Skip to main content

Privacy Policy

Last updated: August 15, 2026

The short version

My Next: List is an offline-first app. Your personal content — your lists and the items on them — stays on your device. We don't collect it, we don't see it, we don't sell it.

Two limited things do leave your device, and neither is your content.

Anonymous product analytics. A small record that the app was opened. It contains no list content and nothing that identifies you. It helps us see whether people actually use the app and which version to keep improving. You can turn it off completely in Settings, and the app works exactly the same either way.

Subscription information. To offer My Next: Extra, the app works with RevenueCat, our subscription provider. It sends a randomly generated customer ID and handles your App Store purchase and entitlement status — never your name, your email address, or your card details. This is how Extra unlocks, how restoring a purchase works, and how one Extra subscription activates across Todo, List, and Note. It is required for subscriptions to function, so it is not covered by the analytics switch.

You never need an account or an email address to use My Next: List.

Data storage

All your lists, items, and settings are stored locally on your device using Apple's Core Data framework. This includes any grocery quantity and unit data you enter. Your personal content never leaves your device unless you explicitly choose to export or back it up.

Anonymous analytics

To understand how much My Next: List is used, the app sends a single kind of event — an app-open event — to OpenPanel, a privacy-focused analytics service. Each event contains only:

  • That the app was opened (the event itself)
  • Which app it was — Todo, List, or Note
  • Whether it was a cold launch or a warm launch
  • The language the app is set to
  • The time the event happened
  • A randomly generated anonymous identifier, used only to tell one device's app-opens apart from another's so we can count people rather than launches. It is not derived from your Apple ID, your name, your email address, or any device identifier, and it cannot be traced back to you.

That is the complete list. No list names, no list items, no note or todo content, no names, no email addresses, no advertising identifiers, no account details, no location, and no purchase information are ever included in an analytics event. (Subscription data is handled entirely separately — see Subscriptions and My Next: Extra below.)

These events are used for one purpose: understanding app openings so we can improve the app. They are not used for advertising, not used for advertising tracking across other apps or websites, not used to build marketing profiles, and never sold to data brokers.

Turning analytics off

Analytics is a single switch in the app's Settings. Turn it off and it stays off — there is no re-prompt and no expiry.

  • No further analytics events are sent.
  • Any events still queued on your device waiting to be sent are deleted instead.

One honest caveat: turning analytics off stops everything from that moment forward, but it does not automatically delete events that OpenPanel already received before you switched it off. If you would like those removed as well, email us and we will arrange it.

To be clear about what the switch does not cover: it turns off the anonymous OpenPanel analytics only. It does not affect RevenueCat, which handles subscriptions and has to run for Extra to work at all. That is described in the next section.

What we never collect

  • No list names or list item content
  • No names, email addresses, or account information
  • No advertising identifiers or cross-app advertising tracking
  • No location data
  • No contacts or calendar data
  • No card numbers or payment details — Apple processes every payment, and card information never reaches us or any of our providers
  • No crash reports sent to us (we use on-device logging only)

Subscriptions and My Next: Extra

My Next: List offers its own per-app Extra subscription and Tip Jar, processed by Apple through the App Store. My Next: Extra — a cross-app subscription that activates Extra in Todo, List, and Note — is an additional option.

Subscriptions are handled by RevenueCat, a subscription-management service acting as our data processor. Being straightforward about the timing: RevenueCat starts when the app starts, not only when you buy something. The app needs it running to load the current offerings and to check whether you already have Extra, so this applies to everyone who opens the app — not only to subscribers.

What the app sends to RevenueCat:

  • A randomly generated My Next customer ID. It contains no name, no email address, no account ID, and no other direct personal identifier — it is pseudonymous, which means it identifies a subscription rather than a named person.

The ID is generated on your device the first time it is needed and kept in a shared keychain entry that Todo, List, and Note can all read. That shared entry is the entire mechanism behind “one subscription, three apps” — it is why Extra works everywhere without you ever creating an account.

What RevenueCat processes on our behalf:

  • Your purchase and subscription history, as reported by Apple
  • Which products and entitlements are active
  • Related subscription information received from Apple

What it is used for:

  • Validating App Store receipts
  • Preventing fraud
  • Unlocking and enabling Extra features
  • Restoring access to a purchase you already made
  • Sharing one Extra entitlement across the My Next app family, so a single subscription works in Todo, List, and Note
  • Subscription analytics — how many subscriptions renew or lapse

RevenueCat never receives your payment-card information. Apple processes all payments, and card details never pass through the app. None of this data is used for advertising or for tracking you across other companies' apps and websites.

Because Extra cannot work without it, RevenueCat is not covered by the analytics switch in Settings. The switch governs the anonymous OpenPanel analytics only. See RevenueCat's privacy policy for details.

Data export and deletion

You can export your data at any time from within the app. Since your personal content lives only on your device, deleting the app removes all of it. We have no backups of your content and cannot recover it.

Worth knowing before you share a backup file: if you have My Next: Extra, the backup also carries your My Next customer ID. That is deliberate — it is how Extra follows you to a replacement phone when you restore a backup, without you needing an account. It does mean a backup file is a private document. Anyone you hand it to receives both your content and a handle that could unlock Extra, so treat it the way you would treat any personal file.

Third-party services

My Next: List uses no advertising services and no cross-app tracking services. The external services involved are:

  • OpenPanel — the analytics processor that receives the anonymous app-open events described above. Nothing you write in the app is sent to OpenPanel, and the events are never used for advertising or sold on. See OpenPanel's privacy policy for details.
  • RevenueCat — our subscription data processor. It receives a randomly generated My Next customer ID plus the purchase and entitlement information Apple reports, and uses it for receipt validation, fraud prevention, unlocking and restoring Extra, sharing Extra across the My Next apps, and subscription analytics. It starts with the app rather than only at purchase time, receives no card details, and is never used for advertising or cross-company tracking. It is required for subscriptions and is not covered by the analytics switch. See RevenueCat's privacy policy for details.
  • Apple App Store — processes all purchases and subscription transactions, including all payment details.
  • Apple Keychain — stores the My Next customer ID in a shared keychain group on your own device, so Todo, List, and Note recognise the same Extra subscription. This never leaves your device except as part of the RevenueCat exchange described above.

Future changes

If we introduce optional cloud sync in the future, it will be entirely opt-in. Your data will remain local by default, and any sync feature will use end-to-end encryption. We will update this policy before introducing any such feature.

Contact

If you have questions about this privacy policy, contact us at privacy@mynextstudio.com.