Listora works without accounts, without advertising and without third-party services. This policy describes what data is nevertheless processed, why, and for how long it is kept.
This English version is a translation provided for convenience. Only the German version is legally binding; in case of any discrepancy, the German text prevails. Read the German version
The controller responsible for data processing on this website is:
Schweinbenz & Hallmayer GbRZollernblick 172108 RottenburgGermanyPhone: +49 1578 7255127Email: info@diformatics.deThe controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
No account is needed to use the service. We ask for neither a name nor an email address nor a phone number. Each shopping list can only be reached through a randomly generated address (UUID); whoever has that address has access to the list.
We therefore build no profile and store nothing that would recognize a specific person over time. What is stored is the content that users themselves enter into a list – see section 4.
The one exception is the IP address. When a list is created, when a PIN is entered and when the recently opened lists are checked (section 7), it is used briefly to limit automated mass requests and the guessing of PINs. For this it is held only in the server's working memory, is not stored permanently, is not combined with other data and is discarded after about an hour at most. The legal basis is our legitimate interest in running the service securely (Art. 6(1)(f) GDPR).
This website is hosted by an external service provider. The data collected on this website is stored on the host's servers. The host is:
netcup GmbHDaimlerstraße 2576185 KarlsruheGermanyThe host is used in order to provide the service securely, quickly and efficiently through a professional provider (Art. 6(1)(f) GDPR) and to perform the usage relationship (Art. 6(1)(b) GDPR). We have concluded a data processing agreement with the provider. It processes the data exclusively on our instructions.
What is stored is what gets entered into a list – whether typed in or imported: the list's name, categories, items with amount and note, and the time an item was ticked off. These entries are free text and are not analyzed.
When an item is ticked off, the display name you chose yourself is transmitted as well and shown next to the item, so the group can see who took care of what. That is why the app asks for such a name before the first tick: you can view a list without one, but not tick items off. A real name is not required for this – a nickname is enough.
Whoever takes over a category can enter a name there too (“Who's doing this?”). That name is stored with the category and shown to everyone who has the list's address. It can be changed or removed at any time and is deleted together with the list. Here, too, a nickname is enough.
Please do not put personal or confidential information into items or notes. Everyone who has the list's address can read them.
A PIN is optional; it can be set when a list is created or later, and changed or removed again. If a list has a PIN, it is never stored in plain text, only as a cryptographic hash (scrypt with a random salt). The PIN cannot be derived from the stored value, which is also why it cannot be recovered.
Failed attempts to enter it are counted temporarily to make guessing a PIN harder. The legal basis is our legitimate interest in running the service securely (Art. 6(1)(f) GDPR).
Exactly one cookie is set, and only for lists with a PIN: when edit mode is unlocked with the PIN, when a list with a PIN is created, or when a PIN is set. It is called listora_edit_<list ID>, is signed against tampering, cannot be read by JavaScript (httpOnly) and becomes invalid after 12 hours. It contains nothing but the expiry time and the signature.
This cookie is strictly necessary to provide the function you explicitly requested. Storing it is therefore permitted without consent under Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG); no consent prompt is required. There is no analytics, no tracking and no advertising; no profiles are built.
Some information is kept locally on the device and not sent to the server: the display name you chose, a list of the shopping lists most recently opened on this device, the chosen view (all, open or ticked items), the chosen color scheme (light, dark or as set on the device), and which one-time hints have already been shown on this device. Right after a list is created, the browser tab also remembers that it is new; that flag disappears as soon as the welcome dialog is closed. The list of recently opened shopping lists serves only to find a list again without a bookmark and to let the app installed on the home screen start directly with the list opened last; on launch, the browser remembers for the duration of that session that this has already happened. To show and open only lists that still exist, the browser asks the server on the homepage, in “My lists” and when the app launches; only the identifiers of those lists are transmitted. This, too, is strictly necessary storage within the meaning of Section 25(2) no. 2 TDDDG.
If an item is ticked off without an internet connection, the browser remembers that tick together with the display name until the connection is back, and then sends it to the server. After that, the entry is deleted from the device. Ticks that have still not been sent after 12 hours, and ticks for lists that no longer exist, are deleted by the browser the next time Listora is opened, without being sent.
So that a list can be opened again without a connection, the browser keeps a copy of the list page and its contents on the device for up to twelve recently opened lists – including the display names shown in them. This is done by a so-called service worker, a part of this website that the browser runs in the background. The copy is refreshed every time the list is opened with a connection, and deleted as soon as the list no longer exists or drops out of the recently opened lists. It never leaves the device.
All of this can be removed at any time with the browser's function for deleting site data; entries in the list of recently opened lists can also be removed individually on the homepage.
When pages are requested, the web server may log access data for technical reasons – typically the IP address, time, requested address, amount of data transferred and browser identification. This serves secure operation and troubleshooting and is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR.
Since a shopping list's address contains its identifier, that identifier may appear in such logs. Their scope and retention period depend on the server configuration at the host named above.
Short-lived access keys can be generated for filling a list through the interface. Of these, too, only a hash is stored. They expire after 60 minutes and can be revoked at any time before that.
No analytics services, no advertising networks and no external content delivery networks are embedded. Data is not passed on to third parties; there is no transfer to countries outside the EU.
Google Fonts are used for a consistent display of typefaces. They are installed locally on our own server. No connection to Google's servers is made in the process.
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the browser's address bar changing from “http://” to “https://”. While encryption is active, the data you send to us cannot be read by third parties.
List contents and the session cookie are processed in order to perform the usage relationship under Art. 6(1)(b) GDPR. Logging access data, limiting failed PIN attempts and limiting the number of newly created lists rest on our legitimate interest in running the service securely under Art. 6(1)(f) GDPR.
Where, exceptionally, consent is obtained, processing is based on Art. 6(1)(a) GDPR. Consent once given can be withdrawn at any time with effect for the future; the lawfulness of the processing carried out up to the withdrawal remains unaffected.
A shopping list is deleted completely and automatically 30 days after the last activity – together with all its categories, items and display names. Any change to the content counts as activity, such as ticking off or adding an item; merely viewing the list does not extend it. A button in the list also resets the period independently of that, without changing anything else.
Individual items and categories can be deleted at any time, and so can the whole list – together with all its categories, items and display names, for everyone who has the link. A list that is not used for the period stated above disappears on its own.
Unless a more specific retention period is stated here, data remains with us until the purpose of the processing no longer applies or deletion is requested. Statutory retention obligations remain unaffected.
Independently of this, we keep a few overall totals, such as how many lists and items have been created in all. These are plain counters with no reference whatsoever to a list, its contents or a person. They remain when a list is deleted, because nothing about that list can be read from them.
Access, rectification and erasure. Within the applicable statutory provisions, you have the right at any time to obtain, free of charge, information about your stored personal data, its origin and recipients and the purpose of the processing, as well as the right to have that data rectified or erased (Art. 15 to 17 GDPR).
Restriction of processing. You have the right to request that processing be restricted (Art. 18 GDPR) – in particular if you contest the accuracy of the data, if the processing is unlawful, if we no longer need the data but you need it to assert legal claims, or if you have objected under Art. 21(1) GDPR and the balancing of interests is still pending.
Data portability. You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract in a common, machine-readable format (Art. 20 GDPR).
Objection. Where data is processed on the basis of Art. 6(1)(e) or (f) GDPR, you may object at any time on grounds relating to your particular situation (Art. 21 GDPR).
Right to lodge a complaint. In the event of infringements of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg).
Since there are no accounts, no information is stored that would link a list to a person. A stored list can therefore only be attributed to you if you tell us its address (Art. 11 GDPR). For requests, a message to the address above is enough; stating the address of the list concerned is helpful.
We update this policy whenever the application's features or the legal situation change. Last updated: 2026-09-21.