← Ledger
Privacy Policy
Last updated: 8 June 2026
Ledger is a private, offline-first personal finance tracker. This policy explains what data the app handles and how.
The short version
- Your financial data lives on your device. The app works fully offline.
- If you create an account, your data can sync across your devices. That synced copy is end-to-end encrypted: encrypted on your device before upload, and we cannot read it.
- We do not sell your data, show ads, or run third-party tracking or analytics.
What we collect
On your device (not sent to us): your accounts, buckets, transactions, recurring rules, and settings, in local storage on your device.
If you create an account (optional, for sync):
- Account identity: your email address and authentication metadata, handled by our auth provider (Supabase). If you sign in with Google, Google shares your email and basic profile per your consent.
- Encrypted backup: one encrypted snapshot of your ledger, encrypted on your device with a key derived from a sync passphrase only you know. We store only ciphertext plus the non-secret parameters needed to decrypt it on your device. We cannot decrypt it.
We do not collect analytics, advertising identifiers, location, contacts, or device fingerprints.
How we use data
To authenticate you and sync your encrypted backup between your own devices. That's it. No profiling, no selling, no advertising.
Where data is stored
- On device: local database, behind your device biometric lock.
- Cloud (only if you enable sync): Supabase (Postgres, auth, storage), with encrypted snapshots isolated per user by row-level security. Web hosting by Vercel. These providers process data as sub-processors.
End-to-end encryption and your responsibility
Your synced data is encrypted with a passphrase only you hold, plus a recovery key shown once at setup. If you lose both, your synced data cannot be recovered by anyone, including us. This is the cost of zero-knowledge privacy.
Your choices and rights
- Use without an account: fully usable offline with no account.
- Delete your cloud data: Settings → Account → Delete cloud data.
- Delete your account: contact us to remove your account and server-side records.
- Export: export your full data as JSON or CSV from Settings anytime.
Children
Ledger is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data.
Changes
We may update this policy. Material changes will be noted in the app or here with a new "last updated" date.
Contact
syed.sarib@imagine.art · Governing region: Pakistan.