// LEGAL
SceneLedger privacy policy
What stays on your device, what our account service receives, and what SceneLedger never collects at all.
// 01
Summary at a glance
- Scene evidence — photographs, recordings, transcripts, plans and exhibit records — never leaves your device unless you choose to export and share it.
- The SceneLedger app contains no behavioural or product-usage analytics, no advertising and no tracking software of any kind. The only analytics-classified processing is RevenueCat’s subscription analytics over your purchase data.
- The SceneLedger account service holds only your sign-in identity, your lifetime scene count and your subscription status. It never receives scene content.
- You can permanently delete your account from the app. If you cannot access the app, you can request deletion by email.
This summary is written for speed, not precision. The sections below are the policy, and they govern where the two differ.
// 02
Who we are and what this covers
Informed Software Solutions Ltd (“Informed”, “we”, “us”) is a New Zealand software company and the publisher of SceneLedger. You can reach us at info@informedsoftware.co.nz.
This policy applies to the SceneLedger mobile app for iOS, iPadOS and Android, and to the SceneLedger account service that verifies your sign-in and your licensing. It does not cover the informedsoftware.co.nz website, which is a separate service with its own practices.
Who is responsible for scene evidence
SceneLedger is a professional field tool. The records you create in it will often contain other people’s personal information — names, addresses, photographs of premises and of individuals, and details of how an exhibit was handled and by whom.
Responsibility for that content rests with you and the organisation you work for. You decide what is recorded, on what authority, how long it is kept and to whom it is disclosed. Informed never receives it. Our role is limited to the account and licensing information described in section 04, for which we are responsible.
// 03
Information stored only on your device
Everything you capture in SceneLedger is written to storage on the device you captured it with. None of it is transmitted to Informed. This includes:
- scene records — reference, title, type, description, address, lead investigator and timestamps;
- photographs of the scene, of exhibits and of exhibit movements;
- voice recordings and the transcripts generated from them;
- 2D plans, room outlines and captured 3D models of the scene;
- exhibit details, including GPS coordinates with an accuracy estimate where location was recorded;
- chain-of-custody movements — the time, place, handler and recipient for each movement, with any verification photograph;
- the audit trail, which records changes made to a record along with the values before and after;
- investigator settings, such as your name, your report email address and your numbering preferences.
How it is protected
- The local database is encrypted with SQLCipher. Its encryption key is held in the device keychain or keystore and is marked for this device only, so it does not transfer to another device.
- The app can be locked behind your device biometrics or passcode.
- On iOS, evidence media and generated exports are marked with complete file protection and excluded from device backups.
- Export packages are generated on the device. They leave it only when you send them yourself through the system share sheet.
Two things worth knowing
Original photographs included in an export retain the metadata the camera wrote into them. That metadata can include GPS coordinates, the device model and the time the photograph was taken. Treat an export as you would any other evidence file.
Deleting a scene in the app permanently removes that scene, and its photographs and audio, from the device. There is no copy held anywhere else, so export anything you need to retain before you delete it.
// 04
Information the account service receives
The SceneLedger account service exists to verify who you are and what you are licensed to do. It is deliberately narrow. This is the complete list of what it receives and stores.
When you sign in
The app sends the signed identity token issued by Apple or Google. Our service verifies that token and records:
- which provider you signed in with — Apple or Google;
- the subject identifier that provider issues for you, which is a stable reference to your account with them;
- your email address. With Sign in with Apple this may be an Apple private relay address rather than your real one;
- your display name. Google supplies this. Apple supplies it only if you choose to share your name at your first sign-in, and if you do not, we simply have no name for you;
- once only, at your first sign-in, your lifetime scene count, so an allowance you have already used carries across rather than restarting.
When you create a scene
The app sends an opaque authorisation identifier for that scene so the service can check it against your free-scene allowance or your subscription. It is an identifier and nothing more. No title, description, address, photograph, recording, plan or coordinate travels with it.
Subscription status
Your entitlement is checked through RevenueCat and the result is cached against your account record. See section 07 for what RevenueCat receives.
Sessions and server logs
- Your session token is stored only as a SHA-256 hash. The token itself is never written to our database. Sessions expire 180 days after they are issued.
- Requests to the account service are written to standard web-server request logs, which include the IP address the request came from. Those logs are held by our hosting provider. We use them to keep the service secure and to apply rate limiting. We do not use them to build a profile of you.
