Peltra Privacy Policy
Last updated: 13 August 2026
In two lines
Peltra is a list app. With no account, what you write never leaves your phone. With an account, your lists are kept on our server so you have them on any phone and can share them. There are no ads, no profiling, and we never sell or pass your data to anyone.
1. Who processes your data
| Controller | [legal name] |
| Tax ID | […] |
| Address | [postal address] |
| Contact | hello@peltra.app |
| Data Protection Officer | Not required: none of the cases in art. 37(1) GDPR applies to the kind and volume of data Peltra processes |
Write to hello@peltra.app about anything in this policy, including your rights. We answer within one month (art. 12(3) GDPR).
2. What we process, what for, and on what legal basis
2.1 Using Peltra without an account
We process no personal data at all. No session is opened with our server, nothing is uploaded, and we do not know you exist. Your lists, items and settings live on your own phone and disappear if you uninstall the app.
The app tells you this permanently while you have no account, because it has one important consequence: if you lose the phone, there is no copy anywhere.
2.2 If you create an account
| What | What for | Legal basis (art. 6 GDPR) |
|---|---|---|
| Email and password (or your Google or Apple identifier if you sign in with them) | Creating your account, signing you in, letting you recover access | Performance of a contract (art. 6(1)(b)): without an account the service of having your lists on several devices cannot be provided |
| Display name, handle, one-line bio, colour and profile photo (all optional) | So the people you share lists with know who you are | Performance of a contract |
| Your lists and what you write in them: titles, notes, quantities, dates (with a time, or marked as all-day), who did what, and the fields each kind of list has of its own (which shop something is bought at, who is bringing it on a trip, who a gift is for, which platform a film is on, who paid and how much, which page you are on in a book), plus any tags you invent yourself, with the names you give them and the values you add | It is the service | Performance of a contract |
| How each list is organised: whether it is marked as a favourite, whether any of its items is, and how it is sorted and grouped | So the list looks the same on every phone that shares it | Performance of a contract |
| Who is in each list and with what role; the invitations you create | Sharing lists | Performance of a contract |
| In a gift list, which gift you have claimed | So that the people you share the list with do not buy the same thing twice. Whoever is getting the gifts cannot see it: the server itself hides it from them | Performance of a contract |
| Your contact list: which people you have a relationship with and in what state (request pending, accepted, blocked or undone), who took the first step, and via which of the four routes (tag, QR code, link or phone address book) | Being able to share a list with someone in one tap, without going through a link, and being able to block anyone you do not want hearing from again | Performance of a contract |
Your tag #ABCD-1234 and the contact links you mint, with their expiry and whether you cancelled them | So the people you choose can find you, and so you can change your code whenever you want | Performance of a contract |
| A code derived from your email, and only if you turn on «let people find me by my email» | So anyone with you in their address book can find you | Consent (art. 6(1)(a)): turned on by hand, turned off by hand, and turning it off deletes the code |
| List history (who added or completed what) | So a shared household knows what happened in a list | Performance of a contract |
| Plan and subscription status | Billing and entitlements | Performance of a contract |
| Device notification token | Alerting you about your lists | Performance of a contract |
| What you tell us from inside the app when we ask how it is going: whether it is an idea, a bug, something confusing or something you like; a one-word rating; and whatever you write, if you write anything. It travels with the app version, the platform (iOS or Android) and the language | Fixing what is broken and deciding what to build next | Legitimate interest (art. 6(1)(f)): improving a product with what the people using it tell us. It is only sent if you send it, and you can say «do not ask again» once and for good |
We do not ask for your real name, phone number, date of birth, address or payment details. Payments are handled by Apple and Google using the details already in your store account: we never see your card, your billing name, your address or the amount. All we keep is which plan you have, what state it is in and until when (see §3.1).
We do not process special categories of data (art. 9 GDPR) and never ask you for them. If you write some yourself in a list — a medical appointment, say — it is treated like any other content of yours: we do not read it and do not analyse it.
2.3 What stays on your phone, with or without an account
These are never uploaded to our server:
- The photos you attach to an item.
- Anything the camera reads: OCR of a receipt or a handwritten list is resolved by the operating system's own recogniser, on the device. The image is never sent anywhere.
- Calendar links and reminders, which are local.
