In short
- Ledgerly needs no account with me and uses no server of mine. It has no ads, no analytics and no tracking. Nothing from the app is sent to me.
- Your household book is stored on your device. Ledgerly does not encrypt it itself; the operating system’s protections and, where it is turned on, your device’s encryption protect it.
- Bank sync connects your device directly to your own bank. Your PIN and TANs are never stored.
- Device backups you have turned on may include your book. You and your backup provider control them; I have no access.
- To delete everything, first remove your bank connections in Ledgerly, then delete the app and its data — on the Mac also its data folder (see “Retention and deletion”). Copies in your device backups stay until you delete them. I hold nothing from the app that I could delete.
Who is responsible
This privacy policy applies to Ledgerly, the household book app for Android, iPhone, iPad and Mac (app ID cloud.lesch.ledgerly). It covers all of the app’s features, including bank sync, which is being rolled out in stages. Some features described here may therefore not be in your version yet.
As the developer of Ledgerly, I am the controller under the EU General Data Protection Regulation (GDPR):
Benedikt Lesch
Merzig
Germany
Email for privacy questions: coderoftime@gmail.com
Further contact details are in the legal notice (Impressum).
What I receive
Nothing from the app. Ledgerly:
- needs no sign-up and no account with me,
- does not connect to any server of mine,
- contains no advertising, analytics, tracking or crash-reporting tools,
- has no in-app purchases.
So I do not collect, sell or share any data from the app. Information reaches me only through the app stores or when you write to me. Both are described below. If you open this policy or my website from the app, it opens in your browser; what my web host processes when you do so is explained in the privacy policy of my website.
On your device
Everything you enter in Ledgerly, and everything it fetches from your bank, is stored on your device in the app’s private storage. This “book” contains:
- Accounts: name, type, colour, currency and opening balance; for bank accounts also the bank’s name, IBAN, BIC and the time of the last sync.
- Transactions: date, optional time, amount, counterparty, note, category and status; for transactions from your bank also the payment reference (kept as the note), the counterparty’s IBAN, the bank’s booking type (such as “direct debit”) and an import key that prevents duplicates.
- Categories, rules, budgets and recurring entries, including the words your rules look for.
- Debts and repayments: the other person’s name, the amount, the reason and the due date.
- Your settings: light, dark or system theme.
Your book can contain information about other people, such as payees or someone you lent money to. It is handled like the rest of your book and is not sent to me.
Ledgerly reads your device’s language and region to show dates and amounts in your format and to name the categories a new book starts with.
The details of a bank connection are kept separately, in the device’s secure storage (see “Bank sync”).
Bank sync (FinTS)
Bank sync is optional. It works with German banks and savings banks that offer FinTS (HBCI) with PIN/TAN.
How it works
When you connect a bank or fetch new transactions, Ledgerly opens an encrypted HTTPS connection from your device directly to your bank’s FinTS server. Apart from the services every internet connection runs through, such as your internet provider and any VPN or proxy you have set up, no other service is in between, and I am not involved. Those services can see which server your device connects to, but not the content. Ledgerly takes the server address from a bank directory built into the app, so looking up your bank sends nothing. The server may be run for your bank by its IT service provider.
Ledgerly contacts your bank only when you connect it or fetch transactions, and you enter your PIN each time. It does not sync in the background.
What is sent to your bank
- the bank code (BLZ),
- your online-banking login name and, if your bank uses one, your customer ID,
- your PIN,
- TANs you type in, or, if you approve in your bank’s app, requests asking whether you have approved,
- the TAN method you use and the name of your TAN medium,
- the customer system ID that your bank has assigned to this installation of Ledgerly,
- Ledgerly’s FinTS product registration number and version, which identify the app, not you,
- your request, for example which accounts and which period to fetch.
As with any internet connection, your bank also sees your device’s IP address and the technical name of the HTTP software Ledgerly uses.
