Effective 17 August 2026 · Last updated 17 August 2026
This policy explains how Fish Ledger (“the app”) handles information. Fish Ledger is published by MS Dev Studio (“we”, “us”). It applies to the Fish Ledger mobile app on Android and iOS.
The short version
Fish Ledger is an offline-first app. The following is created and stored in a database on your device and is not transmitted to us:
This information leaves your phone only when you make it leave: by turning on Google Drive backup, by exporting a PDF or Excel file, or by sharing a receipt.
Fish Ledger relies on your phone's own security — the device lock screen, and the app's optional PIN or fingerprint lock — to protect this database. The database file itself is not separately encrypted at rest. If your device is lost, its lock screen is what stands between a finder and your records, so we recommend keeping one enabled.
Backup to Google Drive is optional and switched off until you connect an account. If you do connect one, you sign in with Google and grant Fish Ledger two permissions.
| Scope | What it is used for |
|---|---|
drive.file |
To create, read, update and delete the backup files that Fish Ledger itself creates in your Drive. This scope gives no access to any other file in your Drive. We cannot see your documents, photos or anything else stored there. |
drive.appdata |
To store the key that encrypts your backups in your Google account's private application data folder. Holding the key with your account is what lets you restore onto a new phone simply by signing in — with no password to remember, and with no copy of the key held by us. This folder is not visible to you or to other apps through the normal Drive interface. |
The app reads your Google account's email address and display name so it can show you which account backups are going to, and warn you if you try to restore a backup made by a different account. This stays on your device.
Before a backup is uploaded, the app encrypts it on your phone using AES-256-GCM, an authenticated encryption scheme. The encrypted file is then placed in your Drive. Because the key lives in your account's private application storage and never with us, a backup cannot be read by us, by Google, or by anyone who obtains the file without your account.
If you enable automatic backups, the app schedules them through your operating system and, by default, only runs them on Wi-Fi. You can change the schedule or turn it off at any time in the app.
Limited Use disclosure
Fish Ledger's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not transfer this data to others except as necessary to provide and improve the app or to comply with applicable law; we do not use it for advertising; we do not sell it; and no humans read it except where required for security purposes, to comply with applicable law, or where you have given explicit consent.
Fish Ledger is licensed per device. Two limited pieces of information therefore reach us:
ANDROID_ID on Android,
identifierForVendor on iOS) by hashing it. It is this hashed
code — not the underlying identifier — that the app displays and that you
send to us when you request a licence key. We store it with your licence
record so the key we issue works only on that phone. The code cannot be
reversed to reveal the original identifier, and it is not used for
advertising, profiling or tracking you across apps or websites.
Alongside these we keep the ordinary commercial record of a licence: your business name, contact details, and which seats were issued and when.
Tapping a customer's phone number opens your phone's dialler. Fish Ledger does not place calls itself and does not read your call history.
Records on your phone stay until you delete them or uninstall the app. Backups stay in your Drive until you delete them. Licence records are kept for as long as the licence is active and afterwards only as long as needed for tax and accounting obligations. Support emails are kept while needed to resolve your question and for a reasonable period afterwards.
Fish Ledger is a business tool intended for adults operating a trading business. It is not directed at children, and we do not knowingly collect information from them.
If this policy changes we will update the date at the top of this page. If a change materially affects how information is handled, we will also give notice in the app before it takes effect.
Questions about this policy, or a request about your information:
support@fishledger.app
MS Dev Studio
Abu Hail, Deira
Dubai, United Arab Emirates