Legal

Data Policy

The technical companion to our Privacy Policy — where your data is stored, how it is secured in transit and at rest, how it syncs across your devices, and how to remove everything.

Effective 1 July 2026Version 2.4

Architecture: Your records are held in your own private, access-controlled account and stored on secure managed infrastructure, encrypted in transit and at rest. They sync to the devices you sign in on.

1. Storage model

Records you enter are saved to your private account on secure, managed cloud infrastructure and cached locally so the app remains responsive. Each account is isolated: your ledger is accessible only through your own authenticated sign-in, and we apply strict access controls so that only you can reach your data.

2. Data categories

The app stores the following categories of data, all locally:

  • Identity records — lendee names, NIC numbers, phone numbers and notes you enter.
  • Financial records — loan principals, interest terms, schedules, installments, payments and balances.
  • Documents — generated receipts and their sequential numbers.
  • Configuration — SMS templates, language preference, theme, PIN hash and app settings.

3. Security measures

  • Access to your account requires authenticated sign-in, and in-app access is additionally gated by a PIN, stored only as a salted hash — never in plain text.
  • Biometric unlock is supported on capable devices via the Android BiometricPrompt API.
  • Data is encrypted in transit using industry-standard TLS and encrypted at rest on the server.
  • Access is governed by per-account rules so that no other user — and no unauthorised party — can read your records.

4. Sync & backup

Your ledger syncs automatically to your account whenever the app has a connection, so your records are continuously backed up and available on any device where you sign in. Recent changes are cached on the device and reconciled with your account when connectivity returns, so short offline periods do not interrupt your work. You may also export a local copy of your data at any time from Settings → Backup.

5. Retention

Your records are retained in your account for as long as you keep them. LoanLedger applies no automatic expiry — you decide what to keep and what to delete. When you delete a record, or your account, the corresponding data is removed from active storage and purged from backups within a limited operational window.

6. Optional diagnostics

If, and only if, you opt in, the app may send anonymous crash reports. These contain the device model, OS version and a technical stack trace. They are stripped of ledger content and cannot be tied back to you. You can turn diagnostics off at any time in Settings.

7. Deleting your data

  • Individual records — edit or delete any lendee, loan or payment from within the app; the change syncs to your account.
  • Everything — use Settings → Clear all data to remove your ledger from your account.
  • Your account — request account deletion to permanently remove all associated data from our systems.

Deletion is permanent and cannot be undone. Export a copy of your data first if you may need the records later.

8. Moving to a new device

Because your ledger is tied to your account, migrating is simple: install LoanLedger on the new device and sign in. Your records sync down automatically — there is no file to move by hand.

→ Privacy Policy→ License Terms