PlaceLedger Privacy Policy
PlaceLedger is designed as a local-first rental documentation app. Move-in and move-out reports, notes, photos, generated PDFs, and app preferences remain on the user's device. Optional verified handoffs use a report-content-free service for identity, delivery, response status, and public verification. Purchase validation and limited diagnostics use the services described below.
Summary
PlaceLedger does not require an account for local reports and does not upload report content, photos, notes, signatures, addresses, or PDFs to a PlaceLedger server. Verified handoffs are optional and use email-code identity only when a user chooses that feature. PlaceLedger is developed by Vellumstead Labs LLC under the public developer brand Vellumstead Labs.
Information Stored On Device
PlaceLedger stores information the user enters or adds to a report, including:
- Property label and flexible address details.
- Report type, such as move-in or move-out.
- Move-in or move-out report date.
- Linked move-in baseline reference when a move-out report is created from a move-in report.
- Optional tenant name.
- Report, room, and checklist item notes.
- Checklist item condition/status.
- Photos captured with the camera or imported from the photo library.
- Signer acknowledgement names, roles, timestamps, and optional drawn signatures.
- Photo metadata needed by the app, such as source, timestamp, dimensions, file name, file type, local file path, and optional GPS stamp if the user turns it on for a camera photo.
- Generated PDF exports and cached PDF files.
- App preferences, including date format and default PDF page size.
- Purchase/unlock state needed to manage report unlocks, lifetime unlock status, and local entitlement state.
Report readiness checks and the in-app “Proof summary” are computed locally from report data. They are not sent to a PlaceLedger server.
Camera And Photo Library Access
PlaceLedger asks for camera access so users can take documentation photos for a report. PlaceLedger asks for photo library access so users can import existing photos into a report.
Photos selected or captured in PlaceLedger are copied into app-controlled local storage on the device. PlaceLedger does not upload these photos to a PlaceLedger server in the current app build.
Location
PlaceLedger can add an optional GPS stamp to camera photos when the user turns GPS stamps on in the camera. PlaceLedger requests location permission only for this user-controlled feature. GPS stamps are stored locally with the related photo and may appear in generated PDF exports if the user previews or shares a report.
PlaceLedger does not request location in the background and does not send GPS stamps to a PlaceLedger server.
Sharing And Exports
Users can generate and preview PDF reports locally. Users can share generated PDF reports using the device's native share sheet. When a user shares a PDF, the destination app or service chosen by the user may process that file under its own privacy policy.
Optional Verified Handoffs
A user may choose to register a passwordless handoff identity, send an invitation, and let a recipient record a bounded response without installing PlaceLedger. The service processes encrypted sender and recipient email addresses, email-code challenges, delivery status, scoped session credentials, recipient role and response status, optional encrypted response text, an opaque share-revision reference, locked fingerprint, finalization time, and signed verification metadata needed to operate that feature.
PlaceLedger does not upload the report PDF, report name, property address, room or item descriptions, notes, photos, signatures, or GPS stamps for a verified handoff. The public verifier exposes only a privacy-minimal signed status record. Invitation links and session credentials are private and should not be forwarded or sent to support.
Optional Usage Measurement
First-party usage measurement is off by default. If a user enables it, PlaceLedger may send a random installation identifier and a small allowlist of milestones, such as onboarding completion, report creation, PDF export, handoff completion, or purchase outcome. These events do not include report identifiers, fingerprints, addresses, email addresses, report content, photos, notes, signatures, GPS coordinates, store transaction identifiers, or recipient response text. The setting can be turned off in PlaceLedger settings.
Purchases And Paid Unlocks
PlaceLedger offers a one-report unlock and a lifetime unlock. Apple App Store or Google Play processes the purchase. Current options and local storefront pricing are shown in the app.
PlaceLedger uses RevenueCat for purchase validation, entitlement status, and restore support while keeping report content local-only. RevenueCat may process app user identifiers, device or store identifiers, product identifiers, entitlement status, transaction history, and store-account purchase information needed to validate purchases and restore access. Reports, photos, notes, addresses, signatures, and PDFs are not sent to RevenueCat by PlaceLedger.
Local Use Without An Account
Creating and exporting local reports does not require an account or email address. A user provides an email address only when choosing a verified handoff. Sender and recipient access then uses short-lived email-code verification and scoped sessions; PlaceLedger does not use passwords.
Crash Diagnostics, No Advertising
PlaceLedger does not include advertising SDKs, targeted advertising, or third-party tracking. PlaceLedger includes Sentry for crash diagnostics so Vellumstead Labs can detect and fix app errors.
Sentry may process crash logs, device and operating-system details, app version, route or screen names, and other diagnostic details needed to troubleshoot crashes. Sentry is configured for crash diagnostics; session replay, performance profiling, and product analytics are not used. Report contents, photos, notes, signatures, PDFs, exact addresses, and exact GPS coordinates should not be sent to Sentry by PlaceLedger.
Service Providers And Retention
Depending on enabled features, PlaceLedger uses Cloudflare for the report-content-free handoff API, recipient and verifier pages, databases, rate limits, and first-party aggregate analytics; Resend for challenge and invitation email; Sentry for limited crash diagnostics; RevenueCat for entitlement validation; and Apple or Google for purchases and app distribution.
Current engineering maximums are 24 hours for challenge and access-token data, 30 days for active refresh-token state and delivery identifiers, 90 days after a terminal event for encrypted recipient contact and optional response text, 7 days for redacted service logs, 30 days for raw opt-in analytics and Sentry events, and up to 7 years for non-identifying handoff and certificate integrity records unless verified deletion withdraws them. The published retention period is subject to final legal and jurisdiction review before the handoff capability is enabled in production.
Data Deletion
Report data is stored locally on the device. Users can delete individual reports in the app; PlaceLedger also attempts to remove the deleted report's local photos and cached PDFs from app storage. Users can remove all local app data by deleting the app from their device or clearing app storage in the operating system.
A signed-in sender can open Settings, Privacy controls, and Remote handoff data to review the impact and request deletion with a fresh email code. A verified recipient can use Delete my handoff data in the recipient page. These controls revoke scoped sessions, remove or cryptographically erase remote contact, delivery, and optional response data, and return a content-free receipt. Recipient deletion also withdraws that recipient's recorded response, deletes the related response certificate, and recomputes the privacy-minimal public revision state. Local reports, backups, exported files, and copies already shared are not removed by a service request.
Contact
PlaceLedger support is available through the support page or by email at [email protected].