Privacy
Last updated: August 21, 2026
This policy covers the TO DO / SHOPPING LIST app only. The other Forsoka Culinary Arts apps are community services and have their own, longer policy; this app is a notebook, and its policy is short because there is little to tell.
The short version
Your lists stay on your device, and on Apple devices in your own iCloud account so your iPhone, iPad and Mac show the same thing. Nothing goes to our server unless you choose to: sharing sends that one list, and the optional backup - off until you turn it on - keeps a copy of your notebook so a lost phone doesn't mean a lost list. There are no accounts and no sign-in (backup works anonymously; an email is optional and only for recovery), no analytics, no advertising, and no third-party trackers.
What is stored on your device
Your lists, the places you attach with the at button, the aisles you teach the app by long-pressing, and a small cache of nearby-store lookups. On iPhone, iPad and Apple Vision Pro this lives in the app's private container; on Mac it lives in the app's sandboxed Application Support folder. The app never reads or writes your Documents, Desktop or other personal folders.
What leaves your device, and when
iCloud, on Apple devices. So that your own devices agree, your lists are kept in your personal iCloud account using iCloud key-value storage. This is Apple's storage under your Apple Account, not ours - we have no account, no container and no way to read it, and it is covered by Apple's privacy policy rather than this one. It syncs your own devices only; it is not how sharing with other people works. Signed out of iCloud, or with iCloud Drive off for the app, the feature simply does nothing and your lists stay on the device.
Android has no equivalent: lists there stay on the phone, plus whatever Google's own app backup keeps (see Backups below).
Our server: only when you share a list. Choosing Share this list uploads that list's contents to our server (pantryponder.com) so other people can open it. It is stored under a random, unguessable 128-bit token.
Our server: backup, if you turn it on. Backup is off by default. Switched on, it keeps a copy of your whole notebook - every list, including the ones you never share - on our server, so a lost or new phone can get them back. It works without any account: your copy is filed under a random identity generated for your device, tied to nothing about you.
- An email address is optional, and it does exactly one thing: it lets a new device claim your lists by proving it can receive a 6-digit code at that address. We use it for nothing else - no newsletters, no login.
- Like shared lists, backups are stored as ordinary text, not end-to-end encrypted. We do not look at them, but we could, so the same advice applies.
- Turning backup off deletes the server copy. It is kept in a recoverable state for 30 days (so an accidental deletion can be undone by support), then permanently removed. The lists on your device are never touched.
Three things to understand about a shared list:
- Anyone with the link can read and edit it. There is no account and no per-person permission. Treat the link like a key.
- We can technically read it. It is stored on our server as ordinary text, not end-to-end encrypted. We do not look at it, but we could, so do not put anything sensitive in a shared list.
- Stopping sharing removes it from the server. Everyone who already joined keeps their own copy on their device. The list stops being reachable the instant you stop sharing; the record is then erased from our database by a separate housekeeping process rather than lingering indefinitely.
A shared list that nobody has changed for 90 days is deleted automatically.
Place lookups. Searching with the at button sends what you typed to a map service to find nearby matches - Apple Maps on Apple platforms, OpenStreetMap's Nominatim on Android - with your coordinates used to bias the results toward you.
Checking whether you are standing at a store works differently depending on what the line says:
- A specific shop you picked is matched entirely on your device, by comparing your position with the coordinates already saved on that line. Nothing is sent anywhere.
- A general label like Supermarket or Safeway sends your coordinates to our places service (
pantryponder.com/places), which answers with the name of the shop at that spot. The request contains no account, device or user identifier - just the coordinates and which app is asking. The service resolves the answer, discards the coordinates, and keeps only an anonymous "this ~55 m square contains a shop called X" cache row shared across the Forsoka Culinary Arts apps. It never records where any individual has been. - Anything it does not recognise falls back to the platform's own nearby search, as above.
Results are cached on your device for a week so the same lookup is not repeated.
Location
Your location is only ever used to look up nearby shops, and is never stored or tied to you. It is requested only while you are using the app, only when a line actually has an at on it, and no location history is kept on your device or ours.
You can decline location access; everything else in the app keeps working and the highlighting simply stays off.
Backups
The app does not run a backup service of its own. It inherits whatever the platform already does for any app: on iPhone, iPad and Apple Vision Pro your lists are included in iCloud Backup and in encrypted computer backups; on Android they are included in Google's app backup to your Drive when you have that turned on; on Mac they are in the app's container, which Time Machine captures. These are your backups in your account, not ours.
What we do not do
No accounts or sign-in. No analytics or crash-reporting SDKs. No advertising or ad identifiers. No selling or sharing of data with anyone. No tracking across apps or websites.
Children
The app is not directed at children and collects no personal information.