Privacy Policy
Last updated: September 18, 2026
Grublist is a shared grocery-list and recipe planning app for households, available on iPhone, Android, and the web, provided by Lhovon Ventures Corp., operating as “Grublist” (“Grublist”, “we”, “us”). This policy explains what information we collect, how we use and share it, how long we keep it, and the choices you have.
Information we collect
- Account information. When you create an account we collect your email address and, if you sign in with Google or Apple, the basic profile information those services share (such as your name, if you choose to share it). If you use Sign in with Apple’s “Hide My Email” feature, we receive only a private relay address, not your real email.
- Household content and activity. We collect the recipes, ingredients, grocery lists, meal plans, recipe photos, source links, and other content you add. We also record changes that members make to shared household content.
- Subscription information. If you buy a subscription, Apple or Google processes the purchase, and RevenueCat helps us manage it. We receive your subscription status, store, and transaction identifiers. We do not receive your full payment-card details.
- Messages and choices. We collect messages that you send to support and your product-email choice. For product email, we keep the email address, the choice, when and where you made it, and the disclosure that you saw.
- Notification information. If you allow push notifications, we collect a device push token, the device platform, your time-zone offset, and your notification choices.
- Technical and usage information. We collect basic device, app-version, network, security, log, and crash information. We also collect operational measurements about recipe imports, such as the source type and URL, outcome, provider, timing, and token use. These measurements use a household identifier and do not include recipe text. We also measure onboarding starts, question views, skips, completion, and use of the existing-account link. These events use an anonymous identifier that we link to an account identifier when you sign in. They do not include your onboarding answers.
How we use your information
- To provide the core service — syncing your recipes, lists, and plans across your devices and your household in real time.
- To authenticate you and keep your account secure.
- To retrieve, read, and format a recipe when you ask us to import it.
- To send you essential service emails, such as verification codes and password resets.
- To send household and cooking notifications that you have enabled.
- To manage subscriptions and provide customer support.
- To send product news, tips, and offers, only where you have chosen to receive them.
- To measure import reliability, maintain, improve, and protect the service, and comply with our legal obligations.
Household sharing
Grublist is built for shared use. When you join a household, the recipes, grocery lists, and plans in that household are visible to and editable by every member, and actions such as checking off an item are shown to other members. Only invite people you trust to your household.
If a member creates a public recipe link, anyone who has that link can see the shared recipe and household name and can copy the recipe to another Grublist household. Treat a public recipe link as public information.
How your information is shared
We do not sell your personal information, and we do not use it for third-party advertising. We share information only as needed to operate Grublist with these providers and recipients:
- Convex — our backend and database host, which stores your account and content.
- SocialKit and source websites or social platforms — retrieve public source content when you ask us to import a recipe. They receive the source link needed for that request.
- Google Gemini, OpenAI, Meta, and OpenRouter — process recipe source text or imported content to extract, translate, or format a recipe. The provider used can change based on availability.
- Resend — sends service and optional product emails and processes delivery and unsubscribe data.
- Zoho — receives support messages and email replies.
- Expo, Apple, and Google — provide app updates and deliver push notifications. A notification can contain a member's first name and details from the relevant household activity.
- RevenueCat, Apple, and Google — process and manage subscriptions bought through the App Store or Google Play.
- Google and Apple — provide sign-in when you choose those options.
- Sentry — receives crash and error diagnostics. We configure it not to collect default personal identifiers and do not enable session replay or performance tracing.
- PostHog — receives pseudonymous operational measurements about recipe imports, including source URLs, and onboarding. Onboarding events include the step, app version, platform, and selected next action. We do not send recipe text or onboarding answers, or attach your account name or email address, to PostHog.
- Cloudflare and Google Fonts — host and deliver our websites and web fonts. They can receive standard connection data, such as your IP address, browser information, and request time.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.
International processing
We operate from Canada. Some providers process information in the United States or other countries. Information processed outside your country can be subject to the laws of that country and can be available to its courts, law-enforcement agencies, or national-security authorities.
Data retention
We keep your account information and household content while your account is active. We keep technical logs, crash reports, import diagnostics, email-delivery records, and support messages only for as long as reasonably needed for the purposes described above, or as required by law.
When you delete your account, we delete your account information and content in a household that you alone own. If other members remain in a shared household, its shared recipes, lists, plans, and history remain available to them. We remove or reassign your account attribution where needed to preserve that shared content. Service providers can keep limited security, billing, suppression, or legal records under their retention requirements.
Your choices and rights
To delete your Grublist account in the app or request deletion without the app, follow our account deletion instructions.
You can update parts of your account information in the app, and you can delete your account at any time. Deletion works as described in the Data retention section. Depending on where you live, you may also have rights to access, correct, delete, or port your information, or to object to certain processing. To exercise these rights, contact our Privacy Officer at support@getgrublist.com.
You may withdraw consent for optional uses of your information at any time. You can turn off device permissions in your device settings, change your product-email choice in the app, unsubscribe using the link in a message, or contact us at the address above. Withdrawing consent does not affect processing that already occurred lawfully. Some account and household data is necessary to provide Grublist's core service; if you no longer want us to process that data, you can delete your account in the app or ask us to delete it.
You can also turn push notifications off in Grublist or in your device settings. The service continues to work without product email or push notifications.
Children’s privacy
Grublist is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their personal information. If you believe a child has provided us information, please contact us and we will delete it.
Security
We use industry-standard measures to protect your information, including encryption in transit and access controls. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any issues.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app or by email.
Contact us
Send questions, complaints, or privacy requests to the Privacy Officer, Lhovon Ventures Corp., at support@getgrublist.com. We operate Grublist from Toronto, Ontario, Canada.
← Back to Grublist