Last updated: 2026-08-28
Overview
EveryList is a self-hosted list app. The EveryList mobile and web app ("the App") is published by Brian Ramsey ("we", "us"), but the App does not talk to any server we operate. Instead, on first launch the App asks you for the address of a EveryList server — either one you run yourself, or one operated by someone you trust — and everything the App does after that happens directly between your device and that server.
Because of that design, this policy is split into what we (the App's developer) do, and what happens on the server you choose to connect to, which is outside of our control.
What we collect
Nothing. We do not operate a backend for the App, do not run analytics or crash-reporting services, do not show ads, and do not use third-party trackers of any kind. We have no visibility into what you do in the App, what server you connect to, or what data that server holds.
Data handled by your self-hosted server
When you set up the App with a server address, that server (not us) stores the data you give it, which typically includes:
- Your account email address, display name, and a salted hash of your password
- The lists, categories, items, and stores you create, and any changes you make to them
- Membership and invite information for lists you share with others
That data is controlled entirely by whoever operates the server you connected to — which may be you. Review that operator's own policies (or your own setup) if you have questions about how it's stored, backed up, or secured.
Data stored on your device
The App keeps a few things locally on your device so it can work offline and remember your settings:
- The server address you configured and your login session token
- A local cache of your lists, items, and categories, so they're available offline and sync back to your server once you're reconnected
This data stays on your device and is never sent anywhere except the server you configured.
Optional third-party integrations
If you choose to connect EveryList to Amazon Alexa or Home Assistant, your server issues a personal access token for that integration. Any data exchanged then flows directly between your server and that third-party service, governed by your own configuration and that service's own privacy policy — not by us.
Children's privacy
The App is not directed at children under 13, and we do not knowingly collect information from them — see "What we collect" above.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Continued use of the App after a change means you accept the update.
Contact
Questions about this policy: privacy@everylist.dev