The short version
My Next: List is an offline-first app. Your personal content — your lists and the items on them — is stored locally on your iPhone and, when installed, your paired Apple Watch. The two apps synchronize directly using Apple's WatchConnectivity framework. We do not receive, view, or sell that content.
Two limited data categories are sent to external services, and neither contains your list content.
Optional usage analytics. Limited events about app and feature usage are sent to OpenPanel with a random installation identifier. They never include list names or item text. They help us understand which features are useful and what to improve. You can turn them off completely in Settings, and the app works the same either way.
Subscription information. To offer My Next: Extra, the app works with RevenueCat, our subscription provider. It sends a randomly generated customer ID and handles your App Store purchase and entitlement status — never your name, your email address, or your card details. This is how Extra unlocks, how restoring a purchase works, and how one Extra subscription activates across Todo, List, and Note. It is required for subscriptions to function, so it is not covered by the analytics switch.
You never need an account or an email address to use My Next: List.
Data storage
Your lists, items, and settings are stored locally on your iPhone using Apple's Core Data framework. This includes any grocery quantity and unit data you enter. If you use the Watch app, the list content and settings needed on your wrist are also stored locally on the paired Watch. Changes synchronize directly between the apps; an offline change waits locally until the devices can communicate again. This synchronization does not upload your list content to a My Next, OpenPanel, or RevenueCat server.
Optional usage analytics
My Next: List sends bounded usage events to OpenPanel. Depending on the event, the payload can include:
- App openings, the app name, cold or warm launch, and language
- App version, analytics schema version, and event timestamp
- Activation milestones, including whether the installation already contained lists and whether a first list or first checked item was recorded
- Daily activity in broad buckets (0, 1, 2–5, or 6 or more) for lists created and items added or checked — not exact totals
- Whether an existing list, cross-app link, export or share, notification, or Apple Watch was used, including whether an item was added or checked on Watch
- Whether a free limit or the Extra screen was reached, and whether Extra was activated through purchase or restore — not a receipt, price, or subscription customer ID
- Backup or restore success, or a broad failure result
- Eligibility for a rating request and whether List asked Apple to consider showing it — not whether you saw, dismissed, or submitted a rating
- A randomly generated installation identifier that links events from the same List installation. It is not derived from your Apple ID, name, email address, or a hardware advertising identifier, but it is a persistent pseudonymous identifier until analytics is turned off.
No list names, item text, quantities, units, linked content, link URLs, names, email addresses, account details, location, advertising identifiers, receipts, prices, or RevenueCat customer IDs are included in these analytics events. Subscription data is handled separately as described below.
Only the iPhone app sends analytics to OpenPanel. Eligible Watch actions can be summarized by the iPhone after synchronization; the Watch app does not contact OpenPanel directly.
These events are used for one purpose: understanding useful app and feature usage so we can improve the app. They are not used for advertising, not used for advertising tracking across other apps or websites, not used to build marketing profiles, and never sold to data brokers.
The app's event payload contains no direct personal identifier. Like any service receiving an internet request, OpenPanel may also process technical request data such as an IP address under its own privacy policy. We do not describe the random installation identifier as impossible to associate with a person.
Turning analytics off
Analytics is a single switch in the app's Settings. Turn it off and it stays off — there is no re-prompt and no expiry.
- No further analytics events are sent.
- Any events still queued on your device waiting to be sent are deleted. The local usage-summary state and installation identifier are also reset.
- Offline Watch actions from the earlier consent period are not added back to analytics if sharing is later turned on again.
Turning analytics off stops future sends, but it does not automatically delete events OpenPanel already received. You may contact us about a deletion request. Associating earlier events with your request may require the installation identifier and may no longer be possible after that identifier has been reset.
To be clear about what the switch does not cover: it turns off the optional OpenPanel analytics only. It does not affect RevenueCat, which handles subscriptions and has to run for Extra to work at all. That is described in the next section.
What we never collect
- No list names or list item content
- No names, email addresses, or account information
- No advertising identifiers or cross-app advertising tracking
- No location data
- No contacts or calendar data
- No payment-card details reach My Next, OpenPanel, or RevenueCat — Apple processes every payment
- No crash reports sent to us (we use on-device logging only)
Subscriptions and My Next: Extra
My Next: List offers its own per-app Extra subscription and Tip Jar, processed by Apple through the App Store. My Next: Extra — a cross-app subscription that activates Extra in Todo, List, and Note — is an additional option.
