1. Scope and summary
This Privacy Policy applies to the Android app PickQueue, package ID com.schukai.pickqueue. The app manages shopping lists without a user account and remains usable for local lists without the sync service.
If you enable optional sync, client-side encrypted list events, selected encrypted images for that list, and necessary technical metadata leave the device. The sync relay receives no list keys and cannot decrypt list or image content.
Effective: 5 September 2026
2. Controller and privacy contact
Ingrid Schukai & Volker Schukai GbR
Eichenstraße 26
82290 Landsberied
Germany
Email: hey@schukai.com
Further provider details are available in the German-language legal notice.
3. Data on the device
Depending on how you use it, PickQueue stores list names, products, quantities, units, notes, shops, favorites, supplies, workflow states, history, local display names, your own product or shop images, and sharing and device configuration.
The data are held in a local app database and private app files. List and sharing keys are kept in protected device storage. Android system backups for the app are disabled. Images for a local-only list remain on the device. Images selected for a synchronized list are encrypted on the device before transfer.
4. Optional end-to-end encrypted sync
For shared lists, the app transfers authenticated encrypted events by HTTPS to pick-queue-sync.schukai.com. The relay stores ciphertext, random list and capability IDs, digests of high-entropy access tokens, access levels, pseudonymous device and operation IDs, revisions, server times, format and size information, and technically visible access volume.
List names, products, quantities, notes, shops, images, display names and list keys must never reach the relay in plaintext. Network operation and abuse protection also process technically necessary connection data such as IP address, time, requested API path, response status and transfer volume.
When pairing devices, the relay additionally processes random invitation and pairing data, hashes, a recipient public key, cryptographic proofs and an encrypted handoff envelope for no more than 15 minutes. Expired pairings are physically removed on a regular schedule.
5. Camera, photos and speech recognition
After you grant permission, the camera is used to read QR invitations, keys or product codes and to take deliberately selected pictures. Images for a local-only list remain on the device. Selected images for a synchronized list may be transferred to the PickQueue relay after client-side encryption.
Speech input uses the recognition service configured on the Android device. Whether speech is processed locally or additionally by that service's provider depends on the device and selected service. Audio is not routed through the PickQueue relay; the app receives recognized text and shows it for confirmation before it is added to a list.
6. Google Play Billing and Sync subscription
On Android, an optional PickQueue Sync subscription can be purchased, restored and managed through Google Play. Google processes the purchase through the Google Account and payment method held by Google. PickQueue receives no card, bank-account or other payment-instrument details.
To provide the subscription, PickQueue processes the product and base plan, purchase state and time, entitlement period, and a purchase token generated by Google. The app sends the purchase token by encrypted HTTPS to the PickQueue entitlement service. The service verifies and acknowledges the purchase through the Google Play Developer API and stores the token in encrypted form and as a cryptographic digest, together with the resulting subscription and entitlement state. Google may send state changes to the service through Real-time Developer Notifications.
Purchase data are not combined with list content; the sync relay receives only a random household entitlement. Local lists, export and deletion remain available independently of the subscription.
7. No accounts, advertising or first-party usage analytics
PickQueue creates no user account and contains no advertising, advertising-ID processing, or first-party client analytics or crash-reporting SDK. The purchase and subscription data described in section 6 remain unaffected. The ML Kit GenAI feature present in the source tree is not included in the Android build currently released to the public.
Sync operations use protected aggregate operating metrics without list content, purchase tokens, or individual list, device or operation IDs.
8. Retention, backups and deletion
Local lists remain until you delete them in the app, clear the app's Android data or uninstall the app. Deleting a local-only list removes all related local content.
For a synchronized list, a device with administrative capability can delete the list, its capabilities and encrypted events transactionally from the relay. A device without that capability removes its local copy while other devices and the relay retain the list. Active encrypted events otherwise remain available so that devices that have been offline for longer can synchronize again.
Encrypted relay backups are currently retained for up to 56 days. A list deleted from the live relay may therefore remain as ciphertext with technical metadata in protected backups until backup rotation expires. schukai cannot read its shopping-list content without an authorized client key.
9. Rights, security and requests
Applicable data-protection rights may include access, correction, deletion, restriction, portability, objection and the right to complain to a supervisory authority.
Because PickQueue operates no user account and the relay cannot decrypt shopping-list content, list-deletion requests generally need to be carried out through an authorized device and the relevant list. Questions about technical relay metadata or privacy can be sent to hey@schukai.com.
PickQueue is a household and shopping app and is not directed specifically at children.
10. Changes
We update this policy if PickQueue's sync operation, retention, integrated services or data processing change. The effective date above identifies the current version.