Privacy Policy
Last Updated: September 9, 2026
Ignitte (“we”, “our”, or “us”) provides an on-device double-entry ledger and continuous financial operating system for small businesses, solo operators, and personal cash flow management. We are committed to uncompromising data privacy, deterministic on-device intelligence, and zero-knowledge encryption.
Ignitte is operated from New South Wales, Australia.
1. On-Device Architecture & Deterministic Invariants
Unlike legacy cloud accounting platforms that stream unencrypted financial receipts and invoices to multi-tenant public AI cloud servers:
- Deterministic Integer-Cent Math: Every balance, tax provision, and ledger calculation is performed in native Swift code using integer cents. No AI language model ever calculates, touches, or commits numbers directly.
- 3-Tier On-Device Intelligence: Ignitte processes natural language and receipts locally using Apple Intelligence (where supported), an optional on-device Gemma 4 E2B model backstop, and a deterministic Swift parser floor. Third-party apps access Apple Intelligence strictly on-device; Apple's Private Cloud Compute is not exposed to third parties, so your figures never reach Apple servers.
- On-Device Apple Vision OCR: Receipt scanning (
VNRecognizeTextRequest) and audio transcript parsing execute exclusively inside your iPhone sandbox. - Proposal-First Confirmation: AI acts solely as a classifier to generate a
LedgerMutationProposal. Nothing is written to the append-only ledger without your explicit confirmation. - Zero Server Inference & Zero Model Training: Our Cloudflare Worker backend contains strictly zero inference endpoints. Your private books, receipts, and financial positions are never sent to cloud servers for AI processing and never used to train foundation models.
2. Apple Privacy Manifest & API Declarations
In accordance with Apple App Store Review Guidelines and Privacy Manifest requirements:
NSPrivacyAccessedAPICategoryUserDefaults
Declared Reason: CA92.1 — Used exclusively to persist local user preferences (such as selected tax country, active currency display, and theme modes) within the local application sandbox. Not used for tracking across different apps or websites.
3. Zero-Knowledge End-to-End Encryption (AES-GCM-256)
When secure cloud backup or multi-device synchronization is enabled:
- Client-Side Encryption: All ledger entries and receipt records are encrypted on your iPhone using industry-standard AES-GCM-256 before transmission. Plaintext ledger payloads are rejected outright with HTTP 400.
- iCloud Keychain Keys: Encryption keys are generated and stored in your private Apple iCloud Keychain (
kSecAttrSynchronizable = true). Automatic cross-device sync and backup recovery require iCloud Keychain to be enabled on your Apple ID. - Cloudflare D1 Zero-Knowledge Storage: Backups stored on Cloudflare D1 databases are sealed cryptographic blobs. Our servers and database administrators cannot read, inspect, or reconstruct your financial records.
- No Data Monetization: We do not sell, rent, broker, or share financial data with advertisers, aggregators, or credit rating bureaus.
4. Information We Collect & Sync Metadata
We collect and process only the minimum required information to provide the application service:
- Encrypted Ledger Backups: Client-encrypted database payloads (unreadable by Ignitte).
- Sync & Operational Metadata: To coordinate multi-device synchronization and prevent merge conflicts, our sync worker stores standard operational metadata alongside ciphertext blobs: account identifier (
user_id), business identifier (business_id), device identifier (last_device_id), sync timestamps, and version counts. - Zero AI Transmission: Nothing is sent to external servers for AI inference. Voice processing, receipt extraction, categorization, and conversational assistance execute 100% locally on your device.
- Account Identity: Email address for TestFlight invitation, authentication, and subscription status.
- Diagnostic Logs: Anonymized crash logs and app lifecycle diagnostics to ensure stability and performance.
5. Data Portability & Deletion
You maintain sovereign ownership of all financial data:
- Export your complete ledger anytime as standard CSV, audit-ready PDF, or open backup files.
- Trigger instant irreversible deletion of your account and encrypted cloud blobs directly from app settings or by contacting our team.
6. Contact Information
If you have any questions regarding this Privacy Policy, your encryption architecture, or data rights:
Ignitte Privacy Officer & Support
Email: supportignitte@gmail.com
Jurisdiction: New South Wales, Australia
Help Desk: Support Page & Inquiries
Website: https://ignitte.app
