The short version. Without an account, nothing leaves your phone. With one, we store what the app needs to sync your lists and receipts — and nothing more. We ask for three permissions: the camera, the microphone while you are dictating a list, and notifications. There is no advertising, no advertising identifier, no location tracking and no audio recording — nothing you say is ever recorded or sent to us — and we do not sell or share your data with anyone for their own purposes.
1. Who this policy is for
This policy covers the Nippy Shopper mobile app, this website, and the backend service they talk to (together, the Service). It is published by Sayari Silicon, which is the data controller for the personal data described here. Contact details are in section 12.
2. What we collect
2.1 If you use the app without an account
The app is fully usable with no account at all. In that mode your lists, items, prices, shopping history and any receipt images live in a database on your phone. They are not sent to us and we cannot see them. The trade-off is that they are not backed up either: if you lose the phone, the data goes with it. Uninstalling the app removes it.
2.2 Account information
- Your email address and a display name.
- A password, stored only as a salted hash — never in a readable form — or, if you sign in with Google or Apple, the account identifier that provider returns to us. We never receive your password for those services.
- Optional profile details you choose to add, such as a profile photo or date of birth. Leaving them blank costs you nothing.
2.3 Your shopping content
Once you have an account, the content you create is synced to our servers so it can be restored and shared: lists and list items, quantities, prices and categories you record, shopping trips, store names you type in, notes, and any receipt photos or videos you attach. It is stored so we can give it back to you and to the people you share a list with. We do not mine it, sell it, or use it to build a profile of you.
Items added by photographing a list or by dictating it are stored exactly like items you typed, because by then that is all they are: text you reviewed and confirmed. The photograph itself is never uploaded and is not kept once its items have been read, and no audio recording is ever created — see section 3, which also explains the one case where dictation uses your phone's built-in speech service rather than your phone alone.
2.4 Device and diagnostic data
- A push notification token for each device you enable notifications on. It identifies the device, not you, and is deleted when you sign out.
- Crash reports and performance traces (via Google Firebase), which tell us that something broke and where in the code — not what was on your list.
- Server logs containing your IP address, the request made and the time, kept for a short period for security and debugging.
2.5 Product analytics
We use Google Analytics for Firebase to answer questions like "how many people who hit the shared-list limit went on to look at the pricing screen". It is deliberately narrow:
- We collect screen names, counts (items in a trip, lists shared), and events on the upgrade path, plus which plan you are on.
- We do not collect list titles, item names, store names, prices, receipts, your email or name — and we do not set a user identifier or an advertising identifier of any kind.
- You can turn analytics off entirely in Account & Settings → Privacy & Legal, which disables collection rather than merely hiding it.
2.6 Purchases
Subscriptions are sold by Apple and Google, not by us. They tell us that a purchase is valid and when it renews or lapses; we store that status, the product purchased and the store's transaction identifier. We never see your card details or billing address — those stay with the store.
2.7 If you contact support from the app
When you start a support email from Help & Feedback in the app menu, the message is prefilled with your app version, device model, operating system version, language and whether your account is a guest, free or Household one — shown to you in the body of the email before you send it, and nothing else: no email address, no account identifier, and nothing from your lists. We then hold what you wrote to us, and our reply, for as long as it takes to answer you and a reasonable period afterwards.
3. Permissions the app asks for
Three, each requested at the moment it is first needed rather than at sign-up:
- Camera — to read a price from a shelf label, to read a written or printed shopping list from a photo, and to photograph or record receipts. Text recognition runs entirely on your device; those camera frames are never uploaded, and the photo of a list is discarded once its items have been read out of it. A receipt is uploaded only if you attach it to a trip while signed in.
- Microphone — only while you are dictating items into a list, and
only after you tap the microphone button. No recording is made, nothing is
written to storage, and no audio is ever sent to us or to our servers on any
path. Your speech is converted to text by your own device wherever your device
is able to do it, which is the default and the usual case; there, nothing leaves the
phone at all.
Some devices have no offline speech model for your language — older Android versions have none at all, and newer ones need the language installed. On those devices we ask you, once and in plain words, whether you would rather have your phone's built-in speech service transcribe instead. That service is operated by Google on Android and Apple on iOS, and choosing it means what you say while dictating is sent to them, as an independent controller, to be turned into text under their own privacy policy. We receive only the finished text, after you have reviewed it. This is off unless you switch it on, you are never opted in by default, and you can change your mind at any time in Account & Settings → Privacy & Legal → Online dictation; signing out clears the choice. Declining leaves every other feature working, including typing and photographing a list. - Notifications — for invitations, changes to lists you share, and billing notices. You are asked after your first invitation, and declining leaves every other feature working.
The app does not request location, contacts or photo-library access, and carries no advertising identifier. Picking an existing photo uses the system photo picker, which hands the app only the file you chose.
Because no audio is ever recorded, and because none of it reaches our servers even when you have turned on online dictation, there is no voice data of yours in our systems: there is nothing about your voice to include in a data export and nothing to delete when you delete your account. If you have used online dictation, any question about what Google or Apple did with that audio is one for their privacy policy, not ours.
4. Why we use it, and on what legal basis
For people in the UK and EU, the lawful bases under the UK/EU GDPR are set out alongside each purpose:
- Running the Service — syncing, sharing, restoring, notifying you about lists you are on. Performance of our contract with you.
