Last updated: 7 September 2026
This policy covers ColorLedger by mindgameapps. For privacy questions, contact s.m.aliabidy@gmail.com. ColorLedger is being prepared for its first public release. The current preview does not enable cloud sync or remote crash reporting.
Your local salon ledger
Client names and contact details, formulas, quantities, entered costs, revenue, notes, photos and preferences are stored in the app’s private storage on your device. Local formula work does not require an account. Camera or photo-library access is requested when you choose to add a photo. The app re-encodes stored photos to remove unnecessary metadata, including location metadata.
Use photos and client information only with the necessary permission. The Show client view displays visit photos without private notes, formulas or costs. It does not publish a customer portal or sharing link.
Apple subscriptions
When subscriptions are available, Apple processes purchases and payment information through your App Store account. ColorLedger receives verified transaction and subscription status needed to provide Pro, restore purchases and reconcile changes. We do not collect payment-card details.
Apple can also send signed subscription notifications to our verification server hosted by Supabase, even when cloud sync is disabled. The server retains notification identifiers, original subscription transaction identifiers, processing timestamps and status, and a ColorLedger account identifier when Apple supplies one. These records support purchase verification, duplicate prevention and subscription reconciliation. They do not contain your salon records or photos. Raw signed notification payloads are checked for verification and are not stored in these notification records.
The app does not generate or send a ColorLedger account identifier for guest purchases. In a release with account features, signed-in purchases may include that identifier to verify which account owns cloud access. Apple subscription transaction identifiers are separate from a ColorLedger account identifier.
Optional accounts and cloud features
Cloud features are not active in the current preview. In a release that offers them, sign-in uses an email address and verified account identifier through Supabase. Choosing cloud sync uploads your account’s ledger and private photos to Supabase; access is restricted to that account. Account sessions use secure platform storage. A verified subscription controls new cloud writes; an expired subscription does not prevent reading or exporting existing owned records.
Cloud ownership is verified separately from the Apple purchase. A guest purchase does not automatically transfer a subscription or salon records into a different ColorLedger account. Before cloud features launch, the release policy and store disclosures must reflect the enabled services and their actual retention settings.
Diagnostics, reminders and exports
If technical crash reporting is enabled in a release, Sentry receives scrubbed technical errors and app/device information. It is configured without session replay, screenshots, view hierarchy, default personal information or performance tracing. The app contains no advertising tracker and does not sell salon data.
Optional reminders are scheduled on your device and use generic wording without customer names or formulas. Basic CSV/PDF exports go only to destinations you select. Exported files and shared copies are outside the app’s deletion controls. Optional pilot-usage counts remain local and can be cleared or exported from the app.
Retention, deletion and device backups
Local records remain on your device until you remove them or the app. Losing a device or deleting the app can remove unsynced work. iOS device backups are managed through your Apple settings; Android OS backup is disabled for this app. Local storage is protected by the app sandbox and platform controls; we do not claim that the SQLite database is separately encrypted.
For an enabled cloud account, the in-app Delete account action requests removal of account records, private photos and authentication data, then removes the local account ledger. A large or interrupted deletion remains pending until it completes. Individually deleted cloud photos are eligible for cleanup after 30 days; account deletion requests bypass that delay. You control backups and exports held outside ColorLedger separately.
Server subscription-notification records are separate from your local ledger and cloud account records. Removing the app or deleting a ColorLedger account does not automatically erase these notification records. No automatic deletion schedule is currently configured for them; they remain until explicitly removed. Contact us for access or deletion help, and we will verify ownership and explain any applicable retention restriction.
See Delete account and data to request help without reinstalling the app. Deleting ColorLedger data does not cancel an Apple subscription.
Your choices and questions
You can decline optional photo/reminder permissions, export your records, use local logging without an account, and request access, correction or deletion help by contacting s.m.aliabidy@gmail.com. Please do not send customer photos, passwords or verification codes in an initial support email.