Your documents stay yours.
- All data is stored on your device and in your own private iCloud database
- We have no servers. Your documents never touch our infrastructure
- No analytics, no tracking, no advertising — ever
- Scans are processed entirely on-device. No cloud OCR
- Face ID is handled by iOS. We never see your biometric data
What Ledger stores
Ledger stores the information you provide when adding documents:
- Document scans (stored as encrypted PDF files)
- Extracted fields — document type, number, issuing authority, issue and expiry dates
- Family member names and relationships you enter
- App preferences such as lock timeout duration
Where your data lives
On your device: Document scans and metadata are stored in the app's sandboxed container, protected by iOS file encryption (NSFileProtectionCompleteUnlessOpen). The app requires Face ID or passcode authentication to open.
In iCloud: If you are signed into iCloud, Ledger syncs your data across your devices using CloudKit's private database. This database is tied to your Apple ID and is completely isolated — no other app or person can access it. We strongly recommend enabling Advanced Data Protection in your iPhone's iCloud settings, which upgrades iCloud encryption to end-to-end, meaning even Apple cannot access your data.
Nowhere else: Ledger has no backend servers, no developer-operated database, and no cloud processing pipeline. Your documents never leave the Apple ecosystem.
Document scanning and extraction
When you scan a document, Ledger uses Apple's Vision framework to extract text and data directly on your device. No image or text is sent to any external server for processing. The camera feed is used only during the moment of scanning and is never saved to your photo library unless you explicitly choose to do so.
Notifications
Ledger schedules local notifications to remind you when documents are approaching their expiry dates. These notifications are generated on-device using the dates you have entered. They are not sent through any external push notification service.
What we do not collect
- We collect no analytics or usage data
- We use no third-party advertising SDKs
- We do not track you across apps or websites
- We do not sell, share, or license any of your data
- We have no account system and no login — there is nothing to breach on our end
Third-party services
Ledger relies on the following Apple platform services, each governed by Apple's own privacy policy:
- CloudKit — private database sync across your devices
- Face ID / Touch ID — local biometric authentication via the Secure Enclave; biometric data never leaves your device
- UserNotifications — local expiry reminders
No other third-party SDKs, analytics services, or crash reporting tools are included in the app.
Children's privacy
Ledger is not directed at children under 13 and we do not knowingly collect personal information from children. Because all data is stored locally and in the user's own iCloud account, there is no mechanism by which we could collect such information.
Your rights
Because your data never reaches our servers, you have complete control over it at all times:
- Access and export: Use the Export feature in Settings to download all your documents as PDFs
- Deletion: Delete individual documents or your entire vault within the app. Deleting the app removes all on-device data. To remove iCloud data, delete the app and then go to Settings → [Your Name] → iCloud → Manage Account Storage → Ledger → Delete Data
- Portability: Exported PDFs are standard files you can open with any PDF reader
Changes to this policy
If we make material changes to this privacy policy, we will update the effective date at the top of this page. Because Ledger collects no contact information, we cannot notify you directly — please check this page periodically if you have concerns.
Contact
Questions or concerns about this privacy policy? Reach out directly:
Ravi — Ledger developer