Privacy You Can Trust
We built BonusLedger because we refuse to link our bank accounts to apps. Your data is yours, period.
Our Privacy Principles
No Account Linking
Unlike Mint, YNAB, or Personal Capital, we NEVER ask for:
- No bank usernames or passwords
- No full account numbers
- No Social Security Numbers
- No credentials of any kind
No Cloud Storage (v1)
Everything stays on your device:
- SwiftData local database
- Encrypted documents in app sandbox
- No network requests (except App Store)
- Optional iCloud backup in v1.1 (user choice)
No Data Collection
We don't collect:
- No usage analytics
- No crash reports
- No personal information
- Literally nothing
Security Features
Bank-level security to protect your financial information
Encryption
- •AES-256-GCM for all documents
- •Keychain storage for encryption keys
- •Complete file protection when device locked
- •Face ID/Touch ID for sensitive documents
- •Unique nonces per file
App Lock
- •Face ID or passcode required on launch
- •Automatic re-lock after app backgrounds
- •Biometric authentication for high-risk documents
Data Minimization
- •We don't ask for full account numbers
- •We don't ask for SSNs
- •We don't ask for credentials
- •We recommend storing only last 4 digits
- •We warn against storing passwords in documents
App Store Privacy Nutrition Label
Data Not Collected
BonusLedger's App Store privacy label shows:
"We're proud to be one of the few finance apps with this label."
Privacy Policy Summary
Information We Collect
We do not collect any personal information.
All data you enter into BonusLedger is stored locally on your device and is never transmitted to our servers or any third party.
Data Storage
All data is stored locally on your iPhone using SwiftData. Documents are encrypted using AES-256-GCM encryption and stored in the app's secure sandbox. Your encryption keys are stored in the iOS Keychain.
Third-Party Services
BonusLedger does not use any third-party analytics services, crash reporting tools, or advertising networks. The only network requests made are to the App Store for app updates.
Data Backup
Backups are user-initiated only. You can export your data as encrypted CSV files. In v1.1, we will offer optional iCloud sync, which will be encrypted end-to-end and entirely under your control.
Data Recovery
We cannot recover your data (because we never have it).
Since all data is stored locally on your device and we have no servers, we cannot recover your data if you lose your device or delete the app. Please export regular CSV backups for safekeeping.
Contact
For privacy questions, contact us at privacy@bonusledger.com
Experience True Privacy
Your data stays on your device, always