Subscriptions are handled by RevenueCat, a subscription-management service acting as our data processor. Being straightforward about the timing: RevenueCat starts when the app starts, not only when you buy something. The app needs it running to load the current offerings and to check whether you already have Extra, so this applies to everyone who opens the app — not only to subscribers.
What the app sends to RevenueCat:
- A randomly generated My Next customer ID. It contains no name, no email address, no account ID, and no other direct personal identifier — it is pseudonymous, which means it identifies a subscription rather than a named person.
The ID is generated on your device the first time it is needed and kept in a shared keychain entry that Todo, List, and Note can all read. That shared entry is the entire mechanism behind “one subscription, three apps” — it is why Extra works everywhere without you ever creating an account.
What RevenueCat processes on our behalf:
- Your purchase and subscription history, as reported by Apple
- Which products and entitlements are active
- Related subscription information received from Apple
What it is used for:
- Validating App Store receipts
- Preventing fraud
- Unlocking and enabling Extra features
- Restoring access to a purchase you already made
- Sharing one Extra entitlement across the My Next app family, so a single subscription works in Todo, List, and Note
- Subscription analytics — how many subscriptions renew or lapse
RevenueCat never receives your payment-card information. Apple processes all payments, and card details never pass through the app. None of this data is used for advertising or for tracking you across other companies' apps and websites.
Because Extra cannot work without it, RevenueCat is not covered by the analytics switch in Settings. The switch governs the optional OpenPanel analytics only. See RevenueCat's privacy policy for details.
Data export and deletion
You can export your data at any time from within the app. Deleting List from one device removes that app container's local list data; it does not necessarily remove a copy still stored by the List app on the other paired device. Delete the app from both iPhone and Apple Watch if you want both app containers removed. Deletions made inside List synchronize when the devices can communicate, so an offline paired device may temporarily retain its earlier local copy.
Exported backups remain wherever you saved or shared them until you delete those files. Deleting the app also does not erase analytics already received by OpenPanel or purchase and entitlement records held by Apple and RevenueCat under their applicable retention rules. We do not keep a separate server backup of your list content and cannot recover it for you.
The My Next customer ID is stored separately in Apple Keychain so it can be shared with Todo and Note. That keychain entry may remain available to another My Next app or after reinstalling List even when List's local list database has been removed.
Worth knowing before you share a backup file: if you have My Next: Extra, the backup also carries your My Next customer ID. That is deliberate — it is how Extra follows you to a replacement phone when you restore a backup, without you needing an account. It does mean a backup file is a private document. Anyone you hand it to receives both your content and a handle that could unlock Extra, so treat it the way you would treat any personal file.
Third-party services
My Next: List uses no advertising services and no cross-app tracking services. The external services involved are:
- OpenPanel — the analytics processor that receives the optional usage events described above. Nothing you write in the app is included in those event payloads. OpenPanel may process ordinary request metadata under its own policy. The events are not used by us for advertising or sold on. See OpenPanel's privacy policy for details.
- RevenueCat — our subscription data processor. It receives a randomly generated My Next customer ID plus the purchase and entitlement information Apple reports, and uses it for receipt validation, fraud prevention, unlocking and restoring Extra, sharing Extra across the My Next apps, and subscription analytics. It starts with the app rather than only at purchase time, receives no card details, and is never used for advertising or cross-company tracking. It is required for subscriptions and is not covered by the analytics switch. See RevenueCat's privacy policy for details.
- Apple App Store — processes all purchases and subscription transactions, including all payment details.
- Apple Keychain — stores the My Next customer ID in a shared keychain group on your own device, so Todo, List, and Note recognise the same Extra subscription. The ID is sent to RevenueCat as described above and can also be included in a backup you choose to export.
Future changes
The current iPhone–Apple Watch synchronization is local to the paired apps and is described above. If we introduce internet or cloud sync in the future, it will be opt-in. We will update this policy before introducing such a feature.
Contact
If you have questions about this privacy policy, contact us at [email protected].