the fine print, minus the fine print

Your grocery run is your business.

Wiggle has no accounts, no ads and no analytics. A solo run never leaves your phone. The one time anything goes online is co-op, when two phones share a run, and even then it's anonymous and deleted within a day.

Effective October 7, 2026 Android & iOS Developer: Jan Aguja

The short version

if you only read one thing, read this

Everything lives on your phone

Budgets, entries, run history, streaks and settings are stored in a local database on your device. We have no copy, because there's nowhere for one to go.

Co-op is the one exception

Hosting or joining a shared run puts that run's prices and categories in Google Firebase under a random, anonymous ID. No name, no email, no item names. Each session expires 24 hours after it starts.

Nothing is watching

No ad networks, no analytics, no crash-reporting SDKs, and no permissions for your camera, contacts, photos, location or microphone.

Pro is a one-time purchase

The App Store or Google Play handles payment. The app only learns whether Pro is unlocked, never your card.

Where does it go?

tap a piece of data and follow it

Every piece of information Wiggle touches ends up in one of four places. Pick one to see where it lives and how long it stays.

Lane 1
📱 Your phone

Local database and preferences. Never uploaded.

Lane 2
☁️ Co-op session

Google Firebase, anonymous, expires in 24 hours.

Lane 3
🏪 App store

Apple or Google handles it. We never see it.

Lane 4
🚫 Nowhere

Wiggle never collects it at all.

  • Your budget and grocery entries → Your phone. Price, quantity, category and time for every item you log during a solo run, saved in a local database on your phone. Kept until you delete the run or uninstall the app.
  • Run history, streaks and win rate → Your phone. Calculated and stored on your phone. Nobody else sees your win/loss record unless you show them. Kept until you delete runs or uninstall.
  • Your settings → Your phone. Currency, tax rate, keypad handedness, keep-screen-awake and similar preferences, saved in local preferences. Kept until you uninstall or clear app data.
  • Exported backups → Your phone. Export builds the file on your phone and hands it to your share sheet. It goes wherever you send it, and nowhere else. Lives wherever you save it.
  • A shared co-op run → Co-op session. Budget, currency, tax rate, and each entry’s price, quantity and category, in one Firestore document keyed by your join code. No item names, notes or personal details. Expires 24 hours after the session starts, then deleted automatically.
  • Anonymous co-op ID → Co-op session. A random ID created by Firebase only when you host or join co-op, so security rules can tell two phones apart. Nothing is attached to it. Only used while you co-op. Solo play never creates one.
  • Payment for Wiggle Pro → App store. Handled entirely by the App Store or Google Play. Wiggle only learns “Pro: yes or no”. Governed by Apple’s or Google’s own policy.
  • Your name, email or phone number → Nowhere. Never asked for, never collected. There is no sign-up. Not applicable: we never have it.
  • Your location → Nowhere. Wiggle doesn’t know which store you’re in, and has no location permission. Not applicable: we never have it.
  • Usage analytics and tracking → Nowhere. No analytics SDK, no ad network, no crash reporter. We don’t know how often you open the app. Not applicable: we never have it.

The full policy

same story, every detail

01Who we are

Wiggle ("the app") is a grocery budget app for Android and iOS, developed and published by Jan Aguja, an independent developer in the Philippines ("we", "us"). This policy explains what information the app handles, where it goes, and how long it stays there.

02What we collect

Nothing that identifies you. There's no sign-up, and nothing in the app asks who you are.

Wiggle does not require an account, sign-in, email address, phone number, or any other personal detail. We do not knowingly collect information that identifies you personally.

The one exception is technical: when you tap Host Session or Join Session to use co-op mode, the app creates an anonymous identity through Firebase Authentication's Anonymous Sign-In. It is a randomly generated ID with no name, email, password or other detail attached. Its only job is letting the co-op service's security rules tell one phone apart from another. Solo play never creates this ID and never contacts any server.

03What stays on your device

This is almost everything, and it stays put.

