Legal

Privacy Policy

Last updated: September 2026

The short version

Privvy Ledger keeps your financial data on your device. Nothing leaves it unless you explicitly ask it to. There is no account, no cloud sync, and no server of ours your data could be sent to — and no ads, tracking or usage analytics anywhere in the app. The one exception is honest: anonymous, fully masked crash reports, so bugs get fixed. Never your numbers.

What we store

All data you enter — transactions, categories, budgets and recurring rules — is stored exclusively in a SQLite database inside this app's private storage on your device, protected by your operating system's app sandbox and device-level disk encryption. Your PIN is never stored in that database, or anywhere in readable form: only a salted hash of it is kept in the system keystore (Android Keystore / iOS Keychain). Your financial data never leaves your device unless you explicitly export it.

What we do not collect

  • —No personal information (name, email, location)
  • —No financial data — your transactions, balances, budgets and categories are never transmitted anywhere
  • —No advertising identifiers, and no advertising or attribution SDKs
  • —No product or usage analytics — we do not track which screens you open or what you do in the app
  • —No financial account credentials, and no bank or card connections
  • —No account, and no server of ours for your data to be sent to

Crash reporting

So that bugs get found and fixed, Privvy Ledger sends anonymous crash and error reports to Sentry (sentry.io), a third-party diagnostics service. These reports contain technical information — the error itself, a stack trace, your device model and OS version, and the app version. They are configured not to attach personal information such as your IP address, and there is no account or identifier tying a report to you. A small sample of sessions also records a fully masked wireframe of the interface to help diagnose crashes: all text, images and graphics are masked out before the recording leaves your device, so amounts, categories and notes are never visible. No transaction data, balance, budget, PIN or receipt content is ever included in a crash report. This is the only data Privvy Ledger sends off your device, and it is declared in the app's Google Play Data safety section.

Exchange rates

If you record transactions in more than one currency, Privvy Ledger downloads the day's exchange rates so it can add them up in your default currency. It does this at most once a day. It never does it if all your transactions are in one currency, or if you have set your own rate for every other currency. The request goes to ExchangeRate-API (exchangerate-api.com), or to a public rates dataset served by jsDelivr (jsdelivr.com) if that is unavailable. It is the same fixed request for every user and contains none of your data: no transactions, no amounts, not even which currencies you use. As with any internet request, those services can see your device's IP address and when the request was made. Rates you enter yourself stay on your device.

Third-party SDKs

Privvy Ledger includes no advertising, attribution or product-analytics SDKs. Three third-party components are present: Sentry, for the anonymous crash reporting described above; Google ML Kit text recognition, which reads receipt text entirely on your device and sends nothing to Google; and the Expo runtime, which may check Expo's servers for over-the-air update manifests. No user data is included in those update requests.

Biometric data

When you enable biometric unlock (fingerprint or Face ID), authentication is handled entirely by your device's secure enclave via the operating system API. Privvy Ledger never has access to your biometric data — only the OS result (success / failure) is returned to the app.

On-device receipt scanning

When you scan a receipt, a quantized language model runs locally on your device to extract amounts and categories. Receipt images and extracted text are never uploaded or sent to any server.

Data export and backups

You can export your data at any time from Settings. Reports export as plain, unencrypted CSV or PDF files. Full backups export as a .plbackup file encrypted with AES-256-GCM, using a key derived from a password you choose (PBKDF2) — without that password the file cannot be read by anyone, including us. In both cases the file is saved to a location you pick, and we have no visibility into it afterwards. If you turn on automatic backup, Privvy also saves an encrypted .plbackup file to a folder you choose, each time you open the app after making changes, keeping the three most recent days. That folder may be one your own cloud storage app syncs; Privvy sends nothing anywhere itself. The key for these files is derived from a password you set and is kept in your device's secure keystore; the password itself is not stored. Because there is no server-side copy, a forgotten backup password cannot be recovered.

Data deletion

All data is deleted permanently when you use Settings → Erase all data, or when you uninstall the app. There is no server-side copy to request deletion of.

Children's privacy

Privvy Ledger is not directed at children under 13. We do not knowingly collect any data from anyone, including children.

Changes to this policy

If this policy changes materially (e.g. a cloud sync feature is added), we will update the "Last updated" date and note the change in the app's release notes.

Contact

Questions or concerns? Reach us at [email protected] or via the contact form at stephenadeniji.com.

Back to site