HearthLedgerPublished by Black and Blue

Privacy policy

How HearthLedger handles household records, SDK technical data and purchases — and how to remove your data.

Black and Blue · Privacy contact
Website: hearthledger.blackandblue.co.in

Effective date: 3 October 2026.

HearthLedger helps adults aged 18 and over organize household insurance, warranties, receipts, appliances and incident evidence. It does not assess coverage, sell insurance or submit claims to insurers. It is not intended for children. This audience statement does not establish an age-verification or parental-consent service.

Your household records

Home names, document titles, policy and serial references, amounts, dates, notes, chosen images/PDFs, recognized text and incident details are stored in encrypted app-private storage on your device. HearthLedger does not send household document contents to Black and Blue, Firebase or RevenueCat. You choose files through Android's file picker; the app does not request broad storage or photo-library access.

Device authentication uses Android's system prompt or screen-lock confirmation. It does not protect against every device compromise. Local records are excluded from Android's ordinary cloud backup and device-transfer mechanisms. Keep a portable backup before uninstalling or changing devices.

Text recognition and Google ML Kit

Text recognition uses the bundled Google ML Kit model on your device. Google states that ML Kit does not send recognition input images/text or resulting recognized text to its servers. You review suggestions before saving them.

ML Kit separately processes technical app/device information, per-installation identifiers, feature events, errors, performance measurements and input/output sizes for diagnostics and usage analysis. Its APIs may contact Google for maintenance or compatibility information. These technical records are distinct from document contents. HearthLedger's Firebase analytics and local-crash switches do not control ML Kit's technical-data handling. The app includes an ML Kit startup provider; avoiding recognition or leaving Firebase choices off is not a guarantee of no SDK initialization or traffic. See Google's ML Kit privacy explanation and data disclosure.

Exports and backups

Claim PDFs and ZIPs contain readable records and are not password protected. Android saves them to your chosen destination, which may be an external provider. Review the contents and recipient before sharing. Portable backups require your chosen password; Black and Blue cannot recover it. Copies saved outside the app remain there after local ledger deletion.

Optional Firebase analytics and local crash reports

Usage analytics and local crash capture are separate choices and start off each app process. Saved positive choices need a new choice after restart. Declining them does not block manual household record features. Analytics can send broad app-action categories, app/device information, interactions, app-instance identifiers and approximate location derived from network information to Google/Firebase. Custom events do not include household document text or OCR output. Advertising-ID collection and advertising-personalization signals are disabled in the app configuration.

Local crash capture can process technical crash traces, device/app details and installation identifiers. HearthLedger prepares manual-report mode before its Firebase entry paths and requests automatic report upload to remain off. If compatibility checks or storage writes fail, those guarded paths do not grant SDK access. This does not recall earlier transmissions or guarantee silence from every SDK.

Pending-report management has a separate disclosure and check. Checking may initialize local crash capture until the process ends even if its switch is off. For an available batch, Send queues one request, Delete requests local batch deletion, and Not now leaves the batch undecided. Delivery and completed deletion are not confirmed by these calls; a queued Send cannot be recalled. Neither consent switch explicitly sends or deletes a batch. Turning capture off closes app-originated diagnostic calls, but an initialized crash handler may continue local capture until process death. Turning analytics off requests collection disablement and local identifier reset. These controls do not erase provider data already received.

Purchases

Google Play and RevenueCat process purchase verification, restoration and Pro access. RevenueCat uses an anonymous app customer identifier and purchase/product/transaction information. Its purchase-history processing supports app functionality and analytics. Billing may contact its services to load products or check access while optional Firebase choices are off. HearthLedger does not receive payment card details. Settings displays the actual purchase support identifier for relevant support or deletion requests. Restoring a purchase can associate store transactions with a customer identifier again.

Reminders and service providers

Expiry notifications are optional and use generic text rather than document names. Notification denial does not prevent viewing dates. Network permission supports the configured SDKs and purchase services. Providers include Google ML Kit, Google/Firebase, Google Play and RevenueCat. Provider processing may occur outside your country. Google's privacy policy and RevenueCat's privacy policy explain their practices.

The app uses encrypted local storage and disallows cleartext network traffic in its Android configuration. Google documents HTTPS for Firebase and ML Kit technical data; RevenueCat documents encryption in transit. These measures do not secure readable exports after you save or share them.

Retention and deletion

Local records stay until you delete individual records, choose Settings → Delete all local data and type DELETE, or uninstall. Read the app's result for any reported failure. Ledger deletion does not clear telemetry choices, SDK identifiers or pending local crash reports, refund purchases, delete provider records, or remove saved exports/backups. Use the separate report controls to request deletion of an available local crash batch.

Google Analytics retention depends on the property's settings and type of data; aggregated reports have separate treatment. Google explains its retention controls. For received crash reports, Firebase states that crash traces and associated identifiers are retained for 90 days before removal from live and backup systems begins; removal is not promised to finish on day 90. RevenueCat does not state a fixed app-specific retention period in its public policy. Deleting a RevenueCat customer does not erase Google Play transactions or prevent a later purchase restoration from establishing another association.

HearthLedger has no sign-in account or cloud document account to close. For requests to access, correct or delete remotely held information, email developer@blackandblue.co.in with the app name and purchase support identifier when relevant. Do not attach household records, passwords, payment details or review codes. We need to identify the applicable provider records and request scope; shared-project purchase associations must be scoped before action. No fixed remote-erasure deadline is promised. Removing the local ledger alone does not identify or delete an anonymous provider record.

Audience, contact and changes

HearthLedger is intended for adults aged 18 and over. If you believe a child has provided personal information, contact Black and Blue without attaching household records. For privacy questions, use developer@blackandblue.co.in. We will update this page and its effective date when practices change.

Contact Black and Blue

For HearthLedger help or privacy requests, email us with the app name and a short description. Include the purchase support identifier from Settings when relevant. Do not attach household documents, payment card details, passwords or review access codes.

developer@blackandblue.co.in