Clipo Ledger

Created on 21 September 2026

Privacy Policy
# Clipo Ledger Privacy Policy

## 1. About Clipo Ledger

Clipo Ledger is an iOS application designed to record personal income and expenses, organize receipt images, set monthly budgets, and track recurring subscriptions. This policy outlines how [LEGAL_ENTITY_NAME] (hereinafter "we" or "us") handles information related to these features.

The current version of the app processes and stores your financial records locally on your device. It does not connect to bank accounts, collect banking credentials, execute payments, provide investment services, or operate a server to receive your ledger data. The optional local account feature within the app does not offer cloud synchronization or email-based password recovery services.

## 2. Information Processed on Your Device

### Selected Receipt Images and Recognized Text

When you use the system photo picker, Clipo accesses only the images you select; it does not automatically scan your photo library. If you confirm and save a record, that record will include a copy of the selected image. The original image in your "Photos" app remains unmodified.

Clipo uses Apple's Vision framework to recognize text on your device. Based on the recognized text, it may suggest a merchant or source, total amount, supported currency, and specific date. You must review and confirm these details before saving. Recognition results may be incomplete or inaccurate. Recognized text is not sent to external AI services.

Depending on the images you select, receipt images may contain additional information, such as addresses or partial account numbers. Please select only the information you wish to keep within Clipo. We do not ask you to enter bank passwords, card security codes, or online banking credentials.

### Income, Expense, and Budget Records

Saved records include the merchant or source name, amount, currency, income/expense type, category, date, notes, record identifier, and any saved receipt images. Budget records store spending limits associated with specific months and currencies. Clipo uses these records to display your ledger, search results, category breakdowns, monthly totals, and budget progress. Records in different currencies are tallied separately; no currency exchange rate conversions are performed. ### Recurring Subscriptions and Reminders

If you add a subscription record, Clipo stores its name, renewal amount, currency, billing cycle (monthly or yearly), renewal reference date, notes, identifier, and reminder preferences. These are merely tracking records manually entered by the user; saving or deleting a record does not actually initiate, pay for, or cancel any subscription service. Subscription plans are not automatically recorded as expenses; you must confirm payment entries separately.

If you enable reminders, Clipo requests iOS notification permissions. Reminder tasks are scheduled locally, and notification text uses a generic format that does not include the service name or amount you saved. The app can schedule up to 60 upcoming renewal reminders and refreshes the schedule when you open the app or modify saved subscription plans. Actual notification delivery depends on iOS permissions and notification settings. Logging out cancels all pending and sent notifications associated with the current session.

### Optional Local Accounts and Session State

Guest mode does not require a name, email address, or password. If you create an account, Clipo processes your name, email address, password, and password confirmation. Your name, email, a randomly generated account identifier, a salt value, and password-derived verification data are stored in the device's Keychain. Clipo does not store passwords or password confirmation data in plain text.

The app saves an account identifier or guest flag to restore your session state. Email addresses are used solely to identify accounts locally; Clipo does not send verification, account recovery, or marketing emails. Guest ledgers and account ledgers are independent; entries made in guest mode are not automatically transferred to a registered account.

## 3. How Information Is Used

We process information to provide the features you choose, including: importing and viewing receipts, saving and editing entries, calculating totals, categorizing items, managing budgets, tracking subscriptions, sending optional local reminders, and verifying local accounts.

We do not use your ledger data, receipt content, or account details for advertising, cross-app tracking, data trading, or training our own AI models. The app currently contains no advertising SDKs, third-party login services, or third-party behavioral analytics SDKs. Where applicable law requires a legal basis, the specific basis depends on the data processing activity and your jurisdiction—for example, providing the services you request, obtaining your consent when necessary, or responding to support requests based on an appropriate legal basis. Creating an account is entirely voluntary; you may always use guest mode. ## 4. Transfers, Third Parties, and Support

Clipo does not upload receipt images, recognized text, ledger entries, budgets, saved subscription details, or local account credentials to the app's backend. We do not sell or rent this information.

Apple provides the operating system, photo picker, on-device text recognition, Keychain, notifications, and App Store distribution services. Apple may independently process platform, diagnostic, or backup information in accordance with your settings and Apple’s Privacy Policy (https://www.apple.com/legal/privacy/).

