How are you sure it's only your grocery list? You trust the networks and states that the content is transferred through to not inject anything potentially malicious or otherwise undesirable into the content? The only way you can be relatively confident that's not happening if the content is delivered via HTTPS, surely.
Right now it's just your grocery list. In the future when it's sucked up into the algorithms used by the underwriters of your health insurance and life insurance, and you can't quite figure out why you aren't getting the healthy-eating-disguised-with-some-ambiguous-name discount, maybe your grocery selection is to blame.
> I assume you are hinting at app operator will sell user’s data? Or do you mean parent’s network provider does?
Yes and yes. ISPs are racing as we speak to develop the technology to data mine their users and inject their own ads. Hopefully we will get the web encrypted fast enough to make it less economically attractive.
They want to know which sites you visit, what you search for, which movies you watch and what you shop for, and package it and sell it to anyone who will pay.
Individual developers could do the same, and we should find ways to prevent that, but they have less negotiating and lobbying power and users have more choice in what apps to use.
I'm one of those people. The grocery list app I use doesn't use SSL and I don't really care because it's just my grocery list lol.