Privacy Policy

Effective date: May 5, 2026 · Last updated: May 5, 2026

SigmaList ("we", "our", or "us") is built on a simple principle: your lists are yours. This policy explains what we collect, why, and how we protect it.

1. What we collect

Account information. When you sign in with Google, Microsoft, or Apple, we receive your email address and display name from that provider. We store only your email and which provider you used — no passwords, no profile photos.

Your lists. Everything you type into SigmaList — list names, item names, quantities — is stored on our servers encrypted with AES-256-GCM. Your email address is used as the encryption key derivation input. Only you can decrypt your data.

Usage signals. We collect anonymous product feedback (thumbs up / thumbs down after AI features) and optional NPS scores. These are not linked to individual items in your lists.

Technical logs. Server logs may include IP addresses and request paths for up to 7 days for security and debugging purposes. We do not log the content of your lists.

2. What we do not collect

3. AI features

When you use the "Generate" or "Categorize" features, your list prompt or item names are sent to the Grok API (operated by xAI) for processing. xAI's privacy policy governs how they handle that data. We do not send your full list history — only the specific items relevant to the current request.

If this concerns you, you can use SigmaList without AI features — sorting, sharing, and real-time collaboration work entirely without sending data to any AI provider.

4. Cookies and local storage

SigmaList sets only the strictly-necessary cookies the app requires to function. We do not display a cookie consent banner because, under GDPR Article 7 (Recital 30) and equivalent regimes, explicit consent is not required for strictly-necessary cookies. The disclosure below stands in lieu of one.

Cookies we set:

Both cookies are first-party (set by sigmalist.xyz), used only by this app, and expire automatically on sign-out or after 7 days of inactivity. We do not set advertising, analytics, or cross-site tracking cookies of any kind.

Your preferences (theme, font, language, per-list toggles) are stored in your browser's localStorage — they never leave your device.

5. Push notifications

If you enable push notifications, your browser's push subscription endpoint (provided by your browser vendor — Google, Apple, or Mozilla) is stored on our servers linked to your email. We use this only to deliver list reminders and nudges from collaborators. You can revoke this at any time in Settings.

6. Sharing

When you share a list, anyone with the link can view (or edit, depending on the link type) that list. Shared lists are not encrypted in transit — they are readable by anyone who has the link. Revoke sharing at any time to remove access.

7. Data retention and deletion

Your account and all associated data can be deleted at any time from Settings → Delete account. Deletion takes effect after a 7-day grace period (to prevent accidental loss). After that, your data is permanently removed from our servers.

Session files are automatically deleted after 7 days of inactivity.

8. Your rights

You may request a copy of your data or its deletion at any time by emailing us at beyondsyms@gmail.com. EU/UK residents have additional rights under GDPR/UK GDPR including the right to rectification and data portability.

9. Security

All data in transit is encrypted via HTTPS. Data at rest is encrypted with AES-256-GCM. Session tokens are signed with HMAC-SHA256. We rotate secrets regularly and clear orphaned sessions on rotation.

10. Changes to this policy

If we make material changes we will update the "Last updated" date at the top of this page. Continued use of SigmaList after changes constitutes acceptance of the updated policy.

11. Contact

Questions? Email us at beyondsyms@gmail.com.