Privacy Policy
Last updated: August 29, 2026
This page is an English translation provided for convenience. The Czech version is the legally binding one.
Rodly is a shopping app that works primarily on your device (local-first). This policy explains what data we collect, why, and how we protect it.
Data we collect
- Account e-mail. Used to sign you in — via single-use magic links, or with Google or Apple — and to contact you about your account.
- Display name. The name shown to people you share lists or recipes with. You can change it at any time.
- Preferences and notifications. Your language and — if you enable notifications — your device identifier, so Apple or Google can deliver them.
- Your lists, items, recipes, tags, loyalty cards and dictionary. Stored encrypted — the server holds only encrypted content, not readable data. This includes loyalty-card barcodes and recipe names, ingredients and steps.
- Recipe photos. Uploaded to our servers so they sync across your devices and appear for anyone you share the recipe with. Unlike your other content they are not encrypted: each is stored as an image file served from a unique, hard-to-guess link — anyone who has that link can view it.
- Profile photo. If you upload one, or we take it over from your Google account, we store it on our storage. Like recipe photos it is not encrypted and is served from a unique, hard-to-guess link — anyone who has that link can view it. You can remove it in the app at any time.
- Who added and checked off an item. For list items we store who added them and who checked them off and when, so members of a shared list can see it. The “Checked-item history” toggle in Settings controls only the display, not the recording.
- Security logs. For sign-ins, sharing and other security-relevant actions we record the time, your IP address and your device or browser details, so we can spot account abuse. E-mail addresses appear in these logs only as a one-way hash.
- Diagnostics. Crash and error reports that help us fix bugs. We disable personal-data collection in our diagnostics tooling and scrub tokens and secrets before anything is sent. No advertising identifiers are collected.
- Usage analytics (off by default; you can enable it when creating an account, or anytime later in Settings). Anonymous product-usage events — for example that a list was created, or which screen was viewed. They contain no list, item, recipe or loyalty-card contents and no personal data. We do not use your IP address for geolocation.
Device permissions
We use the camera and photo library to scan loyalty-card barcodes and to add photos to your recipes. Barcodes are read on your device and never uploaded; recipe photos are uploaded and stored as described above.
Sharing lists and recipes
When you share a list, the people you invite can see its contents, any loyalty cards attached to it, your display name and — per item — who added it and who checked it off and when. When you share a recipe, they can see its name, ingredients, steps, tags and photos, and your display name. You can revoke access at any time. We only show you contacts you already share lists or recipes with, plus the members of your organisation if its administrator has turned on automatic contacts — the app does not read your device's address book.
If an administrator adds you to an organisation (a feature for businesses and households), they can turn on automatic recipe sharing — members' recipes are then shared with each other. They can also turn on automatic contacts — members of the organisation then see each other's display name and e-mail address among their sharing contacts. Both are off by default, and you can leave the share on any individual recipe.
Third-party services
- Notification delivery. Apple (APNs) and Google (FCM) receive a device token so notifications can reach your device, together with the text of the notification itself. For notifications about a shared list that text includes the list name and the names of the items added, so bear in mind it can appear on your lock screen. You can turn these notifications off in Settings.
- Sign in with Google or Apple. If you choose this way to sign in, Google or Apple performs the sign-in and passes us your e-mail address, your name and — with Google — your profile photo. If you use Apple's “Hide My Email”, we only ever receive Apple's relay address, not your real one.
- Diagnostics (Sentry). Crash and error reports are processed by Sentry with personal-data collection disabled.
- Usage analytics (Mixpanel). Only if you enable it, anonymous usage events are processed by Mixpanel on EU-based servers, with IP-based geolocation disabled.
How we use your data
- To sign you in and keep your account secure.
- To synchronise your data across your devices.
- To deliver notifications you've opted into.
- To diagnose and fix crashes and errors.
- To spot account abuse and investigate security incidents.
- To understand how the app is used and improve it (usage analytics), only if you enable it.
We do not sell your data, and we do not use it for advertising.
How we protect it
- List, item, recipe, tag, loyalty-card and dictionary contents are encrypted at rest. Recipe photos are the exception: they are stored unencrypted, as described above.
- All traffic between the app and our servers is encrypted in transit (TLS).
- Sign-in uses single-use, short-lived links — there are no passwords to leak.
Data retention
We keep your data while your account is active. Deleted content is purged from our servers within 30 days — deleting a recipe also removes its photos. Security logs are deleted after 12 months. When you delete your account, it is scheduled for permanent erasure after the 30-day recovery window.
Deleting your account
You can delete your account at any time directly in the Rodly app: open your profile and choose “Delete account and all data”. After you confirm, the account stays recoverable for 30 days — sign in again within that window and the deletion is cancelled — after which the account and all associated data are permanently erased.
Don't have the app handy? You can also delete your account on the web on the Delete account page. Enter the e-mail you sign in with and confirm via the link we send you. The same 30-day recovery window and permanent erasure afterwards apply.
Contact
Questions about your privacy? Write to us at podpora (at) rodly.cz.
Your rights under the GDPR
The GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC), which governs the area of personal data, gives you the right to: access your data, have it rectified or erased, restrict its processing, data portability, object to processing, or withdraw consent. You can exercise your rights at any time by sending an e-mail to podpora (at) rodly.cz.
If you believe that the processing of your personal data violates legal regulations, you have the right to lodge a complaint with the competent supervisory authority in the Czech Republic:
Úřad pro ochranu osobních údajů (ÚOOÚ, the Czech Office for Personal Data Protection)
Address: Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
Web: https://www.uoou.cz | E-mail: posta@uoou.cz