Privacy Policy
Last updated: 13 September 2026
Addola Ltd (“Addola”, “we”, “us”, “our”) provides a collaborative list-sharing mobile app for Android and iOS (the “App”). Addola Ltd is the data controller for the information described here. Our full details are in section 11.
This Privacy Policy explains what information we collect when you use the App, why we are allowed to collect it, who we share it with, how long we keep it, and the rights you have over it.
Two other pages go with this one: Delete your account sets out both ways to have your data erased and exactly what goes, and our Terms of Service covers the agreement between us.
1. Information we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account & identity data | Email address; first and last name; whether you are over 18; profile photo, if supplied via Google Sign-In; a unique account identifier. We ask for your date of birth when you create your account, but we do not store it — see section 7. | Provided by you at sign-up, or by Google when you use “Continue with Google”. |
| Content you create | Lists, list items, categories, and any text you enter into them; membership and collaborator information for shared lists (names/emails of people you invite or who invite you); activity history within a list (who added, completed, or edited an item). | Entered directly by you and other members of your shared lists. |
| Device data | Coarse platform information (Android/iOS/web). | Derived from the device the App runs on. |
| Push notification tokens | A token issued by Apple or Google that identifies your device to the notification service, so we can tell you when something happens on a list you share. It is stored against your account and deleted when you sign out, remove the App, or delete your account. You can turn notifications off in your device settings at any time. | Issued by Firebase Cloud Messaging when you allow notifications. |
| Subscription & purchase data | Whether you hold an active Addola Plus subscription, its renewal status and expiry; purchase and transaction identifiers from the App Store or Play Store. We do not receive or store your card number or other payment details — those are handled entirely by Apple, Google, and our subscription-billing processor, RevenueCat. | Apple App Store / Google Play, relayed to us via RevenueCat. |
| Diagnostic data | Standard connection and request metadata generated by our backend as part of normal operation, such as timestamps on your data. | Generated automatically by our backend infrastructure. |
| Usage data — only if you are 18 or over and turn on “Help improve Addola” | Which screens you open and which features you use (for example, that you created a list or completed an item), how you moved through sign-up, and technical details when something goes wrong (the type of error and where in the App’s code it happened, never the error text). Each event is linked to a random analytics identifier, not your email or name, and may carry an internal identifier for the list it concerns and whether you have Addola Plus. PostHog adds device details: device manufacturer and model, operating system and version, screen size, language, time zone, network type (for example Wi-Fi) and App version. Usage data never includes the names or contents of your lists, invite codes, or anything about the other people on your lists. | Sent by the App to PostHog, our analytics processor, while the setting is on. Nobody under 18 is asked, and nothing is sent for them. |
2. How we use your information
- To create and secure your account, and verify your email address.
- To provide the App’s core functionality: creating, sharing, and syncing lists in real time between collaborators.
- To provide, manage, and restore your Addola Plus subscription, and enforce plan limits.
- To respond to support requests you send us.
- To send you notifications about lists you share, if you allow them.
- To maintain the security and integrity of the App, such as preventing abuse of invitation or sign-up flows.
- If you are 18 or over and turn on “Help improve Addola”: to understand which features are used, where sign-up is hard, and what goes wrong, so we can improve the App.
We do not sell your personal information, and we do not use it for advertising or marketing. Usage data is used to improve the App, not to build a picture of you or to decide anything about you, and no decision affecting you is made by automated means alone.
3. Our lawful basis for each use
UK and EU data protection law requires us to have a lawful basis for every use of your information, and to tell you which one applies.
| What we do | Lawful basis |
|---|---|
| Create your account, verify your email, and run the App’s core list-sharing features | Performance of a contract. These are the service you asked us for. Without this information there is no account and no App. |
| Manage and restore your Addola Plus subscription, and enforce plan limits | Performance of a contract. |
| Send push notifications about your shared lists | Legitimate interests — ours and yours, in a shared list that tells you when it changes. These are service messages about lists you are already on. We do not send marketing push notifications. You can turn notifications off at any time in your device settings. |
| Check you are old enough to use Addola | Legitimate interests — ours, in running an age-restricted service lawfully, and every user’s, in a service that is not open to children below the age of digital consent. We ask for your date of birth, we compare it, and we discard it. We do not ask for a document, and we do not keep the date. |
| Collect usage data to improve the App (“Help improve Addola”) | Consent. We ask once, only if you are 18 or over, and the two answers are equally easy to give. Nothing is collected until you say yes. You can turn it off at any time in Profile, and turning it off deletes the usage data already collected (see section 5). |
| Keep the App secure, and prevent abuse of invitations and sign-up | Legitimate interests — ours and every other user’s, in an App that is not abused. We use the least information needed to do it. |
| Answer your support and privacy requests | Legal obligation for data protection requests; legitimate interests for everything else, in running a service that answers its users. |
| Keep limited records after deletion for fraud, disputes or tax | Legal obligation, and legitimate interests in defending legal claims. |
4. Who we share information with
We share information only with the service providers Addola is built on, strictly to provide the App’s functionality:
| Processor | Purpose | What they receive |
|---|---|---|
| Supabase (Authentication, Postgres database, Edge Functions) | Account sign-in, data storage and sync, backend logic. | All account and content data described above. |
| Google Sign-In | Optional one-tap sign-in method. | Your Google account email, name, and profile photo, if you choose this sign-in method. |
| RevenueCat | Subscription and entitlement management across the App Store and Play Store. | Your app-specific user ID, purchase and subscription status and history, device platform. |
| Firebase Cloud Messaging (Google) | Delivering push notifications to your device. | Your device’s notification token, and the content of the notification — for example the name of the list and what changed. |
| PostHog (EU Cloud) | Product analytics, only for users aged 18 or over who turn on “Help improve Addola”. | The usage data described in section 1, linked to a random analytics identifier. PostHog stores it in the EU (Frankfurt). Its support and engineering staff may access it from the United States (see section 8). Our PostHog project is set to discard your IP address. |
| Apple App Store / Google Play | Payment processing for subscriptions. | Payment details are handled entirely by Apple and Google — Addola never receives your card details. |
| Cloudflare | Hosting this website, including the page you are reading. | Standard web request data such as your IP address. The App itself does not go through Cloudflare. |
These companies are our processors: they act on our instructions and may not use your information for their own purposes. Google Sign-In, Apple and Google Play also act as controllers in their own right for the accounts and payments they run, under their own privacy policies.
