Privacy Policy
Last updated: 5 August 2026
Introduction
This privacy policy has been drawn up to inform you clearly and transparently about how we collect, use, protect and share your personal data when you use our Listeno mobile application (hereinafter "the Application"). It also sets out your data protection rights and how to exercise them.
Definitions
- Personal data: "personal data" means any information relating to an identified or identifiable natural person. This includes, among other things, information such as your name, email address, IP address, etc.
- Processing: the "processing" of personal data covers any operation performed on that data, whether its collection, recording, organisation, storage, use, alteration, transmission or erasure.
- Consent: "consent" is a freely given, specific, informed and unambiguous indication of your wishes by which you agree to your personal data being processed for the specific purposes set out in this policy.
- Application: the "Application" means the Listeno mobile application developed by the company Numeraven and available from a mobile application store. It includes all the features and services available through that application.
- User or "you": the "User" or "you" means a natural person who uses the Application, whether via a guest (anonymous) account or a registered account.
- List: a "List" means a shopping list created by a User within the Application, which may be shared with other Users.
Identity of the data controller
Your personal data is collected and processed by Numeraven, which is the controller of the data collected through the Application.
For any question about the management and use of your personal data, you can reach us by email at contact@numeraven.com.
Numeraven is committed to protecting your personal data and respecting your privacy. If you have any concerns or requests regarding your data, we are here to help.
Collection and use of data
We collect and process your personal data through our Application for the following purposes:
- Authentication to the Application: if you choose to start without creating a registered account, an anonymous technical identifier is generated (guest account), without any personal information being required. If you create a registered account, we collect either an email address and a password (stored securely, never in plain text), or the identifier and email address provided by Google or Apple when you choose to sign in through one of these providers.
- User profile management: collection of a display name and an (optional) profile picture to make it easier for other Users you share a List with to identify you. This information can be viewed by the other Participants of a List shared with you.
- Shopping List management: collection of the name, icon and colour chosen for each List, as well as the list of Users with access to it (Owner and Participants).
- Item management: collection of the name, category, quantity, an optional note and an optional photo associated with each item of a List. Item photos are accessible via a link whose address is randomly generated; anyone who has this link can access them.
- Recipe management: collection of the name of the Recipes you create and the references to the Items of a List that make them up.
- Shopping sessions: collection of the start and end times, the total price (optional) and the split chosen between the Participants of a shopping session, so that you can review the history of your shopping trips.
- Invitations: generation of a unique invitation link associated with a List, allowing another User to join that List as a Participant.
- Listeno+ subscription management: collection and retention of the subscription status associated with your account (free, trial, active, expired or lifetime access). The technical management of in-app purchases and subscriptions on iOS and Android is entrusted to our processor RevenueCat, which links your transactions to a technical identifier (the same identifier as your account) without knowing your name, email address or other profile data.
- Email communication: use of your email address to send you, through our processor Brevo, a link to reset your password when you request one. Confirmation of a change of email address, on the other hand, is sent directly by our authentication provider (Google/Firebase), without going through Brevo.
- Collection of connection data: IP addresses and technical logs are collected in order to maintain the security and stability of our system, to detect and prevent fraud, and to analyse usage trends within our Application.
- Notifications: the Application includes a technical notifications module, but to date it is not linked to any notification being sent (no notification is currently sent to Users). Should this feature be activated (for example to inform you of an invitation or of activity on a shared List), this policy would be updated accordingly before its activation.
Consent
Users' consent is essential to the collection and processing of their personal data. We are committed to obtaining informed and voluntary consent before collecting your personal data. Here is how we obtain your consent.
Consent process
Explicit consent: when you create your registered User account (or on your first use as a guest account), you are asked to read and accept our privacy policy, which explains in detail how we collect, use and protect your personal data. By accepting our privacy policy, you give your explicit consent to the collection and processing of your personal data in accordance with this policy.
Consent options: we only collect the personal data necessary for the specific purposes of the Application.
Withdrawal of consent
We respect your right to control your personal data and to withdraw your consent at any time, where applicable. If you wish to withdraw your consent to any data processing that you previously authorised, you can delete your account from the "Privacy" section of the Application's Settings. Once your account is deleted, your associated personal data (profile, Lists you own, Items, Recipes, shopping Sessions, subscription) is permanently erased from our systems, and you are removed from the shared Lists you took part in. We will not be able to restore this data once your account is deleted.
If you use a guest (anonymous) account and uninstall the Application without first deleting your account from the Settings, that account can neither be retrieved nor deleted remotely, as there is no identifier left to authenticate you again.
Recipients of the data
Your personal data is handled with the utmost confidentiality, and we only share it with specific recipients who are subject to strict data protection obligations. Here are our main data recipients:
Internal service that processes the data
People specialised in the management of the IT infrastructure have access to personal data as part of their work to ensure the proper functioning of the Application.
