TOTEKI PRIVACY POLICY Effective August 22, 2026 SUMMARY ToteKi uses personal information only to provide private shopping-list coordination. ToteKi does not sell personal information, serve advertising, or track people across apps and websites. INFORMATION TOTEKI COLLECTS - Account information: username, nickname, email address, authentication identifier, friend code, profile color, and the sign-in provider you choose. ToteKi profiles do not ask for or store separate first-name or last-name fields. If you use Sign in with Apple or Google, the provider and Supabase may process basic account metadata during authentication. ToteKi uses your provider email and account identifier, then asks you to choose a username and nickname instead of importing a provider name into your ToteKi profile. - Shopping content: list titles, items, quantities, units, notes, optional item images, confirmed receipt prices, receipt tax, split assignments, calculated amounts owed, item status, questions, answers, and related activity history. Receipt images and raw recognized text are processed only on the device for matching and are not uploaded or retained by ToteKi. - Connections: friend requests, friendships, shared-list participation, and the people authorized to collaborate on a list. - Subscription information: the ToteKi Pro product, App Store transaction identifiers, expiration status, and verification time. Apple processes payment details; ToteKi does not receive full payment-card information. - Notification information: if you allow notifications, ToteKi stores the APNs device token and push environment associated with your account. Push payloads use generic alert text and do not include item names or question text. - Local session information and the tutorial-completion preference stored on the device. - Lists and optional item images created in Offline Mode. This content remains only on that device and separate from any ToteKi account. - Service data: Supabase may process network and diagnostic information needed to authenticate requests, secure the service, and operate the hosted database. - Support correspondence: if you contact support, ToteKi receives your account email address, Supabase user identifier, a request identifier, and the message content you submit in the app. HOW INFORMATION IS USED ToteKi uses this information to create and secure accounts, verify and provide ToteKi Pro features, send password-reset emails, match receipt prices and detect tax on the device, synchronize confirmed prices and lists, calculate shared-list amounts owed, support friend and sharing features, deliver item questions, answers, and optional question notifications, preserve in-app mailbox history, restore sessions, prevent unauthorized access, and respond to operational failures. Question notifications contain only generic alert text and authorized list/item routing identifiers; they do not contain item names, question or answer text, list titles, email addresses, or friend codes. ToteKi does not collect or transfer payment between participants. Support correspondence is used to investigate your request and reply to you. SHARING AND SERVICE PROVIDERS People you choose to connect with or share a list with can receive the profile and shopping information needed for collaboration. Depending on the relationship, this can include your username, nickname, friend code, avatar color, shared-list content, optional item images, question-and-answer history, split assignments, receipt tax, and calculated amounts owed. Your email address is used for your account and is not disclosed to friends or list collaborators. ToteKi uses Supabase for authentication, database storage, synchronization, server functions, device-token storage, and notification delivery orchestration. Supabase processes information as a service provider under its contractual and privacy obligations. If you choose provider sign-in, Apple or Google and Supabase process that authentication according to your provider choices. ToteKi uses the provider email and account identifier for account access and does not copy a provider first or last name into your ToteKi profile. Apple separately processes subscriptions and supplies verified transaction information used to provide Pro access. Apple also processes APNs device tokens, generic notification content, and delivery information to deliver notifications you permit. Resend processes your account email, Supabase user identifier, request identifier, and support message to deliver your request to ToteKi Support. ToteKi requires every service provider that receives user data to provide the same or equivalent protection described in this policy and required by applicable law. ToteKi does not share data with advertising networks or data brokers. Supabase privacy policy: https://supabase.com/privacy RETENTION AND DELETION Account, subscription entitlement, and shopping information, including optional item images, is retained while an account is active so lists and collaboration history remain available. Item images are removed when their item, list, or owning account is deleted. Device tokens are removed when you sign out from that device, delete your account, or APNs reports that the token is no longer valid. Offline Mode lists remain on the device until they are deleted individually or the app is removed. You can permanently delete your account from Profile > Account Settings > Delete Account. Deletion removes the account and associated active data. Limited encrypted backups and security records may remain temporarily under the service provider's retention practices or where required by law. LEGAL BASIS AND INTERNATIONAL TRANSFERS Where a legal basis is required, ToteKi processes account, subscription, and shopping information as necessary to provide the service you request and perform its agreement with you. ToteKi processes optional notifications and device access based on your choices or consent. Security, abuse prevention, service reliability, and support are processed as necessary for ToteKi's legitimate interests, subject to your rights, and information may also be processed to comply with legal obligations. Supabase, Apple, Google, and Resend may process information in countries outside your own, including the United States. Where required, ToteKi and its providers rely on legally recognized transfer safeguards, such as applicable adequacy decisions or contractual protections. YOUR RIGHTS AND CHOICES You control which friends are accepted and which lists are shared. You can allow or deny notifications in the iPhone system prompt and later change that choice in iOS Settings. You can remove friends, stop sharing lists, sign out, delete your account, or delete device-local Offline Mode lists individually. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information; restrict or object to processing; withdraw consent; and complain to your local data-protection authority. Withdrawing consent does not affect processing already performed. Contact ton2apps.dev@gmail.com to exercise a right that is not available directly in the app. Deleting your account is the in-app method for requesting deletion of account data. ToteKi does not use personal information for automated decisions that produce legal or similarly significant effects. Receipt matching suggestions can always be reviewed and corrected before prices are saved. SECURITY ToteKi uses encrypted HTTPS connections, authenticated server requests, and database access policies designed to restrict data to authorized participants. No method of storage or transmission can guarantee absolute security. CHILDREN ToteKi is not directed to children under 13 and does not knowingly collect personal information from children under 13. POLICY CHANGES AND CONTACT This policy may be updated as ToteKi changes. The effective date above identifies the current version. The developer identified as ToteKi's seller on the App Store is the controller responsible for ToteKi's processing of personal information. For privacy questions, support requests, or requests that cannot be completed in the app, email ton2apps.dev@gmail.com or visit: https://kqqrxbznokugwxafnbft.supabase.co/functions/v1/support