Privacy Policy — Boggling Invoices
Effective 4 September 2026 · Applies to Boggling Invoices for Android (com.bogglingbrain.bogglinginvoices)
We cannot see your data. We could not hand it over if we were asked to, because we do not have it.
What the app stores, and where
Everything you enter — businesses, customers, products, invoices, payments, receipts and settings — is written to a database on your device. That database is encrypted at rest using ChaCha20-Poly1305. The encryption key is generated on your device the first time you open the app and is held in the Android Keystore. The key never leaves your device and we never see it.
Generated invoice and receipt PDFs are written to a temporary cache folder so they can be handed to the app you choose to share with. The app asks before clearing these, and clearing them loses nothing: any PDF is rebuilt from your records on demand.
What the app sends
Nothing about you, and nothing about your work.
Your invoices, customers, products and figures never leave this device. There is no advertising, no analytics, no crash reporting, no telemetry, and no third-party SDK that could send anything on our behalf. We run no server that this app talks to, so there is nowhere for your records to go.
Two things reach Google, and only Google:
- Checking for a newer version. When the app starts, it asks the Google Play Store app already on your phone whether a newer version of Boggling Invoices exists, so that a fix reaches you without you having to go looking for it. The app opens no connection of its own — it hands the question to the Play Store, which answers from the Play account already signed in on your phone. Nothing about you or your records is included in the question. You can switch this off under Settings → Check for updates, and updating through the Play Store yourself works exactly as before.
- Unlocking a second business, which is a one-time Google Play purchase. That contacts Play only at the moment you tap to buy or restore it. Google’s own purchase library brings its own internal diagnostics for that one feature; we do not add it, configure it, or see anything it sends.
That is the entire list, and both are described in the app itself underSettings → Network activity.
This is checked automatically on every build: if an analytics or advertising library were added, or an unexpected server address appeared anywhere in the source, the release build would fail.
Automatic phone backups are switched off
Android normally copies an app’s data to Google Drive on its own. Boggling Invoices switches this off, so no copy of your database is uploaded there.
This is deliberate, and it is for your benefit as much as your privacy: the encryption key stays in the device keystore and is never included in those backups, so a database restored that way could never be decrypted. Use the app’s own backup instead, which is described below and actually works.
Backups you make yourself
You can export an encrypted backup file from Settings → Backup. You choose a passphrase, and you choose where the file goes — a cloud drive, a computer, an email to yourself, anywhere. The file is encrypted with your passphrase before it leaves the app.
Once you send that file somewhere, it is governed by whatever service you sent it to, not by this policy. Choose a destination you trust.
Sharing invoices
When you share an invoice or receipt, your device’s own share sheet opens and you pick where it goes — email, a messaging app, a printer, a cloud drive. The file goes directly from your device to whatever you chose. It does not pass through us.
What happens to it afterwards is up to the service you selected and its own privacy policy.
Permissions
The app never asks you to approve a permission — no storage, no camera, no contacts, no location. Nothing in it will ever show you a permission prompt.
Its installed manifest declares four install-time entries. None is a permission Android asks you to grant, and none gives the app access to anything on your phone:
INTERNETandACCESS_NETWORK_STATE, required by Google’s own billing and update libraries. They are what allow the two Google interactions described above. Nothing else in the app uses them, and the app contains no code that fetches anything from any address.com.android.vending.BILLING, which exists solely to complete the one-time purchase that unlocks a second business.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION, generated by an Android support library, scoped to this app alone, and present so that other apps cannot reach an internal component. It grants access to nothing.
Choosing a file to restore from, and sharing a document, both use the system’s own picker and share sheet. These grant the app access to the single file you select, at the moment you select it, and require no standing permission.
Children
The app is a business tool and is not directed at children. It collects no data from anyone, including children.
Your rights
Data protection law gives people rights to access, correct, export and erase personal data held about them. We hold none, so there is nothing for us to disclose or erase.
Your own data stays under your control on your device: you can edit or delete records in the app at any time, export an encrypted backup whenever you like, and remove everything by uninstalling the app, which deletes the app’s data.
Changes to this policy
If the app’s behaviour ever changes in a way that affects this policy, the policy will be updated and the effective date above will change.
An earlier version of this policy listed the update check as planned, unbuilt, and intended to be off by default. It shipped in version 1.4.0 (build 15) and is on by default, and this policy has been corrected to describe what the app actually does. The reasoning for that default is set out on the app’s own Network activity page, alongside the switch that turns it off.
Contact
Questions about this policy:
BogglingBrain — support@bogglingbrain.com
bogglingbrain.com
