You're offline. You can look around, but changes won't save until you reconnect.
Spisko pisko

Privacy Policy

Last updated: September 22, 2026

This policy explains what information Spisko ("we", "us") collects when you use the app, why we collect it, and what control you have over it.

This is a plain-language policy drafted for Spisko's actual features. It is not a substitute for legal advice — have it reviewed by counsel before treating it as binding, especially if Spisko is offered outside your home jurisdiction.

What we collect

Account information. When you sign up, we (via Supabase Auth) store your email address and an authentication credential — either a password hash or an OAuth identity if you sign in with a third-party provider. We don't ask for your name, phone number, or any other personal details to create an account.

Inventory and list data. Everything you enter to use the app: items, categories, storage locations, shopping lists, and quantities. This data is yours — it's scoped to your account (or to a shared space you've joined) and isn't visible to other users unless you explicitly share a space with them.

Barcode scans. When you scan a barcode, the product name and details are looked up against a shared, crowd-sourced database of barcode-to-product mappings that all Spisko users contribute to and benefit from. This mapping (barcode → product name) is not linked to your account or identity — it's shared product reference data, not personal data.

Location data. If you use the "nearby stores" feature, we look up your approximate location either from your device's browser geolocation (only after you grant permission) or, as a fallback, from your IP address via a third-party lookup service. This is used to find stores near you and is not stored on our servers beyond the request. If you manually add a store location (e.g. by placing a pin on a map), those coordinates are stored as part of that location record, the same as any other inventory data.

Contact form submissions. If you use the contact form, we receive the subject and message you write, along with your email if you're signed in. We use this only to respond to you — not for marketing.

Cookies and local storage. We use browser local storage to keep you signed in (your session token) and to remember your theme preference (light/dark). We don't use cookies or local storage for advertising or cross-site tracking, and we don't run any third-party analytics or ad scripts.

AI assistant access (MCP). If you generate a personal access token to connect an AI assistant to your Spisko data via our MCP server, that token grants the same access to your data that you have. Treat it like a password — anyone with the token can read and modify your inventory and lists until you revoke it.

How we use it

We use your data solely to operate the app: authenticating you, storing and displaying your inventory and lists, powering search/suggestions, and responding to support requests. We don't sell your data, and we don't share it with third parties except the infrastructure providers necessary to run the service (see below).

Who else sees it

  • Supabase hosts our database, authentication, and file storage. They process data on our behalf under their own data processing terms.
  • ipwho.is (or a similar IP-geolocation provider) receives your IP address if you use IP-based nearby-store lookup, in order to return an approximate location.
  • Other members of a space you share can see the inventory, categories, and lists within that shared space — that's the point of space sharing, and it's something you opt into explicitly.
  • We do not sell, rent, or share your data with advertisers or data brokers.

Your controls

  • You can edit or delete any item, category, location, or list at any time.
  • Deleted items are soft-deleted (recoverable via undo) rather than immediately erased, so accidental deletes aren't unrecoverable. We don't currently run an automatic purge of soft-deleted items; they're excluded from every normal view but remain recoverable until you delete your account.
  • You can revoke any MCP personal access token at any time from Settings.
  • You can leave a shared space at any time, which removes your access to its data.
  • You can download a copy of your data (inventory, categories, locations, shopping lists, and profile) at any time from Settings, as a JSON file.
  • You can delete your account yourself at any time from Settings — this is immediate and does not require contacting us. It removes your account and the inventory data scoped to it, other than data that has become part of a shared space owned by another user, or the crowd-sourced barcode database (which is not personal data).

Data retention

We keep your data for as long as your account is active. If you delete your account, we delete the personal data associated with it within a reasonable period, except where retention is required by law or where the data has been anonymized (like barcode→product mappings, which aren't tied to your identity).

Children

Spisko is not directed at children and we don't knowingly collect data from them. We apply the higher of the age thresholds that can apply to you: under 16 in the EU/EEA and UK (the GDPR default, absent a lower age set by your member state), and under 13 elsewhere (the US COPPA threshold).

Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date above. Continued use of Spisko after a change means you accept the updated policy.

Contact us

Questions about this policy or your data? Use the contact form on the homepage.