Lista da Casa — Gestão de Compras Domésticas
Developer: Leankar.dev
Contact: leankar.dev@gmail.com
Website: https://leankar.dev
Last updated: August 2, 2026
This Privacy Policy describes how Lista da Casa (“the App”, “we”, “our”) handles information when you use our mobile application available on Google Play.
The App is designed with a local-first architecture: all user-generated data (shopping lists, items, markets, and preferences) is stored exclusively on your device and is never transmitted to our servers. However, the App displays banner and interstitial advertisements through Start.io (formerly StartApp), a third-party mobile advertising network operated by Start.io Inc. As a result, certain device and usage information is collected and processed by Start.io for advertising purposes, as described in this policy. The App also uses the Google Play In-App Update API to check for and install app updates, which involves communication with Google Play services.
All data entered in the App is stored exclusively on your device. This includes:
| Data | Purpose | Storage |
|---|---|---|
| Username / Display name | Identify the local account | Device secure storage |
| Numeric PIN | Authenticate access to the App | Device secure storage (hashed + salted) |
| Shopping list names | Organize your lists | Local SQLite database |
| Shopping item names, quantities, prices, notes | Manage purchases | Local SQLite database |
| Category selections | Classify items | Local SQLite database |
| Market / store names and addresses | Track where you shop | Local SQLite database |
| Language preference | App localization | Device secure storage |
This data is never transmitted to us or any third party.
The App uses the Start.io (StartApp) SDK to display banner advertisements (shown on selected screens) and interstitial advertisements (shown occasionally, at most once every 30 minutes, after you complete a purchase in a shopping list). When ads are loaded, Start.io may automatically collect:
| Data | Purpose |
|---|---|
| Advertising ID (GAID on Android, IDFA/IDFV on iOS) | Ad targeting and measurement |
| IP address | Geographic targeting and fraud prevention |
| Device model, OS version, carrier, and settings | Ad rendering and compatibility |
| App/ad interaction data | Performance measurement and fraud detection |
| Coarse location (derived from IP address) | Regional ad targeting |
The App does not request the device’s Location permission, so Start.io cannot access GPS/precise location through the App — only the IP-derived approximate location described above. Start.io’s SDK may, as part of its normal operation, also collect information about other apps installed on the device for ad-targeting purposes.
This data is collected and processed by Start.io Inc. under its own privacy policy. We do not receive, store, or process this data ourselves.
Ads Consent: On first launch, the App shows an in-app dialog asking whether you agree to see ads. If you decline, the Start.io SDK is never initialized and no ad-related data described in this section is collected. If you accept, ads are shown and the data above may be collected by Start.io. You can review or change your choice at any time from Settings → Privacy & Ads. This mechanism does not implement the IAB Transparency & Consent Framework (TCF) or per-vendor granular consent — it is a simple accept/decline choice covering all ad-related data collection by Start.io.
We (Leankar.dev) do not collect any of the following:
All user-provided data is used solely within the App to deliver its features:
The App displays banner and interstitial advertisements provided by Start.io. The purpose of advertising is to sustain the App’s ongoing development while keeping it free for users. Start.io uses the data described in Section 2.2 to select and display relevant advertisements.
We do not use your locally stored app data (shopping lists, items, markets) for advertising purposes.
The App uses the Google Play In-App Update API to check whether a newer version is available and, depending on the update’s priority, to prompt a flexible or immediate update. This feature communicates with Google Play services on your device and is governed by Google Play’s own terms and privacy practices. No app data (shopping lists, items, markets) is shared through this feature.
| Storage Layer | Contents | Technology |
|---|---|---|
| Secure storage | PIN (HMAC-SHA256 hashed with cryptographic salt), username, preferences | Android Keystore / iOS Keychain |
| Local database | Shopping lists, items, markets, history | SQLite (via Drift ORM), file: lista_da_casa.db |
All user-provided data resides entirely on your device. There is no cloud sync, no remote backup, and no server-side storage by us.
FLAG_SECURE window flag at startup, which prevents screenshots, screen recordings, and App Switcher previews from capturing any App content.The local SQLite database itself is not encrypted at the file level. Physical access to a rooted or jailbroken device could expose the database contents. We recommend keeping your device secure and using a strong PIN.
We do not share your locally stored data (shopping lists, items, markets) with anyone. This data never leaves your device.
The App integrates the Start.io advertising SDK, which collects and processes the data described in Section 2.2. This constitutes a sharing of technical and usage data with a third party for advertising purposes. Start.io Inc. acts as an independent data controller for this data.
The App’s in-app update feature (Section 3.3) communicates with Google Play services to determine whether an update is available. This is governed by Google’s own privacy policy: https://policies.google.com/privacy.
No other data is sold, rented, licensed, or shared with any party.
