← mishlist
MishList Privacy Policy Effective: July 28, 2026 MishList ("the app") is made by Nipun Khanna, in British Columbia, Canada. Questions about this policy: [email protected] The short version: your lists live in YOUR iCloud, we run no accounts, and the only things that reach our server are what you type into search or capture, and what you explicitly choose to publish. What the app stores - Your lists, places, notes, ratings, photos, companions, and visit dates are stored on your device and in your personal iCloud (Apple CloudKit), under your Apple ID. We cannot read them and we keep no copy. - Your display name and handle are stored on your device. They appear on pages you publish, and beside places you add to a shared list. iCloud sharing - If you share a list with someone, Apple's CloudKit sharing controls access. Either side can stop sharing at any time. We never see the data. Location - With your permission, the app uses your location "While Using the App" to show where you are on the map, to suggest the right list when you save a place, and to fetch local weather. - Your location is never tracked in the background, and it is never sent to our server. - You can refuse or revoke this any time in iOS Settings. The app still works without it. Weather - Weather comes from Apple Weather (WeatherKit). To return a local forecast, Apple receives the location the app is asking about. Apple's handling is described in Apple's privacy policy and at weatherkit.apple.com/legal-attribution.html. What our server receives - Search: the words you type when searching the place catalog, so we can return matching places. Searches are not tied to any identity. - Smart Capture: the text you paste is sent to our server and forwarded to OpenAI, which extracts the place details from it. This content is not used to identify you, and our server does not store it after returning the result. OpenAI's handling is described at openai.com/policies. - Publish a list: the app sends that list's snapshot — list name, description, place names, locations, categories, tags, notes, ratings, and visit dates, plus your display name and handle — to our server so a public web page can exist at mishlist.ca/@handle/list-name. Anyone with the link can view it. You can unpublish at any time. - Standard web server logs (IP address, user agent, path), kept briefly to operate and secure the service. Share pages count views as an anonymous number. What we do NOT do - No accounts, no passwords, no email collection. - No advertising, no trackers, no analytics SDKs, no selling of data — ever. - No background location tracking, and no profile built about you. Sign in with Apple - Optional. If you use it, the identifier Apple gives us and your name are stored on your device only, so your name can appear beside places you add to shared lists. It is not required for the app, for syncing, or for sharing. Data catalog - The app suggests places from a Vancouver catalog built from Overture Maps (CDLA-Permissive-2.0), OpenStreetMap (© OpenStreetMap contributors, ODbL), City of Vancouver Open Data (OGL), and our own curation. This is editorial content about places — not data about you. Your choices - Delete the app: on-device data is removed. iCloud data: Settings → Apple ID → iCloud → Manage Storage → MishList → delete. - Unpublish a share page: from the app, or email us with the link. - Turn location off any time in iOS Settings. Children MishList is not directed at children under 13. Changes We'll update this page and the effective date when anything changes materially. Contact [email protected]