Legal
Privacy Policy
Effective 28 July 2026
1. Operator and contact
Joashdev operates the official Lootr project from the Philippines. Joashdev controls the limited online data that this policy describes.
Joashdev also acts as the privacy owner and data protection contact for V1. Independent Lootr forks control their own data practices.
To send a private request, use the private contact form. Start the title with “Privacy request.”
Do not attach identity documents, financial records, backups, receipts, or passwords. The operator will reply through the private GitHub thread.
2. Scope
This policy covers official Lootr V1 alpha releases, the Lootr website, and the optional feedback service.
V1 has no Lootr account or cloud ledger. V1 also has no advertising or automatic analytics.
V2 can add accounts, sync, backup, and household sharing. Before V2 starts, Lootr will publish a new policy and an in-app notice.
3. Data on your device
Lootr can store these data categories on your device:
- Accounts, balances, transactions, transfers, and budgets.
- Goals, debts, recurring items, payees, categories, and notes.
- Imported data and migration records.
- Receipt images and text that Lootr extracts from them.
- Notification schedules and app settings.
- Local OCR, parsing, AI, and diagnostic logs.
Lootr uses this data to give you the features that you request. The V1 app does not automatically send this ledger data to Joashdev.
You can edit or delete individual records in Lootr. You can also export transactions and make an encrypted Lootr backup.
To delete all V1 app data, uninstall Lootr or clear its storage in your device settings. This action does not delete your external copies.
Android excludes Lootr app data from operating-system backup. On iOS, encrypted app data can enter an iCloud or device backup under your Apple backup settings. Apple controls that backup under its terms.
4. Optional online features
Public feedback
If you select Send feedback, Lootr shows the complete report before it sends the report.
The report can contain a title, description, report type, app version, build number, platform, and optional diagnostics.
GitHub publishes the approved report as a public issue. Search engines, caches, forks, and notifications can copy the report.
Feedback screenshots
Lootr sends a screenshot only when you select it and approve it separately. Lootr removes the source metadata before upload.
Cloudflare R2 stores the image and gives it a hard-to-guess public link. Screenshot upload must stay off unless the storage lifecycle deletes the image after 30 days.
Human verification
Cloudflare Turnstile checks that a person sent the report. Cloudflare can process an IP address, device data, browser data, and security signals.
The Lootr relay does not add this data to the GitHub issue. It does not log report text, screenshots, tokens, attachment keys, or IP addresses.
Voice input
Voice input is optional. Lootr sends audio to the speech service that your operating system provides or selects.
Your provider can process the audio on your device or on its servers. This behavior depends on your device, language, provider, and settings.
Review your provider's privacy settings before you speak sensitive information.
Website and downloads
The static Lootr website has no ads or behavior analytics. Cloudflare processes request data to deliver and protect the website.
Request data can include an IP address, time, requested path, device data, and security signals. GitHub processes data when you use GitHub pages.
5. Permissions
- Camera: Scan a receipt that you select.
- Photos: Select a receipt or feedback screenshot.
- Microphone: Record voice input after you tap the microphone.
- Speech recognition: Convert your voice input to text.
- Notifications: Schedule reminders that you configure.
- Network: Open links and send feedback that you approve.
You can deny or remove an optional permission in your device settings. Manual ledger entry remains available.
6. Purpose and legal basis
| Activity | Purpose | Basis |
|---|---|---|
| Local ledger | Give the feature that you request | Not operator processing. Joashdev does not receive this data. |
| Public feedback | Publish and review your report | Your clear consent |
| Feedback screenshot | Publish the image with your report | Your separate consent |
| Turnstile and relay logs | Prevent abuse and protect the service | Legitimate security interest |
| Website and download requests | Deliver and protect the service that you request | Legitimate service and security interests |
| Voice input | Convert speech to text | Your deliberate request and consent |
| Privacy and legal requests | Answer your request and keep required records | Legal duty and legitimate claim-management interest |
If consent applies, you can withdraw it before future processing. A withdrawal cannot remove copies that other people made from a public issue.
7. Recipients and international processing
Lootr does not sell personal data. Lootr does not share personal data for targeted advertising.
Lootr uses Cloudflare for website hosting, Turnstile, the feedback relay, and temporary screenshot storage.
Lootr uses GitHub for public issues, source code, and releases. Your operating-system provider controls its speech service.
Cloudflare and GitHub use global systems. They can process data in the United States and other countries where they or their providers operate.
Cloudflare describes its safeguards in its Data Processing Addendum. GitHub describes its transfers in its Privacy Statement.
GitHub can control data when you use GitHub directly. Your speech provider controls its own service. Its privacy terms and transfer safeguards apply.
Apple can process an encrypted iOS device backup under your Apple settings and its privacy terms.
Use the private contact in section 1 to request available information about safeguards for Lootr-controlled processing.
8. Retention and deletion
| Data | Retention | Control |
|---|---|---|
| Local ledger | Until you delete the record or app data | You control the device copy |
| Local diagnostics | Seven days with a 512 KiB limit | You choose whether to publish them |
| R2 screenshot | Until the configured storage lifecycle deletes it | Screenshot upload must stay off unless that lifecycle is 30 days |
| Worker logs | Cloudflare plan and account settings control the period | Logs exclude report content and IP addresses |
| Cloudflare Pages and Turnstile request data | Cloudflare sets the period under its service settings and policy | See Cloudflare's Privacy Policy |
| GitHub issue | Indefinite public project history | You can request correction or removal |
| GitHub release, page, and account metadata | GitHub sets the period under its account and legal rules | See GitHub's Privacy Statement |
| Private privacy request | Until the request closes, then as required for legal records | You can request deletion when no legal duty requires retention |
| Speech data | Your speech provider sets the period | Use your device settings and provider controls |
| Encrypted iOS device backup | Your Apple backup settings and Apple's rules set the period | Use your Apple backup controls |
GitHub notifications, caches, forks, and archives can keep copies after Lootr changes or removes an issue.
Read Cloudflare's Privacy Policy and GitHub's Privacy Statement for their retention rules.
9. Security
Production builds use an encrypted local database and operating-system secure storage. Online requests use transport encryption.
Lootr also uses bounded diagnostics, report preview, consent controls, rate limits, and restricted service credentials.
No security control removes all risk. Keep a separate backup of important records.
10. Your rights
Depending on your location, you can request access, correction, erasure, restriction, objection, or a portable copy of data that Joashdev controls.
You can also withdraw consent and file a complaint. Send a private request through the contact in section 1.
Joashdev will answer a complete request without undue delay. For Philippine requests, the target response period is 30 working days.
If required, Joashdev can extend this period by 15 working days. Joashdev will tell you the reason before the first period ends.
You can also file a complaint with the Philippine National Privacy Commission.
11. Automated decisions
V1 does not make an automated decision that has a legal or similar significant effect.
OCR, parsing, and AI features make suggestions only. You control each financial record and decision.
12. Children
Lootr is for adults who are at least 18 years old. Lootr does not direct its online features to children.
If a child sends personal data, a parent or guardian can contact Joashdev and request deletion.
13. Policy changes
Lootr will change this policy when its data practices change. The date above identifies this version.
Lootr will announce a material change in the app or release notes before the new processing starts.