The following is stored in a local database and local preferences store on your device, and is never sent to us or anyone else:

  • Your budgets and grocery entries (price, quantity, category and time logged)
  • Your run history, streak and win-rate stats
  • Your settings, such as currency, tax rate, keypad handedness and keep-screen-awake
  • Whether Wiggle Pro is unlocked

If you join a friend's co-op run and choose Add to my history when it ends, a copy of that run is saved to this same local database. Nothing extra is sent anywhere to do so.

Export and import. Export in Settings creates a backup file and hands it to your device's share sheet; it goes only where you choose to send or save it. Import reads a backup file you pick with your device's file picker. The app does not upload either file.

04Co-op sessions

Two phones, one run, one temporary document. Gone within a day.

Co-op lets two phones share one live grocery run. Starting a session creates a single document in Google's Cloud Firestore, identified by a six-character join code. While the session is running it contains only:

budget amountcurrencytax rate (optional) each entry's priceeach entry's quantityeach entry's category when each entry was loggedanonymous device IDstart / end time removed entry IDs

It does not contain:

your nameemailitem names notes or photoslocationcontacts

Anyone with the join code can open the session while it's live, so only share the code with the person you're shopping with.

Every session is set to expire 24 hours after it's created, finished or not. Expired sessions are deleted by the app itself: whenever anyone hosts or joins a session, the app removes sessions that have expired. In practice they're gone soon after expiring, though during quiet periods it can take a little longer. If a session ends or the connection drops, the rest of Wiggle keeps working normally.

05Third-party services

Google Firebase for co-op, and nothing else.

Co-op is built on Google Firebase: Firebase Authentication (Anonymous Sign-In), Cloud Firestore, and Firebase App Check. App Check helps confirm that co-op requests come from the genuine Wiggle app, using your device's built-in attestation service (App Attest or DeviceCheck on iPhone, Play Integrity on Android). Whether these checks are enforced or only monitored may change over time. They confirm the app and device are genuine; they don't give us personal information.

These services are only contacted while you're actively using co-op. Google processes the infrastructure-level data involved (such as IP addresses needed to deliver network requests) under its own privacy policy.

Wiggle includes no advertising networks, analytics SDKs or crash-reporting SDKs of any kind. We do not sell, rent or share your information with anyone.

06Purchases

Wiggle Pro is a one-time purchase made through the Apple App Store or Google Play. The store handles the payment entirely under its own terms and privacy policy. We never see or store your payment details; the app only learns whether Pro is unlocked so it can turn the Pro features on.

07Permissions

  • Network access, used only to sync a co-op session and to notice when your connection drops or returns so the app can retry. Not used during solo play.
  • Keep screen awake, optional, so you aren't unlocking your phone at every shelf. It only controls the screen's sleep timer.
  • In-app billing (Android), so Google Play can handle the Pro purchase.

Wiggle does not request access to your camera, photo library, contacts, location or microphone.

08Retention & deletion

You're in control of the local data. The cloud data cleans itself up.

Local data stays on your device until you remove it. The History screen lets you delete individual runs, and uninstalling the app or clearing its data in your device's settings removes everything. There is no account and no server-side copy of your solo runs, so there's nothing for us to keep or for you to request deletion of.

Co-op session data expires 24 hours after creation and is then deleted automatically as described in section 4. If you have a concern about a specific session, email us and we'll help.

09Your rights

Depending on where you live, including under the Philippine Data Privacy Act of 2012, the GDPR or similar laws, you may have the right to access, correct or delete personal data held about you. Because Wiggle doesn't hold personal data on any server, the simplest way to exercise these rights is on your own device. For anything else, contact us and we'll respond.

10Children's privacy

Wiggle is not directed at children under 13. We do not knowingly collect personal information from children, and as described above, the app doesn't knowingly collect personal information from anyone.

11Changes to this policy

If this policy changes, the updated version will be posted at this address with a new effective date. If a change meaningfully affects what data leaves your device, we'll say so in the app's release notes. Continued use of the app after a change means you accept the updated policy.

12Contact

Questions about privacy? Email [email protected]. It goes straight to Jan.