Debt Book app icon
Privacy-first · No backend

Privacy Policy

Stored locally or in your private iCloud. We never see your records.

App · Debt Book Developer · Shahanul Haque Effective · August 29, 2026 Contact · shahanulhaqueshawon@gmail.com

Debt Book (“the App”, “we”, “us”) is a personal loan and debt tracker for iOS. This policy explains what data the App handles and how it is protected. We do not operate an application backend and we do not receive, sell, or share your debt records or contacts. Your records are stored locally on your device and, if you explicitly use Cloud Backup, in your own private iCloud account.

📵

No backend

We run no server. Your financial records never reach us.

📱

On-device

Data is stored in a local database on your device.

☁️

Your iCloud

Optional backup uses your private iCloud — not ours.

📊

Anonymous analytics

Which features get used — never names, notes, or amounts.

1 Summary

  • No backend. The App has no server of ours. We never receive your financial records.
  • Local storage. Your data is stored on your device in a local database (Apple SwiftData).
  • iCloud backup and restore are optional and use your private iCloud account — not ours.
  • No ads in the App, and no ad network SDK inside it.
  • Anonymous usage analytics and crash reports are collected so we can see which features are used and fix what breaks. These carry no names, no notes, and no amounts — see sections 8 and 9.
  • With your permission (the iOS tracking prompt), your device's advertising identifier is used to measure which advertisement led to an install. You can decline, and can change your mind at any time in iOS Settings.
  • Network use: optional iCloud backup, subscription processing through Apple / RevenueCat, analytics and crash reporting, and push notifications.

2 Data You Enter

You may store the following in the App: debtor/creditor names, transaction amounts, dates, notes, interest terms, payment records, books/ledgers, and your own profile.

  • This data is saved locally on your device using SwiftData.
  • It is not sent to us or to any third party we control.
  • You can delete any record, or clear all data, at any time from within the App.

3 iCloud Backup & Restore · Optional, Premium

If you use Cloud Backup or Restore:

  • Your data is stored in your own private iCloud container (iCloud.com.shahanul.Debt-Book) under your Apple ID.
  • This transfer is between your device and Apple's iCloud. We have no access to it.
  • Apple's handling of iCloud data is governed by Apple's Privacy Policy.
  • You can stop using Cloud Backup and manage the App's iCloud data through Apple's iCloud settings.
Cloud Backup requires network access. The App also uses network access for subscription purchase and entitlement processing through Apple and RevenueCat.

4 Contacts Access

The App provides an optional searchable contact list to speed up adding a transaction (NSContactsUsageDescription).

  • Contact access is requested only when you open the contact-selection feature. If permission is granted, the App reads contacts from the device to display the searchable list, including names, phone numbers, email addresses, and contact thumbnails when available.
  • If you select a contact, the contact's name, first phone number, and first email address, when available, are copied into the App's local database and associated with your debt record. Contacts you do not select are not saved in the App's database.
  • We do not receive or upload your address book or selected contact information to a server operated by us, and the App does not send contacts to RevenueCat.
  • If you explicitly use Cloud Backup, saved debt-book records—including contact details you previously selected and saved—are included in the backup stored in your private iCloud container under your Apple ID. We do not have access to that data.
  • A selected contact's name and phone number may appear in a PDF transaction statement generated on the device. The PDF is shared only when you explicitly choose a destination through the iOS share sheet.
  • You can deny or revoke contacts permission in iOS Settings; the App still works (you type names manually).

5 AI Book-Name Suggestions

The App can suggest names for your books using Apple's on-device language model (NSLanguageModelUsageDescription).

  • This runs entirely on your device using Apple's Foundation Models.
  • No prompt or data is sent to us or to an external AI service for this feature.

6 Subscriptions & Payments

Premium features are sold via subscriptions and a lifetime purchase. Payments are processed by Apple (App Store), and subscription state is managed through RevenueCat, our subscription infrastructure provider.

  • We never see or store your payment card details. Apple handles all billing.
  • RevenueCat processes subscription-related identifiers, purchase/entitlement information, and associated technical information needed to validate purchases and enable restore-purchases. The App does not send RevenueCat your contacts, debt records, names, notes, or transaction amounts.
  • RevenueCat's handling of data is governed by RevenueCat's Privacy Policy.
  • Apple's handling is governed by Apple's Privacy Policy.
Manage or cancel your subscription anytime in iOS Settings → Apple ID → Subscriptions.

7 Security

  • Optional PIN lock and auto-lock protect access to the App.
  • Your PIN is stored only as a SHA-256 hash on your device — the raw PIN is never stored.
  • Because your data lives on your device (and in your own iCloud), its security also depends on your device passcode and Apple ID security.

8 Analytics & Advertising Measurement

The App records a small, fixed set of anonymous usage events so we can see which features people actually use, where they get stuck, and whether an update made things better. These are sent to Amplitude and to Google Firebase Analytics.