// 05
What we do not do
- We never transmit your scene evidence. There is no upload path in the app and no evidence store on our side.
- The SceneLedger app contains no behavioural or product-usage analytics SDK, no advertising software, no third-party tracking SDKs and no device fingerprinting. The only processing declared under the Analytics category is RevenueCat’s processing of the account identifier and purchase history for subscription analytics, described in section 07.
- We do not sell personal information, and we do not share it for anyone’s marketing purposes.
- We do not track you across other companies’ apps or websites. SceneLedger shows no App Tracking Transparency prompt on iOS because there is nothing in it that tracks.
// 06
Device permissions and why we ask
SceneLedger asks for a permission only when a feature needs it, and your device asks you before it is granted. You can withdraw any of them in your device settings, which will disable the feature that depends on it.
- Camera
- To photograph evidence, scan QR labels, and measure scene layouts and yard features.
- Microphone
- To record scene and exhibit voice memos.
- Speech recognition
- To transcribe voice memos into editable evidence notes. The app requests on-device recognition. On Android, where on-device recognition is not available, the device’s configured recognition service — typically Google’s — may process the audio off the device. Assess that against your organisation’s policy before dictating sensitive material on an Android device.
- Location, while you are using the app
- To record where an exhibit was found and where it was moved. SceneLedger asks only for while-in-use access. It never tracks your location in the background, and the coordinates it records stay on the device.
- Face ID and other biometrics
- To unlock protected evidence records on the device. This is a local unlock only — the biometric check happens on your device and nothing about it reaches us.
// 07
Third parties we rely on
These are the only third parties involved in running SceneLedger. None of them receives your scene evidence.
- Apple
- Verifies your identity when you use Sign in with Apple, and handles billing for subscriptions bought through the App Store. Apple privacy policy (opens in a new tab)
- Verifies your identity when you sign in with Google, handles billing for subscriptions bought through Google Play, and on some Android devices provides the speech recognition service described in section 06. Google privacy policy (opens in a new tab)
- RevenueCat
- Manages subscription entitlements. It receives an internal account identifier we issue for you, together with store purchase and entitlement information. It uses that identifier and purchase information for subscription entitlement, which is app functionality, and for subscription analytics. RevenueCat privacy policy (opens in a new tab)
- Our cloud hosting provider
- Runs the account service and its database, and stores the server request logs described in section 04.
// 08
How long information is kept
- Records on your device
- Kept until you delete them in the app or uninstall the app. Deletion is permanent and immediate.
- Account records
- Kept for as long as your account exists. Your lifetime scene count is retained so that the free-scene allowance can be enforced, which means deleting scenes on your device does not reduce it.
- Sessions
- Expire 180 days after they are issued, and the expired record is cleared.
- Server request logs
- Retained for the period our hosting provider retains platform logs.
// 09
Backups
- On Android, system backup is disabled for SceneLedger.
- On iOS, evidence media and generated exports are excluded from device backups.
- The encrypted database itself may be included in a backup you take of your own device. It cannot be decrypted on any other device, because its key is held in this device’s keychain and never leaves it. Restoring that backup to a different device produces a database that cannot be opened.
SceneLedger is not a backup system and we hold no copy of your records. Organisations should keep their own evidence-handling backups in line with their policies, using the export packages the app produces.
// 10
Your rights and account deletion
Signing out
You can sign out of your account at any time from the app’s settings. Signing out ends the session on that device. Records already on the device stay there, and a verified account is required before another scene can be created.
Deleting your account
You can permanently delete your SceneLedger account from Settings → Delete SceneLedger account. The app asks you to confirm the request and, for Sign in with Apple, to authenticate with Apple again. Deletion is then completed immediately.
If you cannot access the app, email info@informedsoftware.co.nz from the email address associated with the account, with the subject line SceneLedger account deletion. We verify the request and complete it within 30 days.
Deletion removes the identity reference we hold for you, your email address, your display name, your lifetime scene count, your scene authorisation records, your session records and the RevenueCat customer record associated with your SceneLedger account. Where you use Sign in with Apple, SceneLedger also asks Apple to revoke its sign-in authorisation.
Two things deletion does not do
It does not delete the records held on your device. Those are yours and only you can remove them, by deleting scenes in the app or uninstalling it.
It does not cancel a store subscription. Subscriptions are sold and billed by Apple or Google and must be cancelled through your App Store or Google Play account.
