Ledger of DaysPrivacy Policy

Privacy Policy - Ledger of Days

Provider: bee2.io LLC ("bee2.io", "we", "us")

Contact: [email protected]

Canonical page: https://bee2.io/legal/ledgerofdays/privacy

Last updated: 2026-07-21

Ledger of Days is designed so your journal stays on your Mac. This policy states the exact storage, encryption, permission, and sample boundaries.

What we collect

Nothing. Ledger of Days has no account system, analytics, third-party advertising SDK, telemetry, crash reporter, cloud service, or network entitlement. bee2.io LLC does not receive your entries, recordings, photos, passphrase, recovery key, usage history, or purchase details.

Apple processes App Store purchases through StoreKit. We do not receive your payment information.

Where data lives

Journals, structured pack records, and managed attachments live inside the app's sandbox on your Mac. User-chosen exports and .ledgerbackup files live at the destinations you select. There is no cloud sync and no remote copy made by the app.

Journal database encryption

The SQLite database is encrypted at rest with AES-GCM through Apple CryptoKit:

If you enable Touch ID, the data key is also stored in the macOS Keychain with .biometryCurrentSet and WhenUnlockedThisDeviceOnly protection.

Other protected files

Media boundary

Copied photo and audio files under the app's Media directory stay local and are protected by the macOS app sandbox. They are not individually AES-GCM encrypted. Attachment metadata and transcripts are stored in the encrypted database.

Plain Markdown, PDF, EPUB, CSV, and media exports are intentionally readable. Encrypted backup files remain encrypted until opened with the recovery key.

Permissions

Automated fixtures and all free IAP samples block real recording and file reads, so they never trigger microphone, speech, file, or notification permission.

Interactive samples

A sample uses synthetic data in a separate temporary container and never opens the production journal. Each pack has a small independent action budget. Sample output stays in temporary storage and the container is removed when the sample closes.

Backups, recovery, and deletion

There is no cloud backup or passphrase recovery. If you lose the journal passphrase and cannot use an enrolled Touch ID key, the database cannot be recovered by you or by us. Private-journal passphrases are independent. Keep the printable backup recovery key somewhere safe.

Delete all data removes the app-managed database content, media files, private vault files, and temporary managed outputs, then leaves an empty starter journal. It does not delete exports or backups that you saved outside the app.

Secure erasure on flash storage cannot be guaranteed by macOS. Removal of the unlocked working database is best-effort; durable locked-state protection comes from the encrypted store.

Contact

Questions: [email protected] (bee2.io LLC).

No advertising and no promotional messaging

This Mac app contains no advertising of any kind: no ad SDK, no banner or full-window promotional message, no interstitial, no cross-app identifier, no tracking, no targeting, and no personal profile. Optional one-time packs are presented only in the app's own Packs section, which you open yourself, and on a locked workspace you have chosen to visit.