Privacy Policy
Last updated: August 27, 2026
Klaro Pte. Ltd. ("we", "us") publishes Klaro Ledger ("the app"). Klaro Ledger is built to keep your financial life private: it works offline-first, and your personal finances stay encrypted on your device. A few optional features — Google Drive backup, and Shared Spaces for tracking with a partner or household — connect to services we or others run; where they do, your financial data is end-to-end encrypted, so we still can't read it. This policy explains what is stored, the network services the app uses, and your choices. We aim to meet Singapore's PDPA, the EU/UK GDPR, and California's CCPA.
Your personal data stays on your device
Everything you enter in your Personal ledger — transactions, income, expenses, savings, goals, budgets, recurring rules, cards & accounts (including any balances you set), categories, notes, and your settings — is stored in an encrypted database on your device only. You can use Klaro with no account at all. We have no server that receives or stores your Personal ledger, and we cannot see it. (The optional Shared Spaces and Google Drive backup features are covered below.)
No advertising or tracking
The app contains no advertising or tracking SDKs, and no analytics that track how you use it. We do not build an advertising or behavioural profile of you, and we do not sell or share your data with anyone. The only diagnostic data that can ever leave your device is optional crash reporting, described next.
Crash & error reporting (optional)
To find and fix bugs and crashes, the app can send anonymous crash and "app not responding" reports to Sentry, a third-party error-monitoring service acting on our behalf. A report contains a technical description of the error (a stack trace) and basic device and operating-system information — never your financial data, transactions, notes, or any personal identifier — and it is encrypted in transit. This is on by default; you can turn it off at any time in Settings → Diagnostics, and when it is off nothing is sent. Sentry's handling of this information is subject to its own privacy policy.
Live prices & exchange rates
To convert between currencies and value any investments you add, the app fetches reference data from a few third-party services: currency exchange rates from Frankfurter (api.frankfurter.dev, based on European Central Bank data); live cryptocurrency prices from CoinGecko; and live stock and ETF prices from Yahoo Finance. When it does, only what the lookup needs is sent — a currency code and date, or the ticker/coin symbols you track (and what you type when searching to add one). Your amounts, quantities, balances, and any personal or account information are never sent. These requests are subject to each provider's own terms, and if a lookup fails or you're offline the app falls back to the last known value or a price you set yourself.
Scanning receipts (camera)
If you use "Scan a receipt", the app uses your camera and reads the photo on your device using Google ML Kit on-device text recognition. The image is processed locally to pull out the total and merchant — it is not uploaded to us or to Google, and it is not saved by the app after the scan.
Automatic capture (notification access)
Automatic capture is optional and off by default. If you turn it on, you grant Android's notification access and choose which of your payment apps (banks, wallets) Klaro should watch. Klaro then reads those notifications on your device to detect a payment's amount and merchant and pre-fill a transaction for you to review and confirm — nothing is ever added without you. All of this happens entirely on your device: notification content is never uploaded, never sent to us, and never shared with anyone. Klaro only acts on notifications that look like payments, and only from the specific apps you switch on; everything else is ignored and nothing about it is stored. Klaro never reads your SMS or text messages. You can turn automatic capture off at any time in Settings, revoke notification access in your Android settings, or mark any app as ignored so it is never read.
Shared Spaces (optional)
Shared Spaces let you track a joint ledger — shared expenses, budgets, goals, and who-owes-whom settle-up — with a partner or household. They are entirely optional: if you never create or join one, nothing here applies and your data never leaves your device. When you create or join a Shared Space, the data in THAT space syncs between its members through a relay we operate (hosted on Cloudflare) using end-to-end encryption. Every change is encrypted on your device before it is sent, with a key shared only between the space's members — delivered inside the invite you share directly with each other, never to us — so the relay stores only encrypted content we cannot read. Your Personal ledger is never synced. To run a space, the relay does handle a little information it can see (not your financial content): a Google account identifier and email for each member (to sign you in and manage membership), the space's name (which is not encrypted, so members can recognise it), membership and roles, timestamps, and whether a member has an active subscription. Combined net worth shares only each member's net-worth total (a single number, still end-to-end encrypted and attributed to them) — the accounts and balances behind it never leave your device. You can leave a space, or delete one you created, from its Manage screen; leaving removes your membership, and deleting removes the space's encrypted content from the relay. Because we cannot read a space's contents, if every member leaves or the shared key is lost, its data cannot be recovered by us.