What your bank sends back
- your accounts at that bank (IBAN, BIC, account number, account name or type, and the names of the account holders),
- balances and transactions (booking and value date, amount, the counterparty’s name, IBAN and BIC, the payment reference, the booking type, references such as the end-to-end reference, mandate reference and creditor ID, and, where given, the name of an ultimate payer or payee),
- TAN requests, such as a photoTAN image or a chipTAN flicker code, and notices from your bank,
- technical parameters of your bank and of your access (bank parameter data and user parameter data).
What Ledgerly keeps
- Your accounts and their transactions go into your book (see “On your device”). Other transaction details from your bank, such as the references, are not stored, except where Ledgerly uses them to form the import key. Ledgerly calculates an account’s balance from its opening balance and its transactions; it uses the balance your bank reports at most to set the opening balance and does not store it separately.
- So that you don’t have to set up your bank again each time, Ledgerly keeps these connection details in the device’s secure storage — the Keychain on iPhone, iPad and Mac; on Android, encrypted with a key held in the Android Keystore:
- your login name and customer ID, the bank code and the server address,
- the customer system ID,
- the TAN method you use and the name of your TAN medium (for example, the name your bank has for your phone),
- the list of your accounts at that bank (IBAN, BIC, account numbers),
- the bank and user parameter data, which also contain the account holders’ names and the banking operations your bank allows.
- Your PIN and TANs are never stored. Ledgerly uses them only for the current connection and does not save them anywhere — not in the book, not in secure storage, not in a log and not in a backup.
When you remove a bank connection in Ledgerly, its connection details are deleted from secure storage. Accounts and transactions already fetched stay in your book.
Your bank’s role
Your bank processes the data it receives as an independent controller, under your agreement with it and its own privacy policy. I have no access to the data exchanged between you and your bank.
Device backups
Backups that you have turned on in your device’s operating system may include Ledgerly’s data:
- Android: Android backup to your Google account and transfer to a new device include your book and settings. The bank connection details are encrypted with a key that never leaves your device, so they cannot be read from a backup; after a restore, you set up your bank again.
- iPhone and iPad: iCloud Backup and backups made with a computer (Finder or iTunes) include your book and settings. iCloud Backup and encrypted computer backups can also include the bank connection details from the Keychain.
- Mac: Time Machine and other backup tools can include Ledgerly’s data folder.
These backups are kept by Google, by Apple or on your own backup drive. You and that provider control them, under the provider’s terms; I have no access to them. In your device’s backup settings you can turn backups off or, where your system allows it, leave Ledgerly out.
Sharing and third parties
I share no data from the app with anyone, because I receive none.
Ledgerly passes data on only when you do so yourself:
- Reports: PDF reports leave the app only when you share, save or print them through your system’s share or print dialogue, to a destination you choose.
- Selected text: you can copy text you select in Ledgerly, or pass it to another app you pick from the system menu, such as a translator.
What happens to the data there is up to you and the provider of that destination.
Ledgerly is built with Flutter and with open-source libraries that run only on your device, for example for the database, translations and icons, plus my own open-source FinTS library for bank sync. The fonts are built into the app. Apart from the FinTS library, which connects only to your bank and only when you use bank sync, none of these components sends data anywhere. The app contains no third-party code that collects data.
Your bank, the app stores and your backup provider receive data directly from you or your device, under their own responsibility. I pass them no data from the app. If I ever share data from the app with a third party, I will update this policy beforehand and only work with parties that protect your data at least as well as described here.
Permissions
- Internet access is used only for bank sync, to connect to your bank. On Android this is the “full network access” permission, which is granted on installation; on the Mac it is the App Sandbox permission for outgoing connections. iPhone and iPad need no permission for it. Versions of Ledgerly without bank sync do not request internet access at all.
- On the Mac, PDF reports also use the App Sandbox permissions for printing and, where needed, for saving to a file you choose.
- Ledgerly asks for no other permissions: no access to your camera, microphone, photos, contacts, location, calendar or notifications, and no tracking across apps. photoTAN and chipTAN codes are shown on the screen for your banking app or TAN generator to read; Ledgerly does not use the camera.
Security
- No data reaches me, so there is no server or database of mine from which your data could leak.
