TapLedger

Privacy Policy

The short version

What happens to a capture

When you share a screenshot to TapLedger, the app recognises the text on it using Apple’s on-device Vision framework. The image stays on your phone.

Before any text is sent, the app masks patterns that we never need in order to identify a payment: card numbers, masked account numbers, payment addresses, and long reference numbers. Those are replaced with placeholders such as [CARD] and [ACCT]. The same redaction code runs in both the app and the share extension, so there is one implementation and no drift between them.

The redacted text is then sent to our servers, where an AI model extracts the merchant, amount, currency, category and date. That redacted text is the only raw capture content we ever hold, it exists solely so the job can be retried if it fails, and a sweeper blanks it on a short timer — one hour by default. After that, what remains is the ledger entry itself.

What we store

Payments

Subscriptions are sold through Apple. Your card details go to Apple, never to us — we receive only the subscription identifiers and status needed to unlock the paid tier. Manage or cancel from your Apple account settings.

Who else touches your data

We do not sell personal data, and we do not share it with advertisers or data brokers.

Your choices

Keeping it secure

Traffic is encrypted in transit. Passwords are stored only as hashes, and session tokens are stored only as hashes, so a copy of our database does not yield either. No system is immune to every risk, and we will not pretend otherwise.

Children

TapLedger is not directed at children under 13, and we do not knowingly collect their data.

Changes to this policy

If we change how we handle your data in a way that matters, we will update this page and say so in the app before the change takes effect.

Contact

Questions, requests, or complaints: privacy@tapledger.ai.