Minine Ledger
PrivacyTermsSupport
Back to website
LEGAL · PRIVACY

Privacy Policy

What Minine Ledger handles, why, where it lives, and the choices you have.

Effective July 24, 2026Version 1.0Minine Ledger for iOS
M
The short version

Your ledger is local-first. Transactions, budgets, receipt attachments, and recurring entries stay on your iPhone. Free receipt recognition runs entirely on-device. A receipt image leaves your device only when a Pro subscriber chooses AI scanning. The free version includes advertising and related measurement SDKs, but we do not send your ledger entries or receipt contents to advertisers.

On this page 01 · Who we are02 · Data we handle03 · Receipt scanning 04 · Ads & measurement05 · Service providers06 · Storage & retention 07 · Your choices08 · Device permissions09 · Regional rights 10 · Security11 · Children12 · Changes13 · Contact
01

Who we are

Minine Ledger (“Minine Ledger,” “we,” “us,” or the “App”) is an iOS personal finance tracking application published by Minine Inc. Minine Inc is the data controller for the information described in this policy.

Minine Inc
18952 MacArthur Blvd
Irvine, CA 92612
United States

Privacy questions and rights requests: [email protected].

02

Data we handle

2.1 Data stored on your device

The following data is created and stored locally in the App’s iOS container:

DataExamplesPurpose
Ledger dataAmount, date, category, income/expense type, note, merchantRecord and display your transactions
Receipt attachmentsImages you capture or select and their file metadataAttach supporting images to entries
Budgets and recurring entriesWeekly/monthly limits, alert settings, recurring rules, pending itemsBudget progress, reminders, and recurring-entry review
PreferencesCurrency, language, appearance, AI scan choice, App Lock settingRemember how you configured the App
Purchase statusLocally cached Pro entitlementKeep Pro features available between StoreKit checks

We do not operate an account system or ledger cloud sync. Your ledger content is not uploaded to Minine Ledger servers except for the specific Pro AI scan flow described in §3.

2.2 Data processed when you use network features

  • Pro AI scanning: compressed receipt image(s), App language, selected currency, and an Apple StoreKit transaction credential used to verify Pro access.
  • AI quota record: a pseudonymous subscription transaction identifier, date, and daily request count. This does not include receipt or ledger content.
  • Advertising configuration: the App bundle identifier and App version, sent to our AWS endpoint to retrieve the current ad policy.
  • Support: the content and contact details you provide if you email us.
  • Advertising and measurement data: device and advertising identifiers where permitted, IP-derived general location, ad interactions, app events, purchase value, and diagnostics as described in §4 and in each provider’s policy.

2.3 What we do not upload as part of the ledger service

We do not upload your transaction history, budgets, notes, CSV exports, backup files, or locally attached receipts to our backend for storage. We do not sell your ledger content. We do not use receipt images or ledger entries to train an AI model.

03

Receipt scanning

3.1 Free on-device recognition

The free scan uses Apple Vision on your iPhone. The image is processed locally to detect text and suggest an amount, merchant, category, and date. No image or recognized text is sent to us for this feature.

3.2 Optional Pro AI scanning

If you are a Pro subscriber and AI Scan is enabled, one to three compressed receipt images are sent over an encrypted connection to our backend on Amazon Web Services in the United States (us-west-2). Our backend verifies your active subscription and forwards the images to Google Gemini to generate structured receipt details.

Minine Ledger processes receipt images transiently and does not write them to our server storage. Google processes the submitted images as our AI service provider under its applicable API terms and privacy commitments. A pseudonymous daily quota counter is retained for up to approximately 48 hours. If AI scanning fails or is unavailable, the App falls back to on-device recognition.

You remain in control.

A scan result is never entered silently. The App asks you to review and confirm the amount, merchant, category, and date before saving it to your ledger. AI and OCR can make mistakes; verify anything important.

You can turn off AI Scan in Settings at any time. Doing so keeps future receipt recognition on-device.

04

Advertising and measurement

The free version of Minine Ledger displays ads through Google AdMob. Pro removes ads while the subscription is active. The App also includes Meta App Events to measure app launches, subscription purchases, and advertising performance.

  • Google AdMob may process device information, IP address, advertising identifiers, ad impressions, clicks, and diagnostic data to deliver, limit, and measure ads.
  • Meta App Events may receive standard app events and purchase or ad-value signals, such as product identifier, price, currency, and impression value. We do not include your transaction entries or receipt contents in these events.
  • App Tracking Transparency (ATT): where required, iOS asks for permission before allowing cross-app tracking or access to the advertising identifier. If you decline, the App still works and may show less personalized ads.

You can change tracking permission in iOS Settings → Privacy & Security → Tracking. Ad providers process data under their own privacy policies. Depending on your region, additional consent choices may be presented by them.

