Privacy Policy for DealList
Last updated: September 23, 2026
DealList ("we", "our", or "us") provides grocery search, flyer browsing, shopping lists and price references. This policy covers DealList for iOS and Android and its connected services. Some processing differs by platform and the features you use, as explained below. Contact the DealList developer at info@deallist.ca with privacy questions.
Shopping lists and preferences are primarily stored on your device. However, DealList does not operate without data collection: online search, online translation, advertising, analytics, purchase verification and support can send information off your device, depending on the platform and features used. No DealList account registration or login is required. App-store accounts and anonymous subscription identifiers are separate from a DealList login.
1. Information processed and purposes
Local lists and preferences
Saved shopping lists, selections, preferences and caches are primarily stored in local app storage. We do not provide a general account-based cloud backup or synchronization service for these lists. Text submitted for online search, translation or support is processed separately as described below. Operating-system backup settings may also affect local app data.
Region and approximate location
We process the country and postal or ZIP code you enter to select regional flyers, results and price references. Regional data requests and support submissions can transmit your region or postal code to our services. Search requests may also include regional information depending on the platform; the current iOS AI interpretation request sends the entered text and target language, without a separate postal-code field. Network services receive IP addresses; advertising and analytics providers may derive approximate location from them. DealList does not request GPS-based precise location for these features.
The BLS ZIP-to-region lookup runs locally using a bundled mapping and does not send your ZIP to GeoNames or BLS. Downloading public price data still involves normal network connections.
Search and translation
AI search sends your entered text and selected language to our backend. The current iOS AI request does not separately include your postal or ZIP code; regional flyer and product requests are handled separately. Other platform search requests may include a postal code. The search service sends your text to Google's Gemini service to interpret grocery items or recipe ingredients.
On supported iOS versions, Apple Translation is the default translation option and uses Apple's system translation framework. It may require downloading language resources. When you select a Google translation option, relevant input, product names or other text and language settings are sent to Google translation services, directly or through our backend. Translation results may be cached to reduce repeated processing. Choosing Apple Translation does not change the use of Gemini for AI search.
Google processes submitted content under the terms applicable to each service. Gemini's content use and retention differ between paid and unpaid services. Unpaid-service terms permit product improvement and human review of submitted content and responses; paid-service terms provide different protections and allow limited safety-related retention. Do not include sensitive personal information, passwords, payment details or confidential material in grocery searches or translation requests. We do not promise that every request is immediately deleted after its response.
Advertising
DealList uses Google AdMob to display ads. Its SDK processes IP addresses, app/ad interactions, diagnostic or performance information, and advertising or other app/device identifiers available on the relevant platform. Access to an iOS advertising identifier (IDFA) depends on the applicable system authorization; other identifiers and SDK processing may still be available without IDFA. Google collects and shares this information for advertising, measurement, analytics and fraud prevention. Device settings and applicable advertising choices affect some processing; resetting an advertising ID does not stop all SDK processing.
An ad-free purchase removes the in-app ads covered by the purchase. It does not by itself disable purchase verification, analytics, security checks or every SDK initialization and network request.
Analytics, diagnostics and security
Analytics and integrity services differ by platform. The Android version uses Firebase Analytics and Google services, which can process app interactions, app/installation identifiers, device and software information, approximate regional information and diagnostics. Where enabled on Android, Firebase App Check and Google Play Integrity process app/device integrity information and verification tokens to help verify requests and prevent abuse.
The current native iOS version does not integrate the Firebase Analytics or Firebase App Check SDKs and does not use Google Play Integrity. It accesses Firebase Firestore through online requests for app data and support submissions. AdMob on iOS still processes advertising measurement, interaction, diagnostic and performance information as described above. Hosting services may record IP addresses, request times, response status and errors for operation and security.
Purchases and subscriptions
The applicable app store processes payments. RevenueCat processes purchase history, tokens or receipts, product and transaction identifiers, subscription/entitlement status and an anonymous app-user identifier. These support purchase verification, restoration of benefits and subscription analytics. We do not receive your full payment-card number from an app-store purchase. Records can persist across reinstalls and purchase restoration.
