Legal · Products · LedgerOS
LedgerOS Privacy Policy
Last reviewed: 27 May 2026 · Effective: 27 May 2026
LedgerOS is an Android application developed and operated by NextWave (“we”, “us”, “our”), an Australian business. LedgerOS helps sole traders and small businesses track receipts, prepare Business Activity Statements (BAS), and manage GST compliance.
This policy explains what personal and business information LedgerOS collects, how it is used and stored, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using the app, you agree to the practices described here.
1. What information LedgerOS collects
Account information
- Email address and password — used to create and authenticate your account via Supabase Auth (encrypted at rest and in transit)
Business and financial records
- Business details — business name, ABN, GST registration status, entity type, BAS lodgement frequency, and country/jurisdiction
- Receipts — merchant name, date, total amount, GST component, expense category, and any notes you enter
- Receipt images — photos you capture or import. Images are uploaded to Supabase Storage and linked to your account
- Bank transactions — records imported via CSV or PDF bank statement upload. LedgerOS never connects directly to your bank
- BAS and compliance data — tax period summaries, task statuses, and lodgement notes you create in the app
Device permissions
- Camera — used solely to photograph receipts when you tap the camera button. Photos are never taken automatically and are never used for any purpose other than receipt capture
- Notification permission — used only to send BAS deadline reminders on Android 13 and above. You can revoke this permission in your device settings at any time
- Storage / media access — used only when you choose to import an image from your photo library or a CSV/PDF from your device files
AI-processed content
- When you scan a receipt, the extracted text (merchant name, date, totals) may be sent to OpenRouter (routing to Google Gemma) to assist with field recognition. Raw receipt images are not sent to AI providers — only the OCR text extracted on-device is transmitted. Do not scan documents containing sensitive personal information unrelated to business expenses
- BAS review summaries and transaction categorisation suggestions use the same AI pipeline. Only de-identified financial totals and category labels are transmitted
2. How we use your information
We use the information described above to:
- Provide and maintain the LedgerOS app and sync your records across devices
- Enable BAS preparation, receipt management, and compliance task tracking
- Send BAS deadline push notifications (only if you have granted permission)
- Restore your account and data when you sign in on a new device
- Troubleshoot issues and improve app performance
- Manage your subscription via Google Play and RevenueCat
We do not use your financial records or business data for advertising, profiling, or any purpose beyond operating the app.
3. Subscription billing
LedgerOS Pro subscriptions are processed entirely by Google Play. We do not store your payment card details — Google handles all billing data under their own privacy policy. Subscription status is validated server-side by RevenueCat, which receives a transaction receipt from Google Play for verification purposes only.
- Google Play collects and processes your payment information
- RevenueCat receives your app user ID and Google Play purchase receipt
- We receive only a confirmation of active/inactive subscription status — no card numbers or billing address
To cancel your subscription, use the Google Play subscriptions page on your device or via play.google.com.
4. Cloud storage — Supabase
Your account, business records, receipts, and receipt images are stored in Supabase, a cloud database platform hosted on AWS. Your data is:
- Encrypted in transit (HTTPS/TLS) and at rest
- Protected by row-level security — only your authenticated account can read or write your own records
- Hosted in the ap-southeast-2 region(Sydney, Australia) where available under Supabase's infrastructure
Supabase processes data under their own privacy policy at supabase.com/privacy.
5. Disclosure of your information
We disclose data only to the following sub-processors, strictly as needed to operate the app:
- Supabase — account authentication, database records, receipt image storage
- Google Play / Google — subscription billing
- RevenueCat — subscription status validation (receives app user ID and Play receipt only)
- OpenRouter / Google Gemma — receipt OCR text and financial totals for AI-assisted field extraction and BAS review (no images, no personally identifying information)
We do not sell, rent, trade, or share your personal or business information with any third party for marketing, advertising, or any purpose other than operating the app.
6. Overseas disclosure
Some sub-processors operate outside Australia (United States). Before transmitting data to overseas recipients, we take reasonable steps to ensure they handle information consistently with the Australian Privacy Principles, or the transmission is necessary to fulfil the service you have requested.
7. Data retention and deletion
- Account and business data — retained while your account is active and for up to 3 years after last sign-in, unless you request earlier deletion
- Receipt images — retained in Supabase Storage until you delete them in the app or request account deletion
- Subscription records — retained for 7 years to meet Australian tax and accounting obligations
- On-device data — stored locally in a Room database on your device. Removed when you uninstall the app or clear app data
To delete your account and all associated data, email ns@nextwave.au with the subject line LedgerOS Account Deletion. We will process the request within 30 days.
8. Security
We use HTTPS/TLS for all network communication, Supabase row-level security to isolate accounts, and standard Android DataStore encryption for locally cached credentials. API keys are never embedded in the app binary — they are injected at build time via a git-ignored configuration file.
No method of electronic transmission is 100% secure. We take commercially reasonable precautions but cannot guarantee absolute security.
9. Children
LedgerOS is intended for use by business owners and is not directed at children under the age of 15. We do not knowingly collect personal information from children.
10. Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or out-of-date information
- Request deletion of your account and associated data (subject to legal retention obligations)
- Withdraw consent for camera or notification permissions at any time via your device settings — the app continues to function for manual data entry
- Complain if you believe we have breached the APPs
To exercise any of these rights, email ns@nextwave.au with the subject line LedgerOS Privacy Request. We will respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Changes to this policy
We may update this policy as the app's features or our legal obligations change. Material changes will be noted at the top of this page with a revised effective date. Continued use of LedgerOS after any change constitutes acceptance of the updated policy. For significant changes, we will display an in-app notice on next launch.
12. Contact
Privacy enquiries: ns@nextwave.au
NextWave · Australia