- Your book is kept in Ledgerly’s private storage. On Android, iPhone and iPad, the app sandbox shields it from other apps; on the Mac, programs you run outside the App Sandbox may be able to read it (from macOS 14 on, only if you allow it). Ledgerly does not encrypt the book itself; it relies on your device’s encryption, where it is turned on. Please use a screen lock, and on the Mac turn on FileVault.
- Connections to your bank use encrypted HTTPS only and go only to the address listed for your bank. Ledgerly does not follow redirects to other addresses.
- If your bank refuses a login, Ledgerly does not resend that PIN on its own, so the app cannot lock your access through automatic retries. Your bank’s limit on wrong PINs still applies when you type a PIN in again.
- PIN and TANs are never stored; connection details are kept in the device’s secure storage.
- Ledgerly keeps no logs of its own and writes no PINs or TANs to the system log.
Google Play and the App Store
Ledgerly is distributed through app stores such as Google Play and Apple’s App Store. When you download it, Google or Apple process data about your account, your device, the download and any payment under their own privacy policies. A download does not tell me your name or email address.
Statistics and crash reports
In Google Play Console and in Apple’s App Store Connect and Xcode Organizer I see:
- Statistics: aggregated figures such as installs, uninstalls, countries, device types, operating-system versions and ratings. They do not identify you.
- Crash reports: reports about crashes and about times the app stopped responding, if you have allowed your device to share diagnostic data with developers (on Android under “Usage & diagnostics” in your Google settings; on Apple devices under Privacy & Security > Analytics & Improvements > Share With App Developers). They come from your device’s operating system, not from code in Ledgerly. They contain technical details such as the app version, the device model, the operating-system version and where the error occurred — not the contents of your book and not your name. I use them only to find and fix errors.
Reviews
If you review Ledgerly, I see your review and your public name; on Google Play also technical details of the review such as the device model, Android version, app version and language, and on the App Store the country of the store. I may reply in the store.
Test versions
If you take part in a test version (Google Play testing or Apple’s TestFlight), I see the email address you were invited with and, on TestFlight, also the name you were invited with, your test status and how many sessions and crashes were recorded on your devices. If you send feedback, I also see it with the technical details attached, such as the device model and operating-system version; feedback can include comments, screenshots and crash reports. I use this only to run the test.
Contacting me
If you write to me, I use your email address, your name if you give it, and your message only to answer you. The emails are kept in my mailbox with my email provider (see “Recipients and transfers”).
Legal bases
- In the app, including bank sync: I receive no personal data from the app and therefore process none through it. Should I nevertheless be regarded as responsible for this processing, its legal basis is Art. 6(1)(b) GDPR, because it serves only to provide the app functions you use. For information about other people (such as payees, people you lent money to or co-account holders) it is Art. 6(1)(f) GDPR; the legitimate interest is to let you keep your household book. Ledgerly stores information on your device and reads information from it only as far as this is strictly necessary for the functions you use (§ 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG).
- Statistics and crash reports: Art. 6(1)(f) GDPR. My legitimate interest is to find and fix errors and to understand, in aggregate, how the app is used.
- Reviews: Art. 6(1)(f) GDPR. My legitimate interest is to respond to feedback.
- Test versions: Art. 6(1)(b) GDPR, because you asked to take part.
- Emails: Art. 6(1)(f) GDPR. My legitimate interest is to answer your request. If your request concerns a contract with me, the legal basis is Art. 6(1)(b) GDPR.
You are not required to provide any data. Without it, only the function concerned is unavailable: bank sync needs your bank login, and I can only answer if you write to me. There is no automated decision-making or profiling.
Recipients and transfers
- Apart from the services named below, I pass no data to anyone.
- Google and Apple: I see statistics, crash reports, reviews and tester details in their developer tools, and, to invite testers, I enter their email addresses there. Google and Apple also process this data in the USA, on the basis of the EU–US Data Privacy Framework or the EU standard contractual clauses, as described in their privacy policies.
