Lisli Privacy Policy
Effective date: September 3, 2026
1. About this Policy
This Policy explains how information is handled in the shopping list app "Lisli" (the "App"). The operator is identified as "Lisli," and the contact point is support@lisli.app.
We will respond without delay after confirming a legitimate request for operator information that must be disclosed by law.
2. Personal Spaces and Shopping Information on Your Device
You can use a Personal Space without creating an account. Shopping information entered into a Personal Space, including list names, item names, planned dates, quantities and units, purchase history, store names, product page URLs, photos, notes, and reactions to candidates, is generally stored on your device.
Merely signing in to, creating, or joining a Shared Space does not automatically send, move, or disclose shopping information from your Personal Space to that Shared Space. We copy selected information to a Shared Space only when you explicitly choose to copy an unpurchased list. We do not copy Personal Space purchase history, reactions to candidates, or Product Memory.
3. Lisli Accounts and Shared Spaces
When you create, join, or open a Shared Space on another device, we verify your identity using an email address and a verification code sent by email. In that case, we handle the following information:
- Email address, authentication identifier, and authentication session
- The Shared Space name and display name in the Shared Space that you enter
- Membership status, role, and invitation status for Shared Spaces
- Shared Space lists, item names, planned dates, quantities and units, items to buy later, purchase history, store names, product page URLs, photos, notes, reactions to candidates, and Product Memory
- Editor, update time, change number, and correction or cancellation records used to safely reflect collaborative edits
Shopping information in a Shared Space can be viewed and collaboratively edited by the active members of that space. Your email address is not displayed to other members. Access rights to a Shared Space are verified based on membership status and subscription status.
We use Supabase Auth, Database, and Storage for authentication and storage of shared data. Photos in Shared Spaces are stored in access-controlled Storage, not at public URLs. Authentication sessions are kept in secure storage on your device.
4. Family Plus Purchases and Subscription Status
Family Plus purchases are made through Apple's App Store or Google Play. We use RevenueCat to verify, restore, and update purchases and to manage entitlements. For this purpose, Apple, Google, RevenueCat, and Lisli's servers may handle product IDs, purchase and transaction identifiers, subscription status, renewal and end dates, in-app user identifiers, and similar information.
Lisli does not directly obtain payment information such as card numbers. Even if you cancel Family Plus, you can use it until the end of the subscription period. We do not automatically delete Shared Space data merely because a subscription ends; we may limit available actions to viewing, account deletion, and similar actions. Deleting your Lisli Account does not automatically cancel an auto-renewing subscription with Apple or Google. If necessary, cancel it through subscription management in your Apple Account or Google Play.
5. Advertising and Consent Management
In the free version, we display ads using the Google Mobile Ads SDK and provide region-appropriate privacy choices using Google User Messaging Platform. These services may automatically handle the following information for ad delivery, management of impression counts, effectiveness measurement, fraud prevention, quality improvement, and consent management:
- Approximate region inferred from your IP address
- Device or app identifiers
- Ad display and interaction information
- App performance, crash, and diagnostic information
Ad requests are fixed to non-personalized ads. Lisli does not provide Google with shopping information, such as list names, item names, purchase history, store names, product pages, photos, notes, or reactions to candidates, for ad selection.
Even for non-personalized ads, device identifiers and similar information may be used to manage and aggregate impression counts. In applicable regions, you can review and change your choices through Google's consent screen and "Ad Privacy Settings" in the App. If we cannot confirm your consent status, we do not display ads, and shopping features remain available as usual.
6. Usage Measurement
Lisli uses PostHog Cloud EU to understand usage scale and improve the Services. We measure the first launch after installation, app launches, transitions to the foreground or background, app version, operating system, device type, and anonymous or signed-in state. We measure after the App launches, not at the time of download.
The App sends a randomly generated anonymous installation identifier. We do not send session IDs, email addresses, Supabase user IDs or hashes of them, Shared Space IDs, shopping content, purchase information, advertising IDs, screen names, taps, exceptions, or logs to PostHog. We do not enable PostHog person profiles, session recordings, feature flags, surveys, or exports for advertising.
We do not send device-locale region codes, GPS data, location permission status, or latitude and longitude to PostHog. We also disable location enrichment through PostHog IP or GeoIP. We retain anonymous raw events for one year.
Usage measurement is enabled by default. You can stop or resume it at any time under “Anonymous usage data” in the App's Settings. When you stop measurement, we discard unsent measurement events, change the anonymous installation identifier, and keep measurement disabled after the next launch. When you resume measurement, we use a new anonymous installation identifier.
