EFFECTIVE AUGUST 17, 2026
Privacy policy
How Figure Ledger handles collection records, optional photos, accounts, subscriptions, files, and deletion.
Our privacy approach
Figure Ledger is local-first. Collection records and personal figure photos stay in account-isolated storage on your device. A verified email account and Figure Ledger Pro subscription are optional. We do not enable advertising, behavioral analytics, cloud collection sync, public posting, or remote AI generation in this release.
Information stored locally
You may save figure names, manufacturers, product lines, release years, ownership status, quantity, condition, display or storage labels, notes, and an optional personal photo. These values remain in the app's private local storage and are not transmitted to us.
The bundled catalog contains public product metadata rather than app-user data. It is not presented as complete, official, or manufacturer-endorsed.
Camera and photos
Camera and photo access are requested only after you choose those actions. Both are optional. A selected image is re-encoded to remove source metadata, copied into app-owned local storage, and is not uploaded by this release.
Optional account and subscription data
If you choose to sign in, Supabase processes your email address, authentication events, and secure session. Figure Ledger uses a stable account identifier to isolate local collection storage; it does not use your email as a billing identifier.
If you choose Pro, Apple or Google and RevenueCat process subscription, purchase, trial, restore, cancellation, and entitlement information. The store confirms price and eligibility before purchase. We use this information only to provide and restore Pro access.
Reliability diagnostics
When diagnostic reporting is configured, Sentry receives crash and error details, app version, operating-system version, device model, and a small sample of performance timing. We use these details to find and fix reliability problems. Figure Ledger does not send your collection records, photos, search text, notes, email address, screenshots, session replay, request bodies, or structured logs to Sentry, and default collection of personally identifiable information is disabled.
Backups and imports
A portable JSON backup can contain figure details, notes, and user-entered shelf labels. It excludes photos and device-local photo paths. You choose its destination through the operating-system share sheet. A selected CSV is read and validated locally before any records change.
Retention and deletion
Records remain until you delete a record, erase the active collection, delete your account, clear app storage, or uninstall the app. Erase collection and replacement restore also remove app-owned photo copies; they do not remove your original images.
Account deletion is available in Collector settings. It removes enabled service data, then the verified account, that account's local records, and app-owned photos. Store transaction records may remain where the store, RevenueCat, tax, fraud, or legal rules require retention. Deleting an account does not automatically cancel a store subscription; cancel it in your Apple or Google subscription settings.
We cannot retrieve records that remain only on your device. See the account deletion guide.
Services that are off
Cloud collection sync, ads, behavioral analytics, session replay, remote AI generation, public catalog contributions, and support file uploads are disabled. We will update this policy and store disclosures before enabling a service that changes data collection.
Questions and requests
Email Clueless Creations LLC at eduardo@clueless-creations.com for access, correction, deletion, or another applicable privacy request. Do not include sensitive collection notes or backup files unless support explicitly requests a safe transfer method.