- Email provider: My mailbox is a Gmail account, so emails you send me are stored by Google (for accounts in the European Economic Area: Google Ireland Limited) and processed under Google’s privacy policy. Google may also process them in the USA. Such transfers are based on the European Commission’s adequacy decision for the EU–US Data Privacy Framework of 10 July 2023 or on EU standard contractual clauses, as described in Google’s privacy policy.
Retention and deletion
How long data is kept
- Your book and bank connection details stay on your device until you delete them. I keep none of it.
- Emails are deleted once your request has been dealt with, unless the law requires me to keep them longer.
- Statistics and crash reports remain in Google’s and Apple’s developer tools for as long as Google or Apple keep them there. I copy individual reports only when needed to fix an error and delete the copy afterwards.
- Reviews and my replies stay in the store until you or I delete them, or the store removes them.
- Tester details are removed when the test ends or when you leave it.
Deleting everything on your device
- Android: Uninstall Ledgerly, or open Settings > Apps > Ledgerly > Storage and tap Clear storage (or Clear data; the names vary by device). This deletes your book, your settings and the bank connection details.
- iPhone and iPad: First remove your bank connections in Ledgerly, because the system can keep Keychain entries after an app is deleted. Then touch and hold the Ledgerly icon and tap Remove App > Delete App. “Offload App” keeps your data. If you have already deleted the app, reinstall it, open it, remove any bank connection it still shows and delete the app again.
- Mac: First remove your bank connections in Ledgerly. Quit the app, move it to the Trash and delete the folder
~/Library/Containers/cloud.lesch.ledgerly(in Finder, use Go > Go to Folder; the folder may be shown as “Ledgerly”). Moving the app to the Trash alone does not delete its data. If you have already deleted the app, reinstall it, open it, remove any bank connection it still shows and delete the app and its folder again.
Copies in backups
Copies in backups remain until that backup is deleted or replaced:
- Android: You can delete your device’s backup in your Google account (in Google Drive or Google One, under Backups); this deletes the whole device backup, not only Ledgerly’s part. If you reinstall Ledgerly, Android may restore your book from the backup.
- iCloud: In your iCloud settings (Settings > your name > iCloud) you can leave Ledgerly out of iCloud Backup and delete its data from the backup.
- Computer backups and Time Machine remain until you delete them or they are overwritten.
Deletion on my side
I hold no data from the app, so there is nothing for me to delete and no need to request deletion. If you want me to delete your emails or tester details, write to coderoftime@gmail.com.
Your rights
Under the GDPR you have the right to:
- access (Art. 15),
- rectification (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interests (Art. 21),
- withdraw consent at any time with effect for the future, where processing is based on consent (Art. 7(3)); currently none is.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work or where the alleged infringement took place.
To exercise your rights, write to coderoftime@gmail.com. Because I receive no data from the app, I cannot identify you from your use of it (Art. 11 GDPR) and hold nothing about it to show or delete. Your rights therefore mainly concern emails you sent me, reviews and test versions. The data on your device is in your own hands: you can see it in the app and delete it at any time as described above.
Right to object
Where I process data on the basis of legitimate interests (Art. 6(1)(f) GDPR, for example for statistics and crash reports, reviews and emails; see “Legal bases”), you can object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). Write to coderoftime@gmail.com. I will then stop, unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Your choices
Ledgerly does not ask for your consent: it sends me nothing, and it only stores and reads on your device what the functions you use strictly need (§ 25(2) No. 2 TDDDG). You still decide:
- Bank sync is optional. Ledgerly contacts your bank only when you ask it to. Removing a bank connection deletes its connection details.
- Diagnostic data: you can stop sharing it with developers at any time in your device settings (see “Statistics and crash reports”). This applies to future reports.
- Backups: you can turn them off in your device settings, or leave Ledgerly out where your system allows it.
Children
Ledgerly is a household book for adults and is not directed at children. I do not knowingly receive data from children — and the app sends me no data from anyone, whatever their age.
Changes to this policy
I update this policy when Ledgerly’s handling of data changes. If a change affects which data leaves your device or who receives it, I update the policy before the version with that change is released. This version is effective from 8 October 2026.