Processors
We work with trusted processors to provide certain essential services. Our processors are as follows:
- Google Firebase: we use Firebase (Google) services for account authentication, database storage (Firestore) of your profile, your Lists, Items, Recipes and shopping Sessions, as well as for running our server functions (Cloud Functions). These services are configured to process data in the European region "europe-west3" (Frankfurt, Germany).
- Scaleway: we store Item photos in an object storage space at Scaleway, hosted in the Amsterdam region (Netherlands, European Union).
- RevenueCat: this service helps us manage in-app purchases and subscriptions on the iOS and Android platforms. It links your transactions to a technical identifier, without being able to connect it to your name, email address or other profile data.
- Brevo: we use Brevo to send the password reset email.
- Apple (Sign in with Apple) and Google (Google Sign-In): these third-party authentication providers are only used if you choose to sign in to the Application with one of these methods; they then send us your identifier and your email address (or a relay address, depending on your choice).
- Apple App Store / Google Play Store: these platforms process the payments relating to your Listeno+ subscription, under their own terms and privacy policies.
Data retention period
We only keep your personal data for as long as necessary to achieve the purposes for which it was collected, unless applicable law requires us to keep it longer. Retention periods vary depending on the type of data and its use, and are determined in accordance with the following criteria:
- User account data: your account data, including your display name, your email address (where applicable) and your profile picture, is kept for as long as you use our Application. You can permanently delete your account at any time from the "Privacy" section of the Application's Settings.
- Data relating to Lists, Items, Recipes and shopping Sessions: this data is kept for as long as the relevant List exists and the account of its Owner has not been deleted. Deleting a List results in the cascading deletion of its content (Items, Recipes, shopping Sessions and associated photos).
- Subscription-related data: information relating to your subscription status is kept for as long as your account exists, and deleted if it is deleted.
- Connection data: we are committed to minimising the retention of personal data and to deleting it as soon as it is no longer necessary for the purposes for which it was collected, unless longer retention is required by law or necessary to protect our legitimate interests.
Your rights over your personal data
As a User of our Application, you have certain rights regarding your personal data. We are committed to respecting and facilitating the exercise of these rights. Here is an overview of your rights:
- Right of access: you have the right to obtain confirmation of how we process your personal data and to access that data. You may request a copy of the personal data we hold about you.
- Right to rectification: if your personal data is inaccurate or incomplete, you have the right to request its rectification or update. You can exercise this right directly from your account Settings in the Application to change your display name, your profile picture, your email address or your password.
- Right to erasure (right to be forgotten): you have the right to request the deletion of your personal data, in particular by deleting your account from the Application's Settings.
- Right to restriction of processing: in certain situations, you have the right to request the restriction of the processing of your personal data.
- Right to data portability: you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller, insofar as this is technically feasible.
- Right to object: you have the right to object to the processing of your personal data in certain circumstances, in particular where the processing is based on a legitimate interest.
- Right to withdraw consent: if you have given your consent to the processing of your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of the processing carried out before your consent was withdrawn.
- Exercising your rights: to exercise any of these rights or to ask questions about the protection of your personal data, you can contact us at the email address contact@numeraven.com. We will handle your request within the time limits set by applicable law.
Protection of personal data
We attach the utmost importance to the security of your personal data. To ensure the protection of your information, here are some of the security measures we have put in place:
- Access to personal data is strictly limited to people specialised in the management of the IT infrastructure, who need this data to ensure the proper functioning of the Application.
- Access to our databases is governed by security rules verifying that only Users who are members of a List can view or modify its content.
- All data exchanges between the Application and our servers, as well as with third-party APIs, are encrypted using the SSL/TLS protocol, thereby ensuring the confidentiality of the information transmitted.
- We enforce robust password policies to ensure the security of user accounts registered with an email address and password.
It is important to note that although we implement these security mechanisms, it is impossible to completely eliminate the risks associated with data protection. However, our commitment to security aims to minimise these risks and protect your personal data as best we can.
In the event of a data breach affecting your personal data, we will notify you within the time limits prescribed by law and take the necessary measures to minimise the potential risks and impacts.
Transfers outside the EU
The bulk of your personal data is hosted and processed within the European Union: our databases and server functions (Google Firebase) are configured in the "europe-west3" region (Frankfurt, Germany), and the storage of Item photos (Scaleway) is hosted in Amsterdam (Netherlands).
Some of our processors (in particular Google, Apple and RevenueCat) are companies headquartered outside the European Union. In the course of their activity, these companies may transfer certain data outside the EU. Such transfers, where they take place, are governed by the appropriate safeguards provided for by applicable regulations (in particular standard contractual clauses or adequacy decisions of the European Commission).
Updates to the privacy policy
We reserve the right to amend this privacy policy at any time. In the event of a substantial change, we will inform you by email or by a notification in the Application, before the changes take effect. We encourage you to review this policy regularly to stay informed about how we protect your personal data.