Access, correction and complaints
Under the New Zealand Privacy Act 2020 you have the right to ask us for the personal information we hold about you, and to ask us to correct it if it is wrong. Email info@informedsoftware.co.nz and we will respond within the timeframes the Act sets.
If you are not satisfied with how we have handled your privacy, you can complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz (opens in a new tab).
Where the General Data Protection Regulation or a comparable law applies to you, we honour the equivalent rights it gives you over the information described in this policy.
// 11
Children
SceneLedger is designed as a professional field tool for investigators and the organisations they work for. It is not directed or marketed to children. If you believe a child has provided personal information inappropriately, please contact us and we will assist with its deletion.
// 12
Security
- Traffic between the app and the account service is encrypted in transit using TLS.
- Records on the device are encrypted at rest with SQLCipher, with the key held in the device keychain or keystore.
- Session tokens are stored only as SHA-256 hashes, so a copy of our database does not yield a usable token.
- The account service applies rate limiting to sign-in and to its other endpoints.
No method of transmission or storage is completely secure, and we do not claim otherwise. Much of SceneLedger’s security also depends on how the device itself is managed — a device passcode, the app lock and control of who can reach exported packages all matter. If you find or suspect a security problem, tell us at info@informedsoftware.co.nz.
// 13
Changes to this policy
If our practices change, we will post the updated policy on this page with a new effective date. The date at the top of the page is always the date of the version you are reading.
// 14
Contact
Questions about this policy, requests for access or correction, and account deletion requests all go to the same place.
Informed Software Solutions Ltd New Zealand info@informedsoftware.co.nz
// APPENDIX A
Google Play Data safety declaration
This appendix restates, in the categories Google Play uses, what SceneLedger collects. Where a row says a type is not collected, it means that type is never transmitted off your device by SceneLedger.
Swipe the table sideways to read every column.
| Data type | Collected | Purpose |
|---|---|---|
| Personal info — email address | Collected | Account management. Read from the signed identity token issued by Apple or Google when you sign in. May be an Apple private relay address. |
| Personal info — name | Optional | Account management. Supplied by Google sign-in; supplied by Apple only if you choose to share your name at first sign-in. |
| Personal info — user IDs | Collected | Account management. The subject identifier your provider issues, and the internal account identifier we issue, used to apply your allowance and subscription. |
| Financial info — purchase history | Collected | App functionality and analytics. Purchases are handled by Google Play; subscription entitlement is managed through RevenueCat, which also uses purchase history for subscription analytics. |
| App activity — other actions | Collected | App functionality. A count of scenes created, and one opaque authorisation identifier per scene, used only to apply the free-scene allowance. No scene content is collected. |
| Location | Not collected | Coordinates are recorded on the device only and are never transmitted to us. |
| Photos and videos | Not collected | Never transmitted to us. They leave the device only in an export you choose to share. |
| Audio — voice or sound recordings | Not collected | Never transmitted to us. See section 06 for the Android speech recognition caveat. |
| Device or other IDs | Collected | App functionality. SceneLedger reads no hardware device identifier. What is held is the IP address of requests to the account service, retained in the security and rate-limiting logs described in section 04, and declared under this category because of that use. No advertising identifier and no fingerprinting. |
| Messages, contacts, calendar, health and fitness, files and docs, web browsing | Not collected | SceneLedger does not request or use any of these. |
Swipe the table sideways to read every column.
| Practice | Declaration |
|---|---|
| Data shared with third parties | Only with the processors listed in section 07 — Apple, Google, RevenueCat and our cloud hosting provider — and only for the purposes stated there. Not shared for advertising or marketing. |
| Data encrypted in transit | Yes. All traffic between the app and the account service uses TLS. |
| Users can request that data be deleted | Yes. See Your rights and account deletion for the process and what it removes. |
| Data collection is optional | Signing in is required only to create scenes beyond the free allowance. Existing records can be viewed and exported without an account. |
// APPENDIX B
Apple App Privacy summary
This appendix restates the same practices in the categories Apple uses on the App Store product page. It mirrors the declaration made in App Store Connect.
Swipe the table sideways to read every column.
| Category | Data types |
|---|---|
| Data used to track you | None. SceneLedger contains no tracking software and shows no App Tracking Transparency prompt. |
| Data linked to you |
|
| Data not linked to you | None. |
| Data not collected |
|
End of policy. Effective .