Legal

Privacy Policy

Last updated 15 August 2026

Who this covers

JewelLedger is a private jewelry record book. This policy describes how the website and the Android app (the same web app, opened as a Trusted Web Activity) handle information. A longer, plain-language map of device vs server data is on the privacy architecture page.

On your device only

Item records, photos, valuations, locker details, stories, heirloom notes, reminders, audit history, and price settings live in your browser's IndexedDB. After you set a passphrase, those records are stored encrypted (AES-256-GCM). They are only readable in memory after you unlock with that passphrase. We do not receive that collection data. If you lose the device and have no backup, we cannot restore it. A lost passphrase cannot be recovered.

On the Android app, opening JewelLedger first requires your phone's existing screen lock (PIN, pattern, password, fingerprint, or face). Then you sign in and enter your passphrase before any collection data is decrypted.

Account and server

Sign-in is provided by Clerk. Depending on how you sign in, Clerk may process your email address, phone number, or Google account identifier, plus session cookies. On our Postgres database we store: your Clerk user id, email if present, subscription tier, purchase timestamps and payment ids, vault names and icons, hashed vault PINs, and backup-passphrase metadata (salt, iteration count, and a verifier). The passphrase itself is never sent to us.

Payments

Lifetime Pro on the website is charged through Razorpay. Razorpay receives the payment details you enter in their checkout. We store the order id and payment id so the same payment cannot unlock a second account.

On the Google Play Android app, Google Play Billing processes the same digital unlock as a one-time Lifetime Pro purchase. We store the Play purchase token and order id and verify them with the Google Play Developer API. Pro status is the same account entitlement on the website and Android.

Collection data still never leaves the device except when you start an encrypted Dropbox backup yourself.

Encrypted backup

The same passphrase that unlocks local records also encrypts Dropbox backup files. If you connect Dropbox, OAuth tokens stay on your device. We upload only an encrypted snapshot. Google Drive is reserved behind the same interface and is not active until configured. A lost passphrase cannot be recovered.

Other processors

Live metal prices and FX rates are fetched from third-party market APIs in your browser. Fonts may load from Google Fonts. If an unhandled error occurs in a hosted preview environment, a client error reporter may capture the message and route. We do not run advertising SDKs or sell collection data.

Biometrics

Vault unlock can use the device platform authenticator (fingerprint or face). That biometric data is processed by the operating system. We store only a WebAuthn credential id in localStorage on that device.

Retention and deletion

You can delete your account in Settings. That removes your vault rows and profile from our database and deletes the Clerk user. IndexedDB data on each device should be cleared by signing out / deleting the account on that device. Encrypted files already sitting in Dropbox are yours to delete there.

Children

JewelLedger is not directed at children under 13, and we do not knowingly collect their personal information.

Contact

Use the email on your JewelLedger account, or the developer contact email shown on the Google Play store listing, for privacy questions.