One more sharing route is worth naming plainly, because it is the point of the App: when you join or create a shared list, the other members of that list can see your name, your profile photo, and what you add, complete, or edit on it.
We may also disclose information if required by law, or to protect the rights, property, or safety of Addola, our users, or the public.
5. How long we keep it
We keep your account and content for as long as your account exists. There is no fixed expiry while you are using Addola.
When you delete your account — in the App, or by asking us — this is what happens:
- Your account, profile and push notification tokens are deleted.
- The lists you own are deleted, with everything in them.
- On a shared list you joined but do not own, the list stays with its owner and we remove you as a member. Items linked to you are deleted from it — anything you added, anything assigned to you, and anything you ticked off.
- A limited set of records is kept for longer where fraud prevention, an open dispute, or a legal duty such as tax record-keeping requires it. We keep those for no longer than that purpose needs, then delete them.
Delete your account sets this out step by step, and is the page to use if you cannot open the App.
Usage data (only if you turned on “Help improve Addola”). We use it for up to 12 months. PostHog holds it under its own retention rules while the setting stays on. When you turn the setting off, delete your account, or your profile stops showing you as 18 or over, the App stops sending usage data straight away. By the next day we ask PostHog to delete everything it holds about you. PostHog removes your profile at once and your usage data in its next weekly deletion run. We check that it has gone, and it is deleted within 30 days. Copies can remain in PostHog’s encrypted backups until those backups expire.
6. Your rights
Because we are established in the UK, UK GDPR applies to everyone who uses Addola, wherever you live. These rights are yours:
- Access: ask for a copy of the personal information we hold about you.
- Correction: have inaccurate information corrected. You can edit your profile yourself in the App at any time.
- Erasure: have your information deleted. Do it yourself from Profile → Delete account, or ask us — see Delete your account.
- Portability: receive the information you gave us in a common, machine-readable format, or have us send it to someone else.
- Restriction: ask us to pause what we do with your information while a dispute about it is resolved.
- Objection: object to any use we base on legitimate interests. We stop unless we can show compelling grounds that override yours.
- Withdraw consent: for anything we do on the basis of consent. The only thing that does is usage data: turn off “Help improve Addola” in Profile, with one tap. We then delete the usage data already collected, as section 5 describes.
To use any of these, write to privacy@addola.app. Exercising them is free, and we answer within one month, as UK GDPR requires. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if we do. We may need to confirm who you are before we act, so that nobody else can use these rights against your account.
Subscriptions are managed in your App Store or Play Store account settings, not by us.
7. Children’s privacy
You must be at least 13 to use Addola. We ask for your date of birth when you create your account, and the App refuses an account for anyone younger. This is the same requirement as section 1 of our Terms of Service.
We do not keep your date of birth. The App compares it on your device, works out two things — whether you are old enough to sign up, and whether you are 18 or over — and then discards it. The date is never sent to us and never written down. All we keep is whether you are over 18, which is what lets us give under-18s an age-appropriate experience.
No usage data is collected about anyone under 18. The App only offers “Help improve Addola” to users whose profile shows them as 18 or over, and our database refuses the setting for anyone else. If you change your age to under 18, the setting is turned off and any usage data is deleted.
Because we do not keep the date, we cannot notice when you turn 18. You can update it yourself at any time under Update my age on your profile.
Addola is not directed at children under that age and we do not knowingly collect their personal information. If you believe a child has given us personal information, write to privacy@addola.app and we will delete it.
8. Sending information outside the UK
Our service providers process and store data on servers outside the UK, including in the United States. UK law allows this only with a safeguard in place, and we rely on one of these:
- UK adequacy regulations, where the country has been approved as offering equivalent protection; or
- the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, in our contract with that provider.
To ask which applies to a particular provider, or for a copy of the safeguard, write to privacy@addola.app.
9. Security
We use industry-standard measures to protect your information, including encryption in transit, authenticated access to backend data, and server-side rules that prevent one user from reading or modifying another user’s data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Changes to this policy
We may update this Privacy Policy from time to time. The date at the top always shows when it last changed. If we make material changes, we will notify you in the App or by other reasonable means before the change takes effect.
11. Who we are, and how to contact us
The data controller for the information described in this policy is Addola Ltd, a company registered in England and Wales under company number 17394021. Our registered office is 124–128 City Road, London, EC1V 2NX.
If you have questions about this Privacy Policy, how we handle your data, or you want to exercise any of the rights in section 6, contact us at privacy@addola.app. If you are in the UK and are unhappy with how we have handled your data, you also have the right to complain to the Information Commissioner’s Office (ico.org.uk).