When you sign out, we retain the anonymous installation identifier so that the same installation is not counted twice and return only the state to anonymous. When deletion of a Lisli Account is completed, we also discard unsent measurement events and change the anonymous installation identifier used thereafter. Stopping measurement or deleting an account does not retrospectively delete anonymous events already sent. For questions about deleting measurement records in PostHog, contact support@lisli.app.
7. Photos, Product Pages, Invitations, and OS Sharing
Photos that you select in a Personal Space are stored on your device. Photos added in a Shared Space are sent to Storage that only active members of that space can retrieve.
If you open a product page or retrieve information from one, communication with the relevant website occurs, and that website may handle information such as your IP address.
When you send a list or invitation link using your operating system's sharing feature, you select the recipient. Information provided to the destination app or service is handled under that provider's policy. Secret information for invitations is placed in the URL fragment and is designed not to be sent to Lisli's web servers, access analytics, or advertising.
8. Purposes of Use
- To provide features such as shopping lists, purchase history, candidates, and reminders
- To provide identity verification, invitations, collaborative editing, synchronization, and recovery for Shared Spaces
- To verify and restore Family Plus purchases and manage entitlements
- To operate photos, product pages, invitations, and OS sharing selected by users
- To deliver ads and provide a choice to consent or decline
- To aggregate usage scale and improve the Services
- To respond to issues and inquiries, prevent misuse, and maintain safety
We do not use purchase history or reactions to candidates that make up Product Memory for advertising targeting.
9. Retention, Account Deletion, and Deletion of Information
Shopping information on your device is retained until you delete it in the App or uninstall the App. Depending on your device's backup features, it may be included in backups provided by your operating system provider.
We retain Shared Space information to provide that space and continue its joint use. When a regular member leaves or is removed from a Shared Space, that member can no longer access shared data on the server, and we delete Shared Space data from the device at the next communication. However, past records may remain in the Shared Space and display the former member as a "Former Member" in order to preserve purchase history and collaborative-editing consistency for other members.
You may delete your Lisli Account (withdraw from the service) from "Delete Lisli Account" at the bottom of the "Settings" screen in the App. After identity verification, we will immediately stop use of the server-side service and complete the withdrawal. This action cannot be undone. After withdrawal, we will begin deleting personal data on the server that is linked only to the account and images stored on the server for a Personal Space. We normally process this at the same time as withdrawal, but if we are temporarily unable to process it, we will retry it on the server without restoring access. We do not delete the Personal Space on your device, and you can continue to use it on your device.
You will leave Shared Spaces in which you participated as a regular member. Shared Spaces for which you are the owner or billing party will be closed without handover, and other members will no longer be able to use them. Shared purchase history and other joint records used by other members may remain to preserve consistency. In that case, direct identifiers such as the withdrawing member's display name are removed, and the member is displayed as a "Former Member." Deleting your Lisli Account does not automatically cancel an auto-renewing subscription with Apple or Google. If you cannot use the App, contact support@lisli.app.
We retain tax and payment evidence for seven years from creation of each record or the end of the related transaction. Records of completed account-deletion processing and received payment notifications are deleted in principle within one year. We retain account-deletion records still being processed until completion and delete them within one year after completion. Records used to reconcile purchase and subscription status are deleted within 90 days. We retain information for a longer period only when required for law, disputes, or fraud response and only for the period necessary for that purpose. We do not newly copy shopping content for these purposes. Retention periods for advertising-related information are governed by Google's policies. Purchase-related information retained by Apple, Google, and RevenueCat is governed by their respective policies. We retain inquiry emails for responding and necessary records, then delete them after the purpose no longer exists.
No inquiry is required to complete account deletion. If you wish to ask about access to or deletion of records retained after withdrawal, we will respond after confirming your identity and the records concerned. Joint records used by other members, tax and payment evidence, and records that must be retained under laws and similar requirements may not be deletable. Lisli cannot remotely delete a Personal Space on your device or operating-system backups.
10. Security, External Services, and International Processing
Lisli uses encrypted connections for communications with external services and restricts access to shopping information to the authenticated individual or active Shared Space members. Except as required by law, Lisli does not sell personal information it obtains without the person's consent to third parties.
The App primarily uses the following external services. Each provider may process information in regions including outside Japan.
- Supabase Privacy Policy
- RevenueCat Privacy Policy
- PostHog Privacy Policy
- Apple Privacy Policy
- Google Privacy Policy
- Google Mobile Ads Data Disclosures
11. Children's Privacy
The App is not designed primarily for children. Users who are below the age at which parental consent is required should use the App after reviewing it with a parent or guardian.
12. Changes and Contact
We may update this Policy in response to changes in features, external services we use, laws, and similar matters. We will clearly notify you of important changes on this page or in the App.
For inquiries about the handling, deletion, disclosure, or similar matters concerning information: support@lisli.app