are overwritten after a limited period, so deleted data disappears from them as well.
Export. You can export your expenses as CSV or JSON from the app at any time. We provide other data on request in a common format (Art. 20 GDPR).
15. Self-hosted instances
Whoever runs mitlist on their own server is responsible for the processing there. The mitlist project receives no household data, no usage data, and no crash reports from such instances; optional crash reports go only to the endpoint the operator configures. Which services an instance uses is the operator's decision, and the documentation in the source code describes every option.
16. Children
The official service is intended for people aged 16 and over. Younger people may use it only with the consent of a parent or guardian. If we learn that an account was created without that consent, we delete it.
17. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on Art. 6(1)(f) GDPR (Art. 21). You can withdraw any consent at any time with effect for the future (Art. 7(3)). An informal email to hi@tropicalthink.com is enough, and you can delete your account and data yourself in the app at any time.
You also have the right to lodge a complaint with a data protection authority (Art. 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de. You may also contact the authority where you live.
18. Changes
We update this policy when the service, the providers we use, or the law changes. The current version is always at mitlist.me/privacy, dated at the top. We announce significant changes in the app or by email.