- Billing and entitlements — verifying purchases with the stores and applying your plan. Performance of our contract, and legal obligation for the records we must keep.
- Keeping the Service working and safe — crash reports, logs, abuse prevention. Our legitimate interest in a secure, functioning product.
- Understanding how the product is used — the narrow analytics in section 2.5. Our legitimate interest, and you can switch it off.
- Support — answering the message you sent us. Performance of our contract, and our legitimate interest in helping you.
5. Who else sees it
- People you share a list with. They see the shared list, its items and what you change on it, along with your display name. They do not see your other lists, your history, or your email address unless you tell them.
- Service providers who process data on our instructions: our cloud hosting and database provider, our object-storage provider for receipt media, Google (Firebase Cloud Messaging for notifications, Crashlytics, Performance Monitoring and Analytics), Apple and Google for purchase verification, and an email delivery provider for account emails. Each is bound to use the data only to provide that service to us.
- Your phone's speech service, only if you turn on online dictation. What you say while dictating goes directly from your phone to Google (Android) or Apple (iOS) to be turned into text. It does not pass through us, and they handle it as an independent controller under their own privacy policy — so this is not a service provider acting on our instructions, which is precisely why we ask you first rather than deciding for you. It is off until you switch it on, and never used when your phone can transcribe by itself. See section 3.
- Authorities, where the law actually requires it, and no further than it requires.
- A buyer, if the business is ever sold — with notice to you, and this policy continuing to apply until you are told otherwise.
We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are used in California and other US state privacy laws. There is no advertising in the app and no ad network to sell to.
6. How long we keep it
- Your account and shopping content — for as long as the account is open. Deleting the account erases them immediately; there is no waiting period and no recoverable copy. See deleting your account.
- Receipt images and videos — on a free account, full-size files are kept for 60 days and up to 100 MB, after which the trip, its total and a thumbnail remain and the full-size file is removed. We warn you before that happens. On Nippy Household they are kept for as long as your subscription is active.
- Crash and diagnostic data — for a limited period under our providers' standard retention.
- Purchase records — for as long as tax and accounting law requires. Google Play and the App Store are the merchant for every subscription, so the invoice and the payment details sit with them, not with us.
- Security events — the record that a sign-in or a failed attempt happened, kept briefly so a deleted account cannot be used to cover tracks. When an account is deleted, the name, address, device and IP address are stripped out of these entries and only the de-identified event remains.
- Deletion receipts — the date an account was erased and how much was removed, so we can show that a request was carried out. They contain no name, address or device.
7. Your rights
Wherever you live, you can ask us to give you a copy of your personal data, correct it, or erase it, and you can object to processing based on our legitimate interests. In the UK and EU you also have the right to portability and to restrict processing; in California and similar US states, the rights to know, delete, correct, and to opt out of sale or sharing — which we do not do in any case.
Two of them are buttons rather than requests, because a right you have to ask for is a right that depends on us reading an inbox.
- Get a copy of your data in the app: Account & Settings → Your Profile → Download my data. It produces a single machine-readable file containing your profile, lists, items, prices, trips, reusable lists, contacts, invitations, devices, sign-in history and subscription record, which you can keep or hand to another service. Photos and receipts are listed with download links rather than embedded, so save those before deleting the account. Passwords and sign-in tokens are deliberately not included.
- Delete your account in the app: Account & Settings → Your Profile → Delete account. It takes effect immediately. The account deletion page explains exactly what that erases and what happens to a list you share.
- Everything else — correction, restriction, objection, or any request you cannot make because you can't sign in: email privacy@nippyshopper.com. We will verify that the request comes from you and respond within the time the law allows — a month in the UK and EU, 45 days in California.
- We will not treat you differently for exercising a right.
If you think we have got this wrong, you can complain to your data protection authority —
in the UK, the Information Commissioner's Office at ico.org.uk. We would
rather you told us first.
8. Where your data goes
We and our providers may process data in countries other than yours, including the United States. Where data leaves the UK or the European Economic Area we rely on the transfer mechanisms the law provides, such as the European Commission's standard contractual clauses and the UK addendum.
9. Security
- All traffic between the app and our servers is encrypted in transit (HTTPS/TLS), and the release build of the app refuses unencrypted connections outright.
- Passwords are stored only as salted hashes. Sessions are token-based and can be revoked; deleting your account revokes every one of them immediately.
- Receipt media is stored with access controlled per account, and served through links that expire.
- No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will notify you and the relevant regulator as the law requires.
Found a vulnerability? Please report it privately to security@nippyshopper.com.
10. Children
Nippy Shopper is not directed at children. You must be at least 13 to have an account, or older where your country sets a higher age for consent to online services (16 in parts of the EU). If we learn that we hold an account belonging to a child below that age, we will delete it.
11. Changes to this policy
If we change this policy we will update the date at the top, and for anything that materially affects you we will tell you in the app or by email before it takes effect.
12. Contact
Privacy requests:
privacy@nippyshopper.com
Everything else:
support@nippyshopper.com
Postal address: Sayari Silicon — see the store listing for our registered
address.
This document explains our practices in plain language. It is not legal advice, and it does not reduce any right you have under the law where you live.