05

Service providers

We use a limited number of providers to operate the features described above. They process data on our behalf or under their own platform terms.

ProviderRoleData involved
AppleApp Store, StoreKit, Vision, Face ID, notificationsPurchase status and platform-level data; on-device OCR content does not go to us
Amazon Web ServicesAI-scan endpoint, quota counter, ad-policy endpointAI request payload, pseudonymous quota data, bundle ID and App version
Google GeminiPro receipt understandingReceipt image(s), language, and currency context when AI Scan is used
Google AdMobAdvertisingDevice, advertising, interaction, and diagnostic data
MetaApp-event and ad-value measurementApp events, purchase/ad value, and identifiers where permitted

We may disclose information where required by law, to protect users and our rights, or as part of a merger, financing, acquisition, or sale of assets, subject to appropriate safeguards.

06

Storage, exports, and retention

  • Local data remains until you delete individual records or uninstall the App. Receipt images use iOS file protection.
  • AI receipt images are processed transiently and are not persisted by Minine Ledger on its backend.
  • AI quota records expire after approximately 48 hours.
  • Support messages are retained as long as needed to respond, maintain appropriate records, and meet legal obligations.
  • Advertising and measurement data is retained according to Google’s and Meta’s respective policies.

You can export transactions as CSV or create a complete .minineledger backup that may include financial records, settings, recurring entries, and receipt images. These files are created only at your request and shared to a destination you choose. They are not password-encrypted by the App. You are responsible for storing and sharing them securely.

Before a “Replace” restore, the App may keep up to three local safety backups in its Documents directory. These remain on your device and can be removed through device file management or by uninstalling the App.

07

Your choices and controls

  • Use free on-device OCR and disable Pro AI Scan in Settings.
  • Deny or later change camera, notification, Face ID, and tracking permissions in iOS Settings.
  • Delete transactions and receipt attachments inside the App.
  • Export a CSV or complete backup for portability.
  • Delete local App data by uninstalling the App, after exporting anything you wish to keep.
  • Manage or cancel Pro through Apple ID → Subscriptions.

For server-side privacy requests, contact [email protected]. Because Minine Ledger has no user accounts and does not store your ledger in the cloud, we may hold little or no data that can be linked back to you. We may ask for information reasonably necessary to verify a request.

08

Device permissions

PermissionWhen requestedWhy
CameraWhen you choose to photograph a receiptCapture the image for local or optional Pro AI recognition
Selected photosWhen you choose an image with the system photo pickerScan only the receipt image you select
Face ID / device authenticationWhen you enable App LockRestrict access to the App on your device
NotificationsWhen you enable budget alertsSend local budget-threshold reminders
TrackingDuring initial setup where applicableAllow more relevant ads and cross-app ad measurement

Permissions are optional. Declining one limits only the feature that depends on it.

09

Regional privacy rights

EEA, United Kingdom, and Switzerland

Where GDPR or similar law applies, our legal bases include performance of a contract (providing requested Pro cloud processing), consent (tracking and permissions where required), and legitimate interests (security, fraud prevention, service operation, and non-personalized measurement). Data used for cloud and advertising features may be processed in the United States. Appropriate provider agreements and transfer safeguards apply where required.

California

California residents may have rights to know, access, correct, delete, and limit certain uses of personal information. We do not sell ledger content. Some advertising activity may be considered “sharing” for cross-context behavioral advertising under California law; denying ATT permission limits advertising-identifier access. Email us to exercise applicable rights.

Mainland China and other regions

If you choose Pro AI scanning, receipt images are transferred to and processed in the United States and by the providers listed in §5. By invoking that optional feature, you direct us to perform this cross-border processing. You can withdraw from future processing by disabling AI Scan. We aim to honor equivalent access, correction, deletion, and objection rights wherever you live.

10

Security

We use HTTPS/TLS for network requests, minimize AI payloads, authenticate Pro AI requests with StoreKit credentials, apply rate limits, and rely on iOS file protection for local receipt files. App Lock can add Face ID or device-passcode protection.

No storage or transmission method is perfectly secure. If you believe you found a vulnerability, contact [email protected].

11

Children

Minine Ledger is not directed to children under 13, or the equivalent minimum age in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided information through a network feature, contact us so we can investigate and delete it where applicable.

12

Changes to this policy

We may update this policy as the App evolves. We will change the effective date above and, for material changes, provide notice in the App, through App Store release notes, or by another reasonable method before the change takes effect where required.

13

Contact

Minine Inc
18952 MacArthur Blvd
Irvine, CA 92612
United States
Privacy requests[email protected] Security reports[email protected] General support[email protected]
© 2026 Minine IncPrivacy · Terms · Support