Privacy Policy
Last updated: 22 July 2026
SharedShoppingList is a browser extension for sharing shopping lists with family and friends. This policy explains exactly what data the extension handles, where it goes, and how long it is kept. It is deliberately short because the extension is deliberately simple.
What the extension stores on your device
The extension saves a small amount of configuration locally in your browser (via the browser's extension storage), synced across your own signed-in browsers:
- Your display name (the label shown next to items you add).
- The backend server address the extension talks to.
- The list keys (invite links) for lists you have created or joined.
This data stays in your browser. It is not transmitted to us except as part of the normal list operations described below.
What the extension sends to a server
To make a list shared, the extension sends the following to the backend server you have configured:
- Your display name.
- The items you add to a list (product name, and any quantity or notes you enter), along with the store product page they came from.
- The list key that identifies which shared list the item belongs to.
By default the extension talks to our hosted server at
api.sharedshoppinglist.xyz. If you run your own server (SharedShoppingList is
self-hostable), the extension talks only to the address you configure, and we
receive nothing.
We do not collect analytics, advertising identifiers, browsing history, or any personal data beyond what is listed above. We do not sell or share your data with third parties, and there are no third-party trackers or ad networks in the extension.
Access to store websites
The extension includes content scripts that run only on the supported store domains:
- coles.com.au
- woolworths.com.au
- walmart.com
- amazon.com.au, amazon.com, amazon.co.uk
- costco.com, costco.com.au, costco.co.uk
On those pages, and only when you choose to add an item, it reads the product's details (such as name and page URL) so it can be added to your list. It does not read or collect anything from any other website.
The extension can also request permission to reach a self-hosted backend at an address you enter. That permission is requested at the moment you configure the server and applies only to the specific address you provide.
How long data is kept
On our hosted server:
- Actioned items are kept for a few days (so you can undo or review them), then purged automatically.
- Pending items are purged after 60 days.
If you self-host, these retention windows are configurable on your own server and entirely under your control.
Security model
A shared list is protected by its invite link (its list key). Anyone who has the link can view, add, and action items on that list, so only share it with people you trust. List keys can appear in web addresses and therefore in ordinary server logs. Treat an invite link like the paper shopping list it replaces.
Your choices
- You can remove your configuration and stored list keys at any time by removing the extension or clearing its data in your browser.
- You can run your own server so that no data is sent to us at all.
Contact
Questions about this policy or your data? Contact us and we'll reply by email.