- Your phone's address book. If you use «search my address book», Peltra reads
- App settings (language, theme, text size) and how you prefer to see your lists — as rows or as a grid, and sorted by which criterion — which belongs to the phone and not to the account: changing it does not reorder anyone else's lists.
email addresses only — no names, no phone numbers, no photos, no birthdays — turns them into codes on the device, and sends twelve bits of each code: one of 4096 possible buckets. The server returns whole buckets, with people you do not know in them, and the final comparison happens on your phone. So the server knows which buckets you asked about and does not know who is in your address book. No copy of your address book is kept, on the phone or on the server.
3. Who your data is shared with
We do not sell data. There are no ads. There is no analytics or third-party SDK inside the app. The only third parties involved are these, and each one only gets what it needs:
3.1 Processors
| Who | What they do | What they get |
|---|---|---|
| Supabase (database, accounts, functions) | Stores your account and your lists | Everything in §2.2 |
| Expo (push service) and, behind it, Apple and Google | Deliver alerts to the phones in a list | The device notification token and the text of the alert, which carries the list title and the display name of whoever just did something ("Luísa added 3 things to Groceries") |
| Supabase again, as the email service | Sends the account confirmation and password-reset emails | Your email address |
| RevenueCat (subscription management) | Checks with App Store or Google Play whether your subscription is current, and tells us when it changes | Your Peltra account identifier and the purchase status the store sends it. Only if you subscribe |
| Anthropic (the language model behind the AI features) | Sorts, seeds or splits what you asked for when you tap an AI feature | The text of that one action: the titles of the items in that list, or the text read from a receipt, or what you just dictated. Only when you tap an AI feature |
There is a data processing agreement with each of them (art. 28 GDPR).
About AI, in detail. Three things, all of them design decisions rather than loose promises:
- A photo or a recording never leaves your phone. Not even when what you did was take a photo or dictate: your own phone reads the photo and your own phone transcribes the dictation. What goes up is the text that came out of that.
- Your name does not go, nor anyone else's, nor when, nor which list. The titles go, and nothing else — not who wrote them, not the dates, not who is in the list.
- Most of what Peltra understands never goes through here. Dates, amounts, units, the supermarket aisle and the names it recognises as you type are all worked out by your phone, offline, sending nothing. AI is the last resort and only runs when you ask.
Anthropic processes those texts on our behalf, does not use them to train its models, and keeps them only as long as needed to answer. It is based in the United States, so that transfer relies on the European Commission's standard contractual clauses.
About payments, in detail. Peltra never sees, receives or stores your card, your billing name or your address: the charge is handled entirely by Apple or Google using the details already in your store account, and we take no part in it. All that reaches our server is one row with three things: which plan you have, what state it is in, and until when. Not the receipt, not the amount, not the country, not the transaction identifier.
When you tap "Manage subscription" we leave the app and open your browser on the App Store or Google Play page where you cancel. That page is the store's, not ours, and whatever happens there is governed by their own policy.
There is no AI provider in this version. Peltra sends nothing of yours to an AI service: the features that would use one are switched off and do not appear in the app. If they are ever switched on, this policy will say so first — naming the provider and exactly what it receives, text and never images or audio — and it will change before the first call ever happens.
3.2 Services called only if you use the feature
These calls are made by your phone, only when you ask for that specific thing, and carry neither your identity nor your email:
| Who | What they get | When |
|---|---|---|
| Apple or Google (system speech recognition) | The audio while you dictate | Only while dictating |
| Open Library | The title or author you search for | Only in a book list |
| Open Food Facts | The barcode you scan | Only when scanning |
| The website whose link you paste | The address you pasted | Only when pasting a link |
| The site's own preview service where it has one: YouTube, Vimeo, Spotify or TikTok | The link you pasted, to pull the title from it | Only when pasting a link from those sites |
About dictation, in detail, because it is the one place where something of yours leaves the phone without us asking for it: Peltra uses your phone's own speech recogniser. Apple resolves it on an iPhone and Google on an Android, and they decide whether it is processed on the device or on their servers. We never receive the audio, never store it and never send it anywhere. What reaches Peltra is the recognised text. If you would rather that did not happen, do not use dictation: everything else works the same.
3.3 Other people
When you share a list, whoever is in it sees what is inside and who did what, including your display name. That is not a disclosure to a third party: it is the service you asked for. You can remove someone from a list at any time.
