Privacy Policy
Effective 21 August 2026
This policy explains what Ledger ("we", "us") collects when you use the Ledger app and ledgerapp.uk, and how we handle it. We keep it deliberately plain.
1. What we collect
- No account is required. The app currently works without registration. We do not collect your name, email or contact details unless you email us.
- Usage analytics. The app records product events (screens viewed, features used, subscription funnel steps) tied to a random device-generated identifier — not your identity. We use Amplitude and our own infrastructure for this.
- Your bet journal stays on your device. The entries themselves — what you backed, your notes and your running record — are stored only on your phone and are never uploaded. One exception, stated plainly: logging a bet also sends an anonymous product event carrying the stake, the odds and the market you typed, tied to the random device identifier above and to nothing else.
- Preferences such as followed leagues, teams and strategies are stored on your device; anonymous copies of follow/notification choices may be processed server-side to deliver push notifications you request.
- Push tokens. If you enable notifications, we store the token needed to deliver them.
- Device and app details. Our paywall and subscription providers receive standard device information — device model, OS version, app version, language, currency and Apple's per-vendor identifier (IDFV), which is scoped to us and is reset when you delete our apps. Requests to our own servers carry your time-zone offset so kick-off times show in your local time.
- Approximate location. The app has no location permission and never asks for GPS. Your country or region is nonetheless inferred from your connection's IP address by our analytics and paywall providers, and your App Store country reaches our subscription provider along with a purchase.
- Crash diagnostics. If the app crashes we receive a crash report — device model, OS version and where in the code it failed — labelled with the same random device identifier so a crash can be matched to the session that produced it. It carries no journal entries and no contact details.
- Purchases. Subscriptions are processed by Apple. We receive subscription status (e.g. active/expired) — never your card details.
- Server logs. Our infrastructure provider (Cloudflare) processes IP addresses transiently for security, rate limiting and abuse prevention.
2. What we do NOT do
- We do not sell your data.
- We do not take bets or handle your money.
- We do not build gambling-behaviour profiles of identified individuals.
3. Why we process data (legal bases)
We process the data above to run and improve the Service (legitimate interests), to deliver features you request such as notifications (performance of a contract), and where required, with your consent. On iOS, App Tracking Transparency is requested once, shortly after first launch; your answer does not change the analytics described above, which are first-party and anonymous either way. You can use the core app without granting optional permissions.
4. Third parties
We share only what each provider needs to do its job:
- Amplitude — product analytics. Receives the events described above and infers approximate location from the connection IP.
- Cloudflare — hosting and security, and the database holding our own copy of those same product events.
- Apple — payments and notification delivery.
- Expo — turns your device's notification token into one we can send to.
- Firebase Crashlytics (Google) — crash diagnostics. Google also registers an installation identifier and app-session events that Crashlytics depends on.
- RevenueCat — subscription status. Receives your App Store receipt, which products you bought, and your store country and currency.
- Superwall — paywall delivery. Receives which paywall you were shown and standard device details, including the IDFV and your region.
- Sports data providers — match data flows to us; none of your data flows to them.
None of them receives an account, because there is none. The Meta SDK is compiled into the app but is not configured and transmits nothing; if we ever switch it on, we will update this policy first.
5. Retention
Analytics events are retained in aggregate form for product improvement. Crash reports are retained by Firebase Crashlytics under its own standard retention. Device-local data (journal, preferences) lives on your phone and is deleted when you delete the app — the random identifier goes with it, because it is stored inside the app rather than on the device, so a reinstall starts a new one. Server-side push tokens are removed when notifications are disabled or invalid.
6. Your rights
Under UK GDPR you may request access, correction or deletion of personal data we hold, object to processing, or complain to the ICO. Because we hold no account data, most requests concern the device identifier — include it where possible, or simply reset it by reinstalling the app. Contact: support@ledgerapp.uk.
7. Children
The Service is for adults aged 18+. We do not knowingly process data of anyone under 18.
8. Changes
We will post any changes here with a new effective date; material changes will be signposted in the app.