Privacy Policy
TapLedger reads payment screenshots so you don’t have to type them in. That only works if you trust it with what is on those screens, so this page says plainly what leaves your phone, what we keep, and for how long.
The short version
- Screenshots never leave your phone. Text is recognised on-device; the image itself is never uploaded and we never store it.
- Card and account numbers are masked before anything is sent. That happens on your device, not on our servers.
- We never connect to your bank. There is no linking, no credentials, no statement fetching. You choose what TapLedger sees, one capture at a time.
- The captured text is deleted shortly after processing — within an hour on our default configuration.
- We do not sell your data, and we do not use it for advertising.
What happens to a capture
When you share a screenshot to TapLedger, the app recognises the text on it using Apple’s on-device Vision framework. The image stays on your phone.
Before any text is sent, the app masks patterns that we never need in order to identify a payment: card numbers, masked account numbers, payment addresses, and long reference numbers. Those are replaced with placeholders such as [CARD] and [ACCT]. The same redaction code runs in both the app and the share extension, so there is one implementation and no drift between them.
The redacted text is then sent to our servers, where an AI model extracts the merchant, amount, currency, category and date. That redacted text is the only raw capture content we ever hold, it exists solely so the job can be retried if it fails, and a sweeper blanks it on a short timer — one hour by default. After that, what remains is the ledger entry itself.
What we store
- Your account: email address, a hash of your password (never the password), display name, and default currency. If you sign in with a third-party provider, we store the identifier that provider gives us.
- Your ledger: merchant, counterparty, amount, currency, category, description, date, and how confident the extraction was. Edits are kept as a change history so a wrong correction can be traced.
- Sessions: a hash of each session token, when it was last used, when it expires, and the device description your app sends, so you can see and revoke sessions from other devices.
- Subscription state: whether you are on the free or paid tier, the current period, and the identifiers Apple gives us for your subscription. We also count how many captures you have made in the current period to apply free-tier limits.
- Push tokens, if you allow notifications, so we can tell you when a capture has finished.
Payments
Subscriptions are sold through Apple. Your card details go to Apple, never to us — we receive only the subscription identifiers and status needed to unlock the paid tier. Manage or cancel from your Apple account settings.
Who else touches your data
- Google (Gemini): receives the redacted capture text in order to extract the transaction. It does not receive your images, your name, or your email.
- Apple: handles subscription billing and delivers push notifications.
- Our hosting and database providers, which store the data described above on our behalf.
We do not sell personal data, and we do not share it with advertisers or data brokers.
Your choices
- Export. You can export your transactions as a CSV file at any time from the app.
- Correct or delete entries. Any transaction can be edited or deleted from your ledger.
- Sign out other devices. Sessions can be revoked individually from Settings.
- Delete your account. Write to us at the address below and we will delete your account and the ledger attached to it.
- Lock the app. Face ID app lock is available in Settings.
Keeping it secure
Traffic is encrypted in transit. Passwords are stored only as hashes, and session tokens are stored only as hashes, so a copy of our database does not yield either. No system is immune to every risk, and we will not pretend otherwise.
Children
TapLedger is not directed at children under 13, and we do not knowingly collect their data.
Changes to this policy
If we change how we handle your data in a way that matters, we will update this page and say so in the app before the change takes effect.
Contact
Questions, requests, or complaints: privacy@tapledger.ai.
TapLedger is operated by TapLedger, Inc., 1209 Orange Street, Wilmington, Delaware 19801, United States. If you are in a region with specific data rights — such as the UK, EU or California — those rights apply, and the contact address above is how to exercise them.