Skip to content
doorledge

doorledge for iPhone

Privacy

Your ledger lives on your iPhone. The next release uses a small connected service for helper submissions, optional accountant snapshots and purchase verification. This page explains that release, which is still being prepared, and information already shared by earlier connected versions.

Updated September 10, 2026

Which product this covers

DOORLEDGE LLC, a Texas limited liability company, operates the doorledge iPhone app and its connected features. This policy covers the iPhone app, account sign-in, Apple purchase verification, team submissions and accountant snapshots. The new native sign-in and local-ledger workflow is not yet an App Store release.

doorledge is an iPhone app. This website provides help, account connections, team submission forms and private snapshot readers. It is not a browser version of the ledger. Connected features apply only to app versions that include them.

What stays on your phone

The app stores your ledger locally. Receipt scanning and text recognition happen on the device. Signing in or creating a helper link does not upload your ledger. Publishing an accountant snapshot sends the selected records and any originals you choose to include, as described below. Extracted receipt text is not uploaded as a separate snapshot field. Building and land measurements, team phone numbers and booking-calendar links remain local.

When you add a booking-calendar link, the phone requests that calendar directly from its provider. Exports and snapshots leave the app only when you choose to share or publish them. The app you share to then handles that copy under its own privacy practices.

Apple device backups may include local app data, depending on your settings. The team service cannot recover your ledger or receipt originals. The native app contains no advertising or analytics SDK.

Backups you save

Settings → Backup & restore lets you save a complete local backup to Files. It includes original receipts, extracted text, records, property setup, calendar links, helper contact details, private team links and scheduled visits. Account passwords, sign-in tokens, Apple purchases and the app lock are not included. Keep this file private. The storage provider you choose handles the file under its own terms.

A records export is a separate file for reading or sharing. A records export and the team service do not replace a complete backup of your app data and receipt originals.

What the team connection sends

The next version uses Sign in with Apple inside the iPhone app. Apple provides an identity identifier and the email address you choose to share, which may be a private relay address. Supabase Authentication handles the doorledge account and sign-in session. Your Apple password is not shared with doorledge. Earlier email-based accounts remain associated with their existing identity.

Creating a team link sends the helper’s name, the property display name, role and language, together with identifiers used to route submissions to your account. The helper sends a work date, duration, optional note and optional photo. The service records receipt and delivery status so a retry can be handled without adding a duplicate.

We verify Apple-signed purchase information, including product and transaction identifiers, purchase status and renewal or expiry dates, to check connected access. We do not receive your payment-card details.

Team links and photos

A team link includes a member’s name, role, selected property and language. Anyone with that private link can see the member and property name and submit a work date, duration, notes and one photo. It does not expose the host’s financial ledger. New links remain open until you replace or close them. Links created in earlier versions may still have an expiry date.

The form keeps an unfinished draft, including a resized photo, in that browser tab’s session storage so an interrupted submission can be retried. It clears the draft after a confirmed submission; closing the tab also ends that session. The form asks the sender to agree before submitting and does not request GPS. Images are resized and embedded image metadata is removed. The host receives submissions as drafts and may download a photo to the iPhone. Receiving a draft marks it delivered; it does not immediately erase its work details from the service.

Server photos are available to the host for 30 days after submission. The host needs to open doorledge online and receive the photo within that time to save a copy on the iPhone. Routine cleanup deletes server photos after 30 days, including interrupted uploads. A downloaded copy remains on the host’s phone until the host removes it and can be included in a backup or records export. Closing a link stops new submissions; it does not erase earlier work records.

Copies you share with an accountant

In Export → Share with accountant, choose a period and property, preview the selected confirmed records and decide whether to include originals. Publishing sends the selected property names, vendors or people recorded, amounts, rental and personal allocations, categories, mileage, hours, dates, notes, attribution and record identifiers to our service. Original receipts are included only when you select that option.

Original files are preserved, including embedded metadata and any personal purchases, addresses or other information visible on them. Selecting one property does not crop or redact its full receipt. Check the preview and share only information you have permission to disclose.

Anyone holding the private link can read and download the snapshot without an account. It shows the dated copy you published; later edits on the iPhone do not change it. Helpers cannot access it through their team links. The reader removes the private token from the address bar and keeps it in that browser tab’s session storage. Record responses are not browser-cached; downloaded copies remain with the recipient.

A link expires after 90 days or when you close it in Export → Manage shared links. Closing it prevents new access. An original download already opened can finish for up to 60 seconds, and previously downloaded copies cannot be recalled. You can close existing links after your paid access ends.

Closed or expired snapshot contents are removed by routine cleanup, normally within 12 hours. Unfinished uploads expire after 24 hours and are then cleaned up. An upload already in progress may finish after closure and be removed on a later cleanup pass. Minimal link metadata remains for account management until the account is deleted. Provider backups may retain deleted information temporarily under their backup schedules.

Services we use

We use these providers to run the connected service:

  • Supabase handles account sign-in, team links and submissions, purchase verification records, historical connected data and private team-photo and snapshot storage.
  • Vercel serves the website and connection endpoints.
  • Resend handles service emails, including account-deletion confirmation.
  • Short-lived request counters are stored in the existing Supabase database using hashed identifiers. Routine cleanup removes counters older than two days.
  • Sentry receives limited technical error reports from the web service. Request bodies, cookies, user details, breadcrumbs and variable error messages are removed. We do not record browser sessions.

Providers may process IP addresses, request times and other technical information needed to operate and protect the service. Apple handles app purchases. We do not sell your records or use them for advertising tracking.

Keeping and removing data

Helper work details and delivery records remain on the service after receipt on the phone. They are removed when the connected account is deleted. Closing a link stops new submissions; deleting a local record does not delete the service’s submission. Team-photo retention is described above. Provider backups may retain deleted information temporarily under their backup schedules.

You can export saved local records, disconnect the phone, close team or accountant links, or delete your connected account from the app. The website deletion page remains available for existing email-based accounts. Deletion includes the shared doorledge identity and historical web-service data attached to it. Local iPhone records remain until you remove them locally. Deleting an account does not cancel an Apple subscription.

We may retain information needed to meet legal obligations or resolve a billing or security issue. If this prevents us from fulfilling a deletion request, we will explain what remains and why.

Data from earlier connected versions

Earlier connected versions sent a shared copy of structured records: property names and measurements, vendors, amounts, rental and personal allocations, categories, dates, mileage, hours and notes. They also recorded sync times. Receipt originals and extracted receipt text were not part of that upload.

Updating to the new version stops automatic host-ledger uploads; it does not automatically erase historical cloud records. Those records remain associated with the original account and are included when that connected account is deleted. Local records stay on the iPhone.

Questions and requests

Contact doorledgesupport@gmail.com to request access, correction, export or deletion of connected information, or to ask about privacy. Depending on where you live, you may have additional rights to object to processing, restrict it or contact your local data-protection authority.

doorledge is intended for adults managing rental records, not children. If a child’s personal information has been submitted, contact us so we can review and remove it.

We will update the date on this page when the policy changes. Material changes to connected data use will be explained in the app or account flow before they take effect.