Who we are
Minine Ledger (“Minine Ledger,” “we,” “us,” or the “App”) is an iOS personal finance tracking application published by Minine Inc. Minine Inc is the data controller for the information described in this policy.
Minine Inc18952 MacArthur Blvd
Irvine, CA 92612
United States
Privacy questions and rights requests: [email protected].
Data we handle
2.1 Data stored on your device
The following data is created and stored locally in the App’s iOS container:
| Data | Examples | Purpose |
|---|---|---|
| Ledger data | Amount, date, category, income/expense type, note, merchant | Record and display your transactions |
| Receipt attachments | Images you capture or select and their file metadata | Attach supporting images to entries |
| Budgets and recurring entries | Weekly/monthly limits, alert settings, recurring rules, pending items | Budget progress, reminders, and recurring-entry review |
| Preferences | Currency, language, appearance, AI scan choice, App Lock setting | Remember how you configured the App |
| Purchase status | Locally cached Pro entitlement | Keep Pro features available between StoreKit checks |
We do not operate an account system or ledger cloud sync. Your ledger content is not uploaded to Minine Ledger servers except for the specific Pro AI scan flow described in §3.
2.2 Data processed when you use network features
- Pro AI scanning: compressed receipt image(s), App language, selected currency, and an Apple StoreKit transaction credential used to verify Pro access.
- AI quota record: a pseudonymous subscription transaction identifier, date, and daily request count. This does not include receipt or ledger content.
- Advertising configuration: the App bundle identifier and App version, sent to our AWS endpoint to retrieve the current ad policy.
- Support: the content and contact details you provide if you email us.
- Advertising and measurement data: device and advertising identifiers where permitted, IP-derived general location, ad interactions, app events, purchase value, and diagnostics as described in §4 and in each provider’s policy.
2.3 What we do not upload as part of the ledger service
We do not upload your transaction history, budgets, notes, CSV exports, backup files, or locally attached receipts to our backend for storage. We do not sell your ledger content. We do not use receipt images or ledger entries to train an AI model.
Receipt scanning
3.1 Free on-device recognition
The free scan uses Apple Vision on your iPhone. The image is processed locally to detect text and suggest an amount, merchant, category, and date. No image or recognized text is sent to us for this feature.
3.2 Optional Pro AI scanning
If you are a Pro subscriber and AI Scan is enabled, one to three compressed receipt images are sent over an encrypted connection to our backend on Amazon Web Services in the United States (us-west-2). Our backend verifies your active subscription and forwards the images to Google Gemini to generate structured receipt details.
Minine Ledger processes receipt images transiently and does not write them to our server storage. Google processes the submitted images as our AI service provider under its applicable API terms and privacy commitments. A pseudonymous daily quota counter is retained for up to approximately 48 hours. If AI scanning fails or is unavailable, the App falls back to on-device recognition.
A scan result is never entered silently. The App asks you to review and confirm the amount, merchant, category, and date before saving it to your ledger. AI and OCR can make mistakes; verify anything important.
You can turn off AI Scan in Settings at any time. Doing so keeps future receipt recognition on-device.
Advertising and measurement
The free version of Minine Ledger displays ads through Google AdMob. Pro removes ads while the subscription is active. The App also includes Meta App Events to measure app launches, subscription purchases, and advertising performance.
- Google AdMob may process device information, IP address, advertising identifiers, ad impressions, clicks, and diagnostic data to deliver, limit, and measure ads.
- Meta App Events may receive standard app events and purchase or ad-value signals, such as product identifier, price, currency, and impression value. We do not include your transaction entries or receipt contents in these events.
- App Tracking Transparency (ATT): where required, iOS asks for permission before allowing cross-app tracking or access to the advertising identifier. If you decline, the App still works and may show less personalized ads.
You can change tracking permission in iOS Settings → Privacy & Security → Tracking. Ad providers process data under their own privacy policies. Depending on your region, additional consent choices may be presented by them.
