Who is responsible for your data
BlueList is developed and operated by Lasky, an independent app developer. For the purposes of the EU General Data Protection Regulation (GDPR), Lasky is the data controller for the personal data described in this policy.
For any privacy question, or to exercise your rights, contact us at laskyfeedback@gmail.com.
Your account
To use BlueList — shopping lists, recipes, cookbooks and meal planning — you need an account. We only ask for the essentials:
- Your email address and a password, or your Google or Apple account, used solely to sign you in securely.
- A display name and, if you want one, a profile photo, shown to the people you share content with.
We do not collect your phone number, your location, or any other personal detail beyond the above.
Your lists, recipes and meal plans
Everything you create in BlueList — shopping lists, products, recipes, cookbooks and your meal calendar — is stored on your device and works without any cloud account.
If you have an active Premium subscription, that content is also synced to the cloud so you can use it on all your devices and share it with whoever you choose. Without Premium, your data never leaves your device, except for content you explicitly share.
This content is yours. We do not read it, analyse it, or use it for any purpose other than making the app work for you.
Loyalty cards
BlueList lets you store your supermarket loyalty cards so they are ready at the checkout. For each card we store only the name you give it, its number or barcode and that barcode’s format, and the colour you pick.
Cards are always stored on your device. If you have Premium, they are also copied to your private space in Firebase — encrypted in transit and at rest — so you have them on your other devices and on your watch. Only you can access them: they are never shared with other users, never passed to third parties, and never sent to any supermarket.
Keep in mind that a loyalty card number can identify you to the retailer that issued it. If you would rather not have it stored, delete the card in the app: it is removed from your device and from the cloud.
Camera and photos
BlueList can use your camera to scan product and loyalty-card barcodes so you don’t have to type them. Images captured while scanning are processed there and then, on your own device: they are never stored or sent anywhere.
You can also pick images from your gallery for recipes, cookbooks or your profile. Those are only uploaded to the cloud if you select them.
Sharing with other people
BlueList lets you share recipes, cookbooks and shopping lists through a link or an invite code. It is worth knowing exactly how that works:
- Anyone holding the link or code can see the shared content, even if you did not invite them personally.
- Your display name and profile photo are visible to the people taking part in that content.
- You can stop sharing at any time from the app. When you do, the shared content is deleted from the cloud and the link stops working for everyone at once: access cannot be withdrawn from a single person.
- For shared lists you can also generate a new code. The old one stops working, but anyone who already joined stays in until you stop sharing the list altogether.
- Whatever someone has already imported is theirs. Importing a recipe or a cookbook creates an independent copy in their account. Stopping sharing cuts access to the original, but it does not delete or retrieve copies already made — just like sending a file over a messaging app.
- Anyone who joins shared content can leave it whenever they want.
Offline use
BlueList keeps a local copy of your data on your device, so the app works with no internet connection. If you have cloud sync (Premium), changes are sent automatically as soon as you are back online.
Cloud storage and security
Synced data is stored on Google Firebase (Firebase Authentication, Cloud Firestore and Cloud Storage). Firebase handles sign-in, data storage and images, always with encryption in transit and at rest.
Access is restricted by security rules: your private content is only reachable from your own account, and shared content only with the corresponding link or code. We also use Firebase App Check to stop unauthorised applications from reaching our servers.
Google acts as a data processor on our behalf. You can read how it handles data at policies.google.com/privacy.
Analytics, advertising and diagnostics
BlueList has no analytics. We do not use Firebase Analytics, Google Analytics or any other usage-measurement tool: the app sends no events about the screens you open or what you do inside it.
We do not use advertising identifiers either (neither Android’s AAID nor Apple’s IDFA), we show no ads, we build no profiles, we do not track you across apps or websites, and we do not sell or share your data with third parties for their own purposes.
We send no automatic crash reports. If the app fails and you want to help us fix it, just write to us: we will only have the information you choose to tell us. If you send us feedback from within the app, that message is stored in Firebase together with the app version, device model, system version and language — just enough to reproduce the problem — and we use it solely to address it.
Third-party services
To work, BlueList relies on these providers:
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and App Check): sign-in, database, images and abuse protection.
- Google Play and the App Store: they handle Premium subscriptions and their payments. We never see or store your card details.
- Sign in with Google and Sign in with Apple, if you choose either option to log in.
When you import a recipe from a web address, your device downloads that page directly from the site in question and parses it locally, using the phone’s own on-device AI. Neither the address nor the recipe content passes through our servers.
Your rights
You are in control of your personal data. Under the GDPR and equivalent laws, you can:
- Access the personal data we hold about you.
- Correct any inaccurate or incomplete information.
- Obtain a copy of your lists, recipes, cookbooks and meal plans (portability).
- Request the deletion of your account and all its data.
- Object to certain processing, or ask for it to be restricted.
- Lodge a complaint with your data protection authority (in Spain, the AEPD).
To exercise any of these rights, write to laskyfeedback@gmail.com. Most of them are also available directly in the app.
Deleting your account
You can delete your account and all its data whenever you like, from the app’s settings or by asking us by email. Once processed, your personal data and content are erased from our servers; routine backups cycle out within 30 days at most.
Step-by-step instructions, and how to request it without the app, are on the Delete your account page.
Legal basis and retention
We process your account and content data to provide the service you asked for (performance of a contract). Other people seeing shared content follows from your own decision to share it. We carry out no processing for advertising or analytics purposes, because there is neither advertising nor analytics.
We keep your personal data for as long as your account exists. When you delete it, the data is erased as described above. We do not store payment card details: subscriptions are handled entirely by Apple and Google.
Firebase stores data on Google infrastructure. Where there are transfers outside the European Economic Area, Google covers them with the standard contractual clauses approved by the European Commission.
Children
BlueList is not directed at children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
We may update this policy from time to time. Changes will be reflected on this page, along with the last-updated date. We recommend checking back occasionally.
If you have any questions, get in touch: