Privacy Policy

Last updated: 2026-09-16

This Privacy Policy explains how Cartly+ (“the App”, “we”, “us”, “our”) collects, uses, and shares information when you use the App. If you have questions, contact us at support@cartly.plus.

Summary

Information We Collect

Account Information

When you create an account or sign in, we collect identifiers necessary to provide authentication and account management. Depending on the sign-in method, this may include:

User Content (User-Generated Content)

The App stores content you create and manage, such as shopping list items, household data, and related text-based content. This content is visible to you and, if you use shared households, to members you invite.

Subscription and Purchase Information

If you purchase a subscription, the platform store (Apple or Google) processes the payment. We and our subscription provider (RevenueCat) may receive subscription status information (e.g., active/expired) and transaction identifiers required to validate access. We do not receive your full payment card details.

Usage and Diagnostics

We use the following tools to operate, secure, and improve the App. These services may collect device identifiers and technical metadata as part of their normal operation:

App Tracking Transparency (iOS)

On iOS 14.5+, before any advertising/measurement tools track you across other apps and websites, we show Apple’s standard App Tracking Transparency prompt. If you decline, the Meta SDK is initialized in a non-tracking mode, AdMob is asked to serve non-personalized ads, and the iOS Advertising Identifier (IDFA) is not shared with these SDKs. You can change this at any time in Settings → Privacy & Security → Tracking.

Data used for tracking. When you allow tracking, the following categories may be linked with third-party data for advertising and measurement, consistent with our Apple App Store privacy disclosures:

If you decline the ATT prompt, this data is not used for tracking.

How We Use Information

How We Share Information

We share information only as needed to operate the App:

We do not sell your personal information and do not share it with third parties for their own independent marketing purposes.

Connected AI Assistants

When you connect an assistant such as ChatGPT to Cartly+, you authorize access to the households and shopping lists available to your Cartly account. At your request, the assistant can read items, add items, change quantities and notes, mark items as bought, and remove items. Responses can include household names, item names, dates, quantities, units, categories, notes, completion state, and record identifiers needed to select and update the correct items.

The connection runs on Cloudflare and uses Supabase for authentication and data storage. Renewable account credentials used by the connection are stored encrypted. Your Cartly password and your Apple or Google sign-in credentials are not shared with the assistant. Request-duration logs help us diagnose performance; those timing records do not include shopping-list content or authentication secrets.

Temporary sign-in transactions expire after ten minutes. Connection access tokens expire after five minutes; renewable connection tokens have a thirty-day lifetime and may be renewed while the connection is in use. Shopping-list content follows the account retention rules below.

You can revoke assistant access at Manage connections. Existing access tokens may remain usable for up to five minutes after revocation. Revoking access does not remove information already received by the assistant. The assistant provider processes and retains that information under its own privacy policy and account controls.

Data Retention

We retain your information for as long as your account is active or as needed to provide the service. You may request deletion as described below.

Your Choices and Rights

Security

We implement reasonable technical and organizational measures to protect information. No method of transmission or storage is 100% secure.

Children’s Privacy

The App is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided personal information, contact us and we will take appropriate steps to remove it.

International Availability

The App may be available in multiple countries/regions. Data may be processed where our service providers operate, consistent with applicable law.

Contact (Including DSA Contact Point)

For privacy questions, user reports, or legal/DSA inquiries, contact:
support@cartly.plus

Changes to This Policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, when appropriate, provide additional notice.