Draft. These details are incomplete and not yet legally binding. Bagful is in a non-public beta.

Privacy policy

Courtesy translation. The German version is the legally authoritative one.

1. Controller

«Anbietername eintragen»
«Straße und Hausnummer»
«PLZ» «Ort»
Deutschland
Email: «kontakt@bagful.app»

No data protection officer has been appointed; the threshold in §38 BDSG (generally at least 20 people permanently engaged in automated processing) is not met.

2. What we process

DataPurposeLegal basis
Name, email address, password (stored only as a hash)Creating and running your accountArt. 6(1)(b) GDPR
Your device's push token, its platform, and when it was last seen Delivering notifications to that device. The token belongs to the app installation rather than to you: signing into a different account on the same device moves it to that account. It is removed when you sign out and when you delete your account. The data export omits the token itself — it is a key, not a fact about you Art. 6(1)(b) GDPR
Profile picture, if you upload one Making you recognisable in your bags. The picture is served publicly from a random, unguessable address and is shown in the app only to people you share a bag with. Anyone who knows the address can fetch it; replacing or removing the picture retires that address. The public invitation preview never shows pictures, only initials Art. 6(1)(b) GDPR
Guest account: a random identifier, no name, no email addressUsing Bagful without registering, in particular when joining via an invitation linkArt. 6(1)(b) GDPR
Session identifier, session IP address and user agentKeeping you signed in, detecting abuseArt. 6(1)(b) and (f) GDPR
Lists, items, quantities, units, notes, categories, emojisThe service itselfArt. 6(1)(b) GDPR
Memberships and roles, invitation tokens and bag codes, expiry and use countersSharing lists with other peopleArt. 6(1)(b) GDPR
Who added or checked off an item, and whenMaking collaboration legible — visible to every member of that listArt. 6(1)(b) GDPR
Who has taken on fetching an item, and when Avoiding duplicate shopping — visible to every member of that list, and readable by a connected AI assistant if you have one. The entry is cleared when the item is checked off or removed, when you leave the list, and when your account is deleted. Art. 6(1)(b) GDPR
Notifications: what happened, who did it and in which bag — stored as a snapshot taken at the time of the event Telling you about changes in your bags. A notification about you stays in other members' inboxes even if you delete your account — your name is removed, the event itself remains. Art. 6(1)(b) GDPR
Units you create: a short form and a name, both your own words Your own measures, like "bunch" — visible to every member of a bag where you have used one on an item. They are not translated and stay exactly as you write them. Art. 6(1)(b) GDPR
Registered AI clients, consents granted, access tokensConnecting your own AI assistant over MCPArt. 6(1)(a) GDPR

We process no special categories of personal data within the meaning of Art. 9 GDPR. The service is not directed at children.

3. Recipients and processors

Data processing agreements under Art. 28 GDPR are in place with all of the following.

ProviderRoleProcessing location
NeonDatabase — all account and list dataAWS eu-central-1, Frankfurt
CloudflareRunning the application, caching, realtime connections, serving the website, bot protection (Turnstile), and sending verification and password-reset email. Processes the IP address of every requestEU data centres, global network
SentryError diagnostics in the web application and the api / realtime workersEU region (Frankfurt)

On Sentry specifically: the error message, stack trace, page or route visited and browser/OS or Worker runtime version are transmitted. The IP address is technically present on receipt but is not stored (sendDefaultPii: false). There is no session replay and no performance tracing. Invitation tokens and connection tickets are stripped from URLs before transmission. The mobile app has no error diagnostics wired in.

On voice input in the mobile app: dictation is optional and stays off until you tap the microphone in the app. When you do, the recording is handed to your own device's speech recognition (iOS Speech, or Android SpeechRecognizer). On many devices that recognition does not happen on the phone but on Apple's or Google's servers, under those companies' own terms and within your own relationship with your operating system's vendor. We have no control over it and cannot enter into a processing agreement about it — which is exactly why Apple and Google are named here and not in the table above. Bagful itself never receives or stores the recording. All that reaches us is the text that comes back, and even that only once you actually save the item — cancel the dictation and nothing is left behind. On iOS the permission prompt tells you the same thing before speech recognition is used for the first time.

4. Disclosure to AI assistants on your instruction

Bagful exposes an MCP interface that lets you connect your own AI assistant (such as Claude or ChatGPT) to your lists. That connection is created solely by your explicit consent on the consent screen. The connected service receives the lists:read scope (read lists and items) and, where granted, lists:write (create, change, check off and delete items).

The provider of the assistant you choose is an independent controller for the processing that happens on their side; this is not processing on our behalf. You may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR) — an email to the address above is enough.

5. Fetching recipe pages

When your AI assistant asks for the contents of a recipe URL you named, our server fetches that page, not your browser. The site in question therefore sees our server's IP address, not yours. Only publicly reachable addresses are fetched. The URL and the extracted text are cached for one hour.

6. Realtime synchronisation

An open list holds a WebSocket connection so changes appear immediately for every member. The connection is authorised with a short-lived signed ticket. Change events travel over it; nothing is stored there.

7. Cookies and local storage

PurposeLifetime
Session cookie keeping you signed in (HttpOnly, SameSite=Lax)Until the session expires or you sign out
Short-lived cache of the session check5 minutes
Bot protection (Turnstile) on sign-up and guest accessOnly for the duration of the check
Mobile app: session token in the device's secure storageUntil you sign out
Mobile app: local shopping-list copy and pending sync queue (SQLite on the device)Until you sign out or delete the account; wiped with the session

All of the above are strictly necessary for the service you explicitly requested, within the meaning of §25(2) no. 2 TDDDG. No consent is required and we run no consent banner. We use no analytics, tracking or advertising cookies. The web app does not keep a local shopping-list database — only the mobile app does.

8. Retention

9. Account deletion

When an account is deleted, every list owned solely by that account with no other members is permanently deleted along with all its items. Lists that do have other members are automatically transferred to the longest-standing remaining member, so that the other members' data is preserved. Membership is removed from all other lists, and remaining entries are anonymised so they can no longer be attributed to the deleted account. Invitation links and bag codes created by that account stop working — including the code of a bag that was transferred to another member. The new owner can create a fresh code at any time.

10. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Consent you have given may be withdrawn at any time with effect for the future (Art. 7(3) GDPR).

The main ones you can exercise directly in the app, under Account:

For anything else, send a message to «kontakt@bagful.app».

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is: «zuständige Landesdatenschutzbehörde» («https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_node.html»).

11. No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. We run no advertising and sell no data.

12. Changes to this policy

We update this policy as the service changes. The version published here, with the date shown below, is the applicable one.

Last updated: 2026-07-28