The complete list of events is: app opened; onboarding started and completed; book created; person added; transaction created; partial payment added; transaction paid off; interest calculated; PDF exported; PIN enabled; iCloud backup enabled; paywall viewed; purchase started; purchase completed. The App also records app launches and session starts automatically.

An event may carry structural details only — whether a transaction was a lend or a borrow, whether it had interest or a due date, how many books exist, the subscription product identifier and its price, and whether you are on the free or paid plan.

What is never sent, in any event: the name, phone number or email of anyone in your books; any amount lent, borrowed, paid or owed; interest figures; note text; photos; PDF contents; or your own profile details. The analytics services cannot see your ledger.

Advertising identifier & the tracking prompt

We advertise the App. To learn which advertisement led to an install, Firebase can share your device's advertising identifier (IDFA) with Google Ads, where it is matched against advertisements you were shown. Under Apple's rules this counts as tracking, so:

  • iOS asks your permission first, through the standard App Tracking Transparency prompt.
  • If you decline, no advertising identifier is read, and iOS additionally blocks the App's analytics traffic to Google's measurement endpoint. The App works exactly the same either way.
  • You can change your answer at any time: iOS Settings → Privacy & Security → Tracking.

Purchase events — which subscription was bought, its price and currency — are also used to measure advertising performance. No advertising network operates inside the App, and we never receive advertising profiles built about you elsewhere.

9 Crash Reports & Diagnostics

When the App crashes, a report is sent to Google Crashlytics so the bug can be found and fixed. A report contains:

  • The crash itself — the stack trace and the code that failed
  • Device model, iOS version, App version, and the App's database schema version
  • A randomly generated installation identifier, which is not tied to you or to any account

We also record a report when the App's database fails to open, because the App recovers from that silently and it would otherwise be invisible to us. No ledger content is ever attached to a crash report — no names, amounts or notes.

10 Notifications

  • Due-date reminders are local. Your device schedules them and they never leave it. No server is involved and we cannot see them. With Discreet Notifications on, names and amounts stay off your lock screen.
  • Announcements are push notifications delivered through Firebase Cloud Messaging. If you allow notifications, your installation receives a push token — that is what lets an announcement reach everyone at once. The token identifies an installation, not you, and we keep no list of who received what.
  • Turn either off at any time in iOS Settings → Notifications → Debt Book.

11 Data We Do Not Receive

The developer does not receive or have access to:

  • Your debts, transactions, amounts, interest terms, or notes
  • The names, phone numbers or email addresses of the people in your books
  • Your own profile details — name, email, phone or photo
  • Your contacts
  • Your photos, or any PDF statement you generate
  • Your PIN (only a one-way SHA-256 hash is stored on your device, never sent anywhere)
  • Your location
  • Any data on a server operated by us (we have none)

12 Children's Privacy

The App is not directed to children under 13 and we do not knowingly collect personal data from children. We operate no server that holds your records, and the analytics and crash data described above carry no personal details. The App does not ask for the tracking permission in order to build a profile of anyone, and tracking can be refused outright.

13 Your Rights & Control

You are in full control of your data:

  • Access / Export: Export your data from within the App.
  • Delete: Delete individual records or clear local data in the App. If you used Cloud Backup, you can manage the App's stored iCloud data through Apple's iCloud settings.
  • Because we hold no copy of your ledger, deletion on your device (and iCloud) removes it entirely.
  • Tracking: allow or refuse it when the App asks, and change it later in iOS Settings → Privacy & Security → Tracking. Refusing stops the advertising identifier from being read or shared.
  • Notifications: turn announcements and reminders off in iOS Settings → Notifications → Debt Book.
  • Analytics: to ask that analytics and crash reporting be disabled for your installation, or to ask what has been collected, email us — the address is at the top of this page.

14 Third-Party Services

ServicePurposeData involved
Apple iCloudOptional backup/restoreYour saved records, which may include contact details you selected (in your private container)
Apple App StorePayment processingHandled by Apple
RevenueCatSubscription validationSubscription-related identifiers, purchase/entitlement information, and associated technical information
AmplitudeProduct analyticsAnonymous event names and properties, a generated device identifier, app version, device model and OS version
Google — Firebase Analytics & CrashlyticsProduct analytics, advertising measurement, crash reportingThe same anonymous events, crash logs and diagnostics, and — only if you allow tracking — your device's advertising identifier
Google — Firebase Cloud MessagingPush notificationsA push token issued to your installation

None of these services receive your debt records, the people in your books, or your notes. No advertising network runs inside the App.

15 Changes to This Policy

We may update this policy as the App evolves. The “Effective date” above reflects the latest version. Material changes will be reflected here and, where appropriate, in the App.