1. Who this policy covