Privacy Policy — Boggling Invoices
Effective 2 August 2026 · Applies to Boggling Invoices for Android and iOS (com.theulloo.boggling_invoices)
We cannot see your data. We could not hand it over if we were asked to, because we do not have it.
What the app stores, and where
Everything you enter — businesses, customers, products, invoices, payments, receipts and settings — is written to a database on your device. That database is encrypted at rest using ChaCha20-Poly1305. The encryption key is generated on your device the first time you open the app and is held in the Android Keystore or the iOS Keychain. The key never leaves your device and we never see it.
Generated invoice and receipt PDFs are written to a temporary cache folder so they can be handed to the app you choose to share with. The app asks before clearing these, and clearing them loses nothing: any PDF is rebuilt from your records on demand.
What the app sends
Nothing.
The app makes no network requests. On Android, the released app declares no permissions at all. There is no advertising, no analytics, no crash reporting, no telemetry, and no third-party SDK that could send anything on our behalf.
This is checked automatically on every build: if an analytics or advertising library were added, or an unexpected server address appeared anywhere in the source, the release build would fail.
Automatic phone backups are switched off
Android and iOS normally copy an app’s data to Google Drive or iCloud on their own. Boggling Invoices switches this off, so no copy of your database is uploaded to either.
This is deliberate, and it is for your benefit as much as your privacy: the encryption key stays in the device keystore and is never included in those backups, so a database restored that way could never be decrypted. Use the app’s own backup instead, which is described below and actually works.
Backups you make yourself
You can export an encrypted backup file from Settings → Backup. You choose a passphrase, and you choose where the file goes — a cloud drive, a computer, an email to yourself, anywhere. The file is encrypted with your passphrase before it leaves the app.
Once you send that file somewhere, it is governed by whatever service you sent it to, not by this policy. Choose a destination you trust.
Sharing invoices
When you share an invoice or receipt, your device’s own share sheet opens and you pick where it goes — email, a messaging app, a printer, a cloud drive. The file goes directly from your device to whatever you chose. It does not pass through us.
What happens to it afterwards is up to the service you selected and its own privacy policy.
Permissions
The released Android app requests no permissions.
Choosing a file to restore from, and sharing a document, both use the system’s own picker and share sheet. These grant the app access to the single file you select, at the moment you select it, and require no standing permission.
Children
The app is a business tool and is not directed at children. It collects no data from anyone, including children.
Your rights
Data protection law gives people rights to access, correct, export and erase personal data held about them. We hold none, so there is nothing for us to disclose or erase.
Your own data stays under your control on your device: you can edit or delete records in the app at any time, export an encrypted backup whenever you like, and remove everything by uninstalling the app, which deletes the app’s data on both Android and iOS.
Changes to this policy
If the app’s behaviour ever changes in a way that affects this policy, the policy will be updated before that version ships, and the effective date above will change.
One change is already planned: an optional check for app updates, which would contact the Google Play or Apple update service and nothing else. It is not built and is not in any released version. If it ships it will be off by default, will be described here, and will appear on the app’s own Network Activity page in Settings before it can be switched on.
Contact
Questions about this policy:
BogglingBrain — support@bogglingbrain.com
bogglingbrain.com