The App uses the following open-source and third-party libraries:
| Library | Purpose | Data Collection |
|---|---|---|
| Drift / SQLite | Local database | None — local only |
| flutter_secure_storage | Platform-native secure storage | None — local only |
| crypto | PIN hashing | None — local only |
| google_fonts | Font rendering (may cache fonts locally) | May request font files from Google servers; no personal data sent |
| fl_chart | Charts and graphs | None |
| flutter_riverpod | State management | None |
| flutter_neumorphic_plus | UI design system | None |
| url_launcher | Opening external links (e.g. this policy, app store page) in the device’s browser | None collected by the App itself |
| startapp_sdk | Banner and interstitial advertising (Start.io) | See Section 2.2 and Section 7 |
| in_app_update | Google Play in-app update checks and prompts | See Section 3.3 and Section 5.3 |
Note on Google Fonts: The
google_fontspackage may request font files from Google’s servers on first use if fonts are not yet cached on the device. No personal data is included in these requests.
Before any ad is loaded, the App shows an in-app consent dialog asking you to accept or decline ads. Your choice is stored on your device and used as follows:
This is a binary accept/decline mechanism, not an IAB Transparency & Consent Framework (TCF) implementation with per-vendor granularity. In addition:
For users located in the EU/EEA, the following applies under the General Data Protection Regulation (GDPR):
For users located in Brazil, the following applies under the Lei Geral de Proteção de Dados (LGPD — Lei nº 13.709/2018):
For users located in California and other US states with applicable privacy laws:
Because all user-provided data is local to your device, you have full and immediate control:
| Right | How to Exercise |
|---|---|
| Access | All your data is visible directly within the App |
| Correction | Edit any list, item, or market from within the App |
| Deletion | Delete individual items, lists, or markets within the App; use “Delete Account” in Settings to erase all data |
| Portability | The SQLite database file (lista_da_casa.db) can be accessed and exported from the application data directory |
| Withdraw | Uninstall the App — all local data is permanently deleted from the device |
| Ad Preferences | Opt out directly with Start.io at start.io/optout-right or privacy@start.io |
| Advertising ID | Reset or delete via device settings (see Section 7.4) |
Lista da Casa, developed by Leankar.dev, gives you two ways to delete your data:
1. Delete in-app data (Settings → Delete Account)
This immediately and permanently erases, from your device:
Your language preference and ad-consent choice (Section 7.1) are device settings, not personal data, and are kept so the App remembers them if you continue using it — they are also erased if you uninstall the App.
2. Uninstall the App
Uninstalling Lista da Casa from your device deletes the entire application, including the local database and all secure storage entries, with no data retained on our side — we never had a copy, since everything is local-first (Section 4.1).
3. Data held by Start.io (advertising SDK)
If you accepted ads (Section 7.1), the Start.io SDK may have already sent your Advertising ID and IP address to Start.io’s servers before you delete the App. Neither of the two options above can recall data already sent to Start.io. To request its deletion, contact Start.io directly:
Start.io retains this data according to their own retention policy (see Section 10.2); we do not control or have access to it.
What is never deleted because it was never collected: we do not operate any servers or accounts, so there is no copy of your shopping data, username, or PIN anywhere outside your device to delete.
For rights requests related to advertising data collected by Start.io, contact Start.io directly (privacy@start.io) or use the controls described in Section 7.
The App does not knowingly collect personal information from children under the age of 13 (or the applicable minimum age in your jurisdiction). The App contains no social features, no accounts linked to real identities, and no online communication.
The advertising displayed through Start.io is configured for a general audience. If you believe a child is using the App, we recommend using parental control features available on your device to limit ad-related data collection.
If you are a parent or guardian and have concerns, please contact us at leankar.dev@gmail.com.
Data is stored on your device for as long as the App is installed and you choose to retain it. There is no automated expiration of data. When you uninstall the App, the operating system removes all application data, including the SQLite database and all secure storage entries.
Advertising data collected by Start.io is retained according to Start.io’s own data retention policies. For details, see Start.io’s Privacy Policy.
The App requests the following permission:
| Permission | Required For |
|---|---|
INTERNET |
Loading and displaying advertisements (Start.io) and checking for app updates (Google Play In-App Update) |
The App does not request access to:
All user-provided data (lists, items, markets, credentials) is accessed only within the App’s own sandboxed application directory on the device. Note that, independent of the permissions listed above, the Start.io advertising SDK may automatically access certain device-level and network-level information (such as the Advertising ID, IP address, and technical device data) as described in Section 2.2, as is standard for mobile advertising SDKs.
We may update this Privacy Policy to reflect changes in the App’s features or applicable law. When we do:
Continued use of the App after an update constitutes acceptance of the revised policy. We encourage you to review this page periodically.
If you have any questions or concerns about this Privacy Policy or the App’s data practices, please contact us:
Email: leankar.dev@gmail.com
Website: https://leankar.dev
App: Lista da Casa — available on Google Play
We will respond to all inquiries within 30 days. For EU/EEA users: we will respond within the timeframes required by GDPR (typically within one month, extendable to three months for complex requests).
© 2026 LeanKar. All rights reserved.