Privacy First

Privacy You Can Trust

We built BonusLedger because we refuse to link our bank accounts to apps. Your data is yours, period.

Our Privacy Principles

No Account Linking

Unlike Mint, YNAB, or Personal Capital, we NEVER ask for:

  • No bank usernames or passwords
  • No full account numbers
  • No Social Security Numbers
  • No credentials of any kind

No Cloud Storage (v1)

Everything stays on your device:

  • SwiftData local database
  • Encrypted documents in app sandbox
  • No network requests (except App Store)
  • Optional iCloud backup in v1.1 (user choice)

No Data Collection

We don't collect:

  • No usage analytics
  • No crash reports
  • No personal information
  • Literally nothing

Security Features

Bank-level security to protect your financial information

Encryption

  • AES-256-GCM for all documents
  • Keychain storage for encryption keys
  • Complete file protection when device locked
  • Face ID/Touch ID for sensitive documents
  • Unique nonces per file

App Lock

  • Face ID or passcode required on launch
  • Automatic re-lock after app backgrounds
  • Biometric authentication for high-risk documents

Data Minimization

  • We don't ask for full account numbers
  • We don't ask for SSNs
  • We don't ask for credentials
  • We recommend storing only last 4 digits
  • We warn against storing passwords in documents

App Store Privacy Nutrition Label

Data Not Collected

BonusLedger's App Store privacy label shows:

✓ Data Not Collected

"We're proud to be one of the few finance apps with this label."

Privacy Policy Summary

Information We Collect

We do not collect any personal information.

All data you enter into BonusLedger is stored locally on your device and is never transmitted to our servers or any third party.

Data Storage

All data is stored locally on your iPhone using SwiftData. Documents are encrypted using AES-256-GCM encryption and stored in the app's secure sandbox. Your encryption keys are stored in the iOS Keychain.

Third-Party Services

BonusLedger does not use any third-party analytics services, crash reporting tools, or advertising networks. The only network requests made are to the App Store for app updates.

Data Backup

Backups are user-initiated only. You can export your data as encrypted CSV files. In v1.1, we will offer optional iCloud sync, which will be encrypted end-to-end and entirely under your control.

Data Recovery

We cannot recover your data (because we never have it).

Since all data is stored locally on your device and we have no servers, we cannot recover your data if you lose your device or delete the app. Please export regular CSV backups for safekeeping.

Contact

For privacy questions, contact us at privacy@bonusledger.com

Experience True Privacy

Your data stays on your device, always