Support and feedback
If you submit feedback, we receive the name and email you provide, category, message, app version, platform, country/postal code and browser/device environment information. It is stored in Firebase Firestore and forwarded through our email provider to our support mailbox. We use it to respond, investigate problems and provide support. You can use the app without submitting feedback. Do not include unnecessary sensitive information or information about other people.
2. Recipients and service providers
Information is processed by the DealList developer and providers supporting these features, including Google Firebase/Google Cloud, Google Analytics on supported platforms, AdMob, Google translation and Gemini services, Apple system translation services on supported iOS versions, RevenueCat, app stores and our support email provider. Which providers receive information depends on your platform and the features you use. Providers acting on our behalf process information to deliver services; advertising and other Google services also process information under their applicable terms and policies. We may disclose information when required by law or reasonably necessary to address fraud, security incidents or threats to users.
We do not sell personal information for money. The advertising-related collection and sharing described above still occurs; this is not a claim that no data leaves your device or is shared with advertising services.
- Google Privacy Policy
- Google Mobile Ads data disclosure (Android)
- Google Mobile Ads data disclosure (iOS)
- Apple Privacy Policy
- Firebase privacy and security
- Gemini API terms and data handling
- RevenueCat Privacy Policy
External websites have their own privacy practices. StatCan and BLS supply public statistical data and do not sponsor or endorse DealList.
3. Storage, retention and deletion
Local lists and preferences remain until removed or overwritten through app or device controls. Clearing app storage or uninstalling can remove local data, but operating-system backups may retain or restore copies. These actions do not automatically delete cloud support records, emails, purchase records or provider-held information, and do not cancel subscriptions.
Support submissions remain in our database and mailbox for request handling and follow-up. Purchase records are retained to verify and restore entitlements and meet applicable recordkeeping requirements. Logs, analytics and provider-held records follow service configurations, provider retention practices and applicable legal requirements. Retention depends on the purpose and record type; we do not currently implement a universal 90-day automatic deletion policy.
The app does not currently offer a self-service cloud-data deletion tool. For questions or requests about access, correction or deletion, contact info@deallist.ca. Identify the relevant data or support request without sending passwords or full payment-card details. Applicable rights, our ability to identify records, and legal/security retention requirements affect what can be provided or removed. Independently controlled app-store or provider records may require contacting that provider. Uninstalling or emailing us does not immediately erase every provider's records.
4. Choices
You can choose not to submit feedback, purchase products or use online search. This does not disable all advertising, analytics or network processing during continued app use. Android and Google settings provide advertising-identifier and certain advertising-preference controls. On iOS, Settings > Privacy & Security > Tracking controls whether apps may request permission to track you across other companies' apps and websites. The current iOS version does not present an in-app tracking-permission request. This system setting does not disable all advertising, identifiers, diagnostics or network requests. On supported iOS versions, you can choose Apple Translation instead of a Google translation option in DealList settings; AI search still uses Gemini. DealList does not currently have a single switch disabling all SDK collection. Manage or cancel subscriptions through the store where you purchased them; uninstalling does not cancel them.
5. Security and international processing
Connections from the app to our online APIs and listed SDK services use encrypted transport such as HTTPS/TLS. This is not a promise of end-to-end encryption or a guarantee against security incidents. Providers may process information outside your country, including in the United States, where privacy laws may differ.
6. Children
DealList is not directed to children under 13, and we do not intentionally solicit personal information from them. Contact us if you believe a child has submitted personal information so we can review the situation. Individual online services may impose additional age restrictions. We do not claim that SDKs stop processing data solely because a user's age is unknown.
7. Changes and contact
Revisions will appear on this page with an updated date. We will provide additional notice or obtain consent where required. This policy describes our practices and does not replace disclosures or consent required for particular features.
Privacy contact: info@deallist.ca