Privacy Policy
RentalLedger helps you record income and expenses for the properties you rent out and keep receipts as evidence. Your ledger is stored on your phone. The one feature that sends anything off your device is the optional receipt import, and this policy explains exactly what that sends and where.
Summary
- Your properties, income, expenses, and receipt files are stored only on your device, in an encrypted database.
- There are no accounts. The app identifies your installation to our server with a random ID, not with your name, email, or phone number.
- When you choose to import a receipt with AI (a Plus feature), that receipt is sent to our server and passed to our AI provider for that one scan. It is not stored on our server.
- The app contains no analytics, advertising, or crash-reporting services.
- Deleting a record in the app removes it. Deleting the app removes everything on the device.
Information the app handles
| Information | Where it lives | Why |
|---|---|---|
| Properties: the name, address, and notes you enter | Your device only | To group records by property |
| Expenses and income: amounts, dates, categories, payer or vendor, notes, and status | Your device only | To keep your ledger and build the tax-year summary |
| Recurring income templates and the months you skipped | Your device only | To propose each month’s rent for you to confirm |
| Receipt photos, PDFs, and pasted text you attach as evidence | Your device only, in the app’s private storage | To keep proof next to each expense |
| Settings and whether Plus is active | Your device only | To run the app the way you set it |
| A random installation ID and a secret the app generates | Your device’s keychain, and our server | To tell our server which installation is asking, without an account |
| How many AI imports this installation used this month | Our server | To apply the monthly import limit of your plan |
We do not collect your name, email address, phone number, contacts, location, or advertising identifiers. We never see your ledger.
Receipt import with AI
Receipt import is available on the Plus plan and runs only when you tap to import a receipt. For that one request the app sends to our server:
- the receipt image, PDF, or text you chose;
- the list of expense categories the app uses; and
- the names of your properties, so the result can suggest which property the receipt belongs to.
Our server, which runs on Cloudflare, forwards this to our AI provider, Anthropic, and returns the suggested amount, date, vendor, category, and property to your phone for you to review. Our server does not store the receipt, the names, or the result. It records only that a request happened: the installation ID, the route, how long it took, whether it failed, and the number of tokens the AI processed. Anthropic processes the request under its commercial terms, which do not allow it to use the data to train its models; see Anthropic’s commercial terms and privacy policy. Nothing is saved until you confirm the result in the app, and you can edit every field first.
If you never use receipt import, no receipt, name, or record ever leaves your device.
Device permissions
- Camera: used only when you choose to photograph a receipt.
- Photo Library: used only when you choose a photo as evidence. Photos you attach are copied into the app’s private storage. The app does not browse your library.
- Files: used only when you choose a PDF as evidence or choose a backup file to restore.
Purchases
RentalLedger Plus is sold through Apple’s App Store. Apple handles payment under Apple’s privacy policy; we never receive your payment details. Purchases are managed with RevenueCat, which receives the purchase information from Apple together with the app’s random installation ID, so that Plus can be recognized on this installation and restored on a new phone. Our server asks RevenueCat whether an installation has Plus. See RevenueCat’s privacy policy.
Backups
On Plus, you can create a backup file that contains every record and receipt. The file is encrypted with a passphrase you choose, and the app hands it to the iOS share sheet. Where it goes from there, such as Files, iCloud Drive, or Google Drive, is your choice and is governed by that service’s privacy policy. We never receive the file or the passphrase, and cannot recover a forgotten passphrase.
Storage and security
Your ledger is kept in an encrypted database (SQLCipher) inside the app’s private container, with the encryption key held in the device keychain. Receipt files sit in the same private container, protected by the device’s encryption and passcode. Your iCloud or computer backup of the device may include the app’s data, under Apple’s policies. Requests to our server use HTTPS. We recommend keeping a device passcode enabled.
Your choices and deletion
- Edit or delete any property, expense, income entry, template, or receipt in the app at any time.
- Deleting the app removes the database, receipt files, and keychain entries from the device.
- The record our server keeps for an installation contains no personal information: a random ID, a hashed secret, the platform, the plan, and monthly import counts. If you would like it removed, email us and we will work with you to identify and delete it.
Because we hold no copy of your ledger, there is nothing for us to access, correct, or export on your behalf.
Children
RentalLedger is not directed at children under 13, and we do not knowingly collect information from them.
Changes
If this policy changes, the new version will be posted here with a new effective date. Material changes will also be noted in the App Store release notes.
Contact
A.I. Whoo LLC
Email: support@aiwhoo.com