Service providers
We use a limited number of providers to operate the features described above. They process data on our behalf or under their own platform terms.
| Provider | Role | Data involved |
|---|---|---|
| Apple | App Store, StoreKit, Vision, Face ID, notifications | Purchase status and platform-level data; on-device OCR content does not go to us |
| Amazon Web Services | AI-scan endpoint, quota counter, ad-policy endpoint | AI request payload, pseudonymous quota data, bundle ID and App version |
| Google Gemini | Pro receipt understanding | Receipt image(s), language, and currency context when AI Scan is used |
| Google AdMob | Advertising | Device, advertising, interaction, and diagnostic data |
| Meta | App-event and ad-value measurement | App events, purchase/ad value, and identifiers where permitted |
We may disclose information where required by law, to protect users and our rights, or as part of a merger, financing, acquisition, or sale of assets, subject to appropriate safeguards.
Storage, exports, and retention
- Local data remains until you delete individual records or uninstall the App. Receipt images use iOS file protection.
- AI receipt images are processed transiently and are not persisted by Minine Ledger on its backend.
- AI quota records expire after approximately 48 hours.
- Support messages are retained as long as needed to respond, maintain appropriate records, and meet legal obligations.
- Advertising and measurement data is retained according to Google’s and Meta’s respective policies.
You can export transactions as CSV or create a complete .minineledger backup that may include financial records, settings, recurring entries, and receipt images. These files are created only at your request and shared to a destination you choose. They are not password-encrypted by the App. You are responsible for storing and sharing them securely.
Before a “Replace” restore, the App may keep up to three local safety backups in its Documents directory. These remain on your device and can be removed through device file management or by uninstalling the App.
Your choices and controls
- Use free on-device OCR and disable Pro AI Scan in Settings.
- Deny or later change camera, notification, Face ID, and tracking permissions in iOS Settings.
- Delete transactions and receipt attachments inside the App.
- Export a CSV or complete backup for portability.
- Delete local App data by uninstalling the App, after exporting anything you wish to keep.
- Manage or cancel Pro through Apple ID → Subscriptions.
For server-side privacy requests, contact [email protected]. Because Minine Ledger has no user accounts and does not store your ledger in the cloud, we may hold little or no data that can be linked back to you. We may ask for information reasonably necessary to verify a request.
Device permissions
| Permission | When requested | Why |
|---|---|---|
| Camera | When you choose to photograph a receipt | Capture the image for local or optional Pro AI recognition |
| Selected photos | When you choose an image with the system photo picker | Scan only the receipt image you select |
| Face ID / device authentication | When you enable App Lock | Restrict access to the App on your device |
| Notifications | When you enable budget alerts | Send local budget-threshold reminders |
| Tracking | During initial setup where applicable | Allow more relevant ads and cross-app ad measurement |
Permissions are optional. Declining one limits only the feature that depends on it.
Regional privacy rights
EEA, United Kingdom, and Switzerland
Where GDPR or similar law applies, our legal bases include performance of a contract (providing requested Pro cloud processing), consent (tracking and permissions where required), and legitimate interests (security, fraud prevention, service operation, and non-personalized measurement). Data used for cloud and advertising features may be processed in the United States. Appropriate provider agreements and transfer safeguards apply where required.
California
California residents may have rights to know, access, correct, delete, and limit certain uses of personal information. We do not sell ledger content. Some advertising activity may be considered “sharing” for cross-context behavioral advertising under California law; denying ATT permission limits advertising-identifier access. Email us to exercise applicable rights.
Mainland China and other regions
If you choose Pro AI scanning, receipt images are transferred to and processed in the United States and by the providers listed in §5. By invoking that optional feature, you direct us to perform this cross-border processing. You can withdraw from future processing by disabling AI Scan. We aim to honor equivalent access, correction, deletion, and objection rights wherever you live.
Security
We use HTTPS/TLS for network requests, minimize AI payloads, authenticate Pro AI requests with StoreKit credentials, apply rate limits, and rely on iOS file protection for local receipt files. App Lock can add Face ID or device-passcode protection.
No storage or transmission method is perfectly secure. If you believe you found a vulnerability, contact [email protected].
Children
Minine Ledger is not directed to children under 13, or the equivalent minimum age in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided information through a network feature, contact us so we can investigate and delete it where applicable.
Changes to this policy
We may update this policy as the App evolves. We will change the effective date above and, for material changes, provide notice in the App, through App Store release notes, or by another reasonable method before the change takes effect where required.
Contact
Minine Inc18952 MacArthur Blvd
Irvine, CA 92612
United States