Privacy Policy
Effective 16 September 2026
Shallot is a grocery list and recipe app for iPhone made by Thomas Battaglia (“Shallot”, “we”). This policy says what Shallot stores, why, and what you can do about it. The short version: your lists, recipes and plan are stored so they sync between your devices and your household; Shallot does not sell data, does not show ads, and does not track you across other apps or sites.
What Shallot stores
| Data | Why |
|---|---|
| An account identifier created on first launch (anonymous) | To sync your data between devices without requiring a sign-in. |
| Your Apple ID email, if you Sign in with Apple and choose to share it (Apple's “Hide My Email” works) | To make the account permanent and let you get back into it. Never used for marketing. |
| Your lists, items, item history, recipes (including photos you add), collections, ratings and notes, meal plan, and settings | That's the app. Stored so it syncs and, if you join a household, so members see what you share. |
| Your household: its name, the display name you enter, and who belongs to it | To share lists, recipes and the plan with your household and show who changed what. |
| A random per-install device identifier | To tell your devices apart when syncing and to rate-limit search. |
| Search queries you type into the Search tab | To find recipes. The query is sent to the search service and, when the answer is not already cached, to Brave Search. Shallot's own log keeps only a hash of the query and of the device, not the text. |
| Which recipe pages households save, as counts per page | To show Popular recipes. Counts are only shown once at least three households have saved a page, and you can switch this off in Settings (“Count my saves toward Popular”). |
Shallot does not collect your location, contacts, or advertising identifier, and does not use analytics or advertising SDKs. Crash reports, if you have enabled sharing them with developers in iOS Settings, come from Apple and contain no account data.
Where it lives
Data is stored on Supabase infrastructure hosted by Amazon Web Services in Ohio, United States, encrypted in transit and at rest. A copy is on each of your devices. When you import a recipe, Shallot's server or your phone fetches that page from the recipe site; the site sees an ordinary page request.
Who else sees it
- Apple, when you Sign in with Apple, under Apple's privacy policy.
- Supabase and Amazon Web Services, which host the database and photos, as processors on our behalf.
- Brave Search, which receives search queries that aren't already cached, without your account or device identifier.
- Your household members, who see the lists, recipes and plan entries you share and your display name.
Nobody else. Shallot does not sell or rent data and does not share it for advertising.
How long
As long as your account exists. Deleted items are removed from the server within days of the deletion syncing. Search logs (hashes only) are kept for 90 days. Popular counts are aggregate and not tied to an account once counted.
Your choices
- Delete everything: Settings → Account → Delete Account removes your account, your data and your photos from Shallot's servers and from the phone, immediately.
- Leave a household: Settings → Household → Leave. Shared items stay with the household; your own stay with you.
- Opt out of Popular: Settings → Popular.
- Export: email support@shallotlist.com and we'll send your data as JSON.
If you are in the EU, UK, or another place with data-protection rights, you can exercise them by email at the address above. Shallot is not directed at children under 13.
Changes
If this policy changes in a way that matters, the app will say so on next launch. Older versions are in the source repository.