Subscriptions & billing
Klaro Ledger is a paid subscription app: continued use requires an active subscription (any free trial and the price are shown before you buy). Purchases are made through the Google Play Store, which processes your payment — we never see or store your card or bank details. We use RevenueCat to manage subscription status on our behalf; it receives a pseudonymous identifier linked to your Google account and whether your subscription is active, so the app (and any Shared Space) knows what you're entitled to. Creating a Shared Space requires the space's owner to have an active subscription; people the owner invites can take part in that space. Google Play's and RevenueCat's handling of this information is subject to their own privacy policies. The app contains no ads.
Permissions we use
Camera — only to scan receipts, processed on-device as above. Notification access — only if you turn on automatic capture, to read payment alerts from the apps you choose, processed on your device (you can revoke it anytime). File access — only when you choose to save an export (CSV or PDF statement) to a folder you pick. We do not request location, contacts, microphone, or SMS access.
Exporting & sharing
When you export your data as CSV, or share/save a PDF statement, the file is created on your device and you choose where it goes through your device's own share or file picker. We never receive a copy.
Optional Google Drive backup
Backup never runs unless you choose to connect a Google account — the app offers to set it up when you first start (you can skip it), and you can connect or disconnect anytime in Settings → Backup & restore. When you connect, the app stores an encrypted copy of your data in a private "app data" folder inside your own Google Drive — a space only this app can access — and keeps it up to date as your data changes. We still run no servers and never receive a copy: the backup lives in your Drive, under your Google account, and is encrypted. The app requests only the Drive "app data" permission (drive.appdata), which cannot see any of your other Drive files. You can back up, restore, turn backup off, or disconnect your Google account at any time, and you can delete the backup from your Drive. Signing in is handled by Google; their handling of your Google account is subject to Google's own privacy policy. Klaro Ledger's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Services we rely on
Where the optional features above use a network, these providers are involved, each receiving only the limited information noted: Google — Sign-In (your Google account identifier + email) for Drive backup and Shared Spaces, and Google Drive (an encrypted backup in your own private app-data folder). Cloudflare — hosts our Shared Spaces relay and its database, storing end-to-end-encrypted space content plus the membership metadata described above. Google Play and RevenueCat — process and manage subscription billing status. Frankfurter, CoinGecko, and Yahoo Finance — supply reference exchange rates and live prices, using only a currency code/date or the symbols you track. Sentry — receives optional, anonymous crash and error diagnostics (a stack trace plus device/OS information, and no personal or financial data) when crash reporting is enabled. We use no advertising or tracking SDKs.
Your control and rights
Your Personal ledger lives on your device: view and edit it in the app, export it from Settings → Data, and permanently delete everything from Settings → Delete all data, or by uninstalling. For Shared Spaces, you can leave a space or delete one you created to remove its data from our relay, and disconnect your Google account at any time. Under laws such as the PDPA and GDPR, you can also ask us to access, correct, or delete the limited personal data our relay holds about you (your Google identifier and space membership) — email us and we will action it, usually within 30 days.
Children
Klaro is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect personal data from them. The optional sign-in and Shared Spaces require a Google account, which Google restricts by age. If you believe a child has provided data through these features, contact us and we will help.
Changes to this policy
We may update this policy as the app evolves. We will announce material changes in the app's "What's new" before they take effect, and update the date above.
Contact
Questions or privacy requests? Email [email protected]. We aim to respond within 30 days, as required by PDPA/GDPR.