4. Where your data is
Data is stored on Supabase infrastructure, in the eu-west-3 (Paris, France) region.
That is inside the European Economic Area, so there is no international transfer of data and no Chapter V safeguards are required.
The services in §3.2 handle what they receive under their own policies, which we do not control.
5. How long we keep things
| What | How long |
|---|---|
| Your account and your lists | As long as you have the account |
| What you delete | 90 days in the bin, then really deleted, on the server too |
| Invitations | Expire after 30 days; dead links are removed 30 days later |
| Contact links (the ones behind the QR) | Expire after 14 days and renew themselves; dead ones are removed 14 days later |
| Your contact list | As long as you have the account. An undone relationship is deleted after 180 days, once both people have undone it. A block never expires: if it did, the blocked person could reach you again without you having decided that |
| The code derived from your email in the directory | As long as you keep it on. Turning it off deletes it immediately — it is not just flagged |
| List history | 12 months. After that it is deleted automatically, even if the list is still alive |
| Subscription plan and status | As long as you have the account. The row is kept even after a subscription expires — it says "expired", it does not vanish — so we can show what you were entitled to and since when, which is what settles a billing complaint. It is deleted in full when you delete your account |
| What you tell us about the app | 24 months. If you delete your account, what you wrote stays without your name: it stops being linked to you, just like a list's history |
| Database backups | [per the Supabase plan in use: state the real period] |
| Your own phone's backup | You decide, in your phone's settings. See below |
Your phone's own backup also takes your lists, and that part is not ours to control. Peltra keeps your lists on the device itself, so the system's automatic backup — Google One on Android, iCloud on iOS — includes them, encrypted and inside your own Google or Apple account. We have no access to that copy and cannot delete it: you turn it off in your phone's settings, not here. We mention it because it is one more place your lists end up, even if it is yours. Your session is not in that backup: it lives in the system keychain and is deliberately excluded.
When you delete your account, all of the above goes immediately, with two exceptions that exist so that other people's things are not destroyed:
- Shared lists where someone else remains change owner: they are not deleted, because they belong to whoever stays too.
- What you wrote in other people's lists stays there, but without your name: authorship is cleared and the history stops identifying you.
6. Your rights
You can exercise these at any time, free of charge:
| Right | What it is | How |
|---|---|---|
| Access (art. 15) | Know what we hold about you and get a copy | Settings → Privacy → "Ask for a copy of your data", or hello@peltra.app |
| Portability (art. 20) | Receive your data in a machine-readable format | Same route. Sent as JSON |
| Erasure (art. 17) | Delete your account and your data | Profile → Your account → Delete account. No emails, no waiting. Also at https://peltra.app/borrar-cuenta if you no longer have the app |
| Rectification (art. 16) | Fix what is wrong | Profile → Edit profile, or hello@peltra.app |
| Restriction and objection (arts. 18 and 21) | Ask us to stop processing something | hello@peltra.app |
We answer within one month. If you think we got it wrong, you can complain to the Spanish Data Protection Agency (AEPD, aepd.es) or to your own country's supervisory authority.
We make no automated decisions producing legal effects on you or similarly significantly affecting you (art. 22 GDPR). What the app "guesses" — the supermarket aisle for a product, the date inside a sentence — are writing aids you can always change, and they never leave your phone.
7. Children
Peltra is not directed at children under 14 and they may not use it (art. 7 of the Spanish LOPDGDD). We do not ask for age and do not profile by age. If we find an account belonging to someone below that age, we delete it.
8. Security
Concretely:
- Access to data is decided on the server, not in the app: every row has a policy saying who may read it and who may write it, so someone who can only view a list cannot change it even by tampering with the app.
- The session is kept in the system keychain (Keychain on iOS, Keystore on Android), never in ordinary storage.
- All traffic is encrypted (HTTPS/TLS).
- The key that bypasses permissions is not in the app: it lives only on the server.
No system is infallible. If a breach happens that poses a risk to your rights, we will notify the supervisory authority within 72 hours and you without undue delay, as arts. 33 and 34 GDPR require.
9. Changes to this policy
If something relevant changes we will update this page and say so inside the app before the change affects you. The date at the top says when it was last touched.