If you contact [PRIVACY_EMAIL], we receive the information you choose to include in the email and its attachments. We use this information to respond to your requests and resolve issues. Your communications service provider also processes the email according to its own terms. We may disclose support communication records if required by applicable law. Please do not send passwords, banking credentials, or unnecessary financial information. We cannot remotely view your local ledgers or recover your local account password.

## 5. Storage, Backup, and Security

Ledger records and receipt copies are stored in the app's device storage. Newly saved ledger and receipt files utilize iOS file protection options. Local account records use the Keychain feature with device-only access; Clipo is not configured for iCloud Keychain synchronization. Password verification employs a randomly salted key derivation function rather than storing passwords in plain text.

Clipo does not provide its own cloud backup or synchronization services. However, depending on your settings, device backups managed by Apple or computer backups may still contain app files. Deleting information from Clipo does not automatically delete copies contained in previously created backups. Please manage these copies via your device or backup service.

Security also depends on your device passcode, operating system protections, and who has access to the device. No storage method can guarantee absolute security. ## 6. Retention and Deletion

### Individual Entries

Saved entries remain in your ledger until you delete them, clear the ledger, or remove the associated app data. Open an entry in the **Ledger** and select **Delete Entry** to remove that entry and its saved receipt copy from Clipo. The original photo image remains unchanged.

### Budgets and Subscription Plans

You can delete monthly budgets from the budget editor. You can delete saved subscriptions from the editor; Clipo will then update its local reminder schedule. Removing tracking records does not cancel billing for the underlying service.

### Clearing the Ledger

In **Your Space**, select **Clear This Ledger** and confirm to remove the current ledger's entries, receipt copies, budgets, saved subscriptions, and associated local reminders. Other account ledgers and guest data remain unaffected. Clearing the ledger does not delete its local account record.

### Deleting a Local Account

After logging in, open **Your Space → Delete Local Account** and enter your password to confirm. Clipo removes the current account's ledger, receipt copies, budgets, subscription records, and Keychain account records, then ends the session and cancels local reminders. Other local accounts and guest ledgers remain available.

If a storage error occurs during deletion, the app will report it. Do not assume deletion is complete until the operation succeeds and the app returns to the welcome screen; a retry may be necessary. We cannot perform this deletion operation remotely on your device.

### Guest Data, Signing Out, and Uninstalling

Guests can use the "Clear This Ledger" function and then "Exit Guest Mode." Signing out or exiting guest mode preserves saved records. Deleting the application usually removes the application container files; uninstalling the application may leave these files behind. Keychain records may persist after uninstallation, so if you wish to delete an account, please use the "Delete Local Account" function before uninstalling. Existing device backups must be managed separately.

### Support Communications

Support communications will be retained for [SUPPORT_RETENTION_PERIOD_OR_CRITERIA] days, unless applicable law requires a longer retention period. Operators must state their actual retention practices prior to publishing this policy. ## 7. Your Choices and Rights

You have control over the images you import, the recognized details you use, and the entries you save. You can use Guest Mode, edit or delete records, remove budgets and subscription plans, disable reminders, clear the current ledger, or delete your local account. Please manage notification permissions and backups within the relevant system settings.

Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to certain processing, obtain a copy of your personal information, or withdraw consent where processing relies on it. These rights are subject to applicable conditions. You may also have the right to contact the competent data protection authority.

If you have questions regarding privacy, please contact [PRIVACY_EMAIL]. We can respond to inquiries regarding information we hold, such as support messages. We do not store server-side copies of your local financial records; please use the controls provided within the app to view information stored solely on your device. Clipo does not currently offer a ledger export function.

## 8. Children's Privacy

Clipo Ledger is a general-purpose personal bookkeeping tool and is not designed specifically for children. We do not use the app to build advertising profiles of children. If a parent or guardian has any concerns regarding the information we collect, please contact [PRIVACY_EMAIL]. Before releasing this app in a specific market, the operator must assess any age-related requirements applicable to that market.

## 9. Policy Changes

We may update this policy when the app's features or data processing practices change. Updated policies will indicate their effective date. Before implementing changes that require notification or consent, we will provide notice or obtain consent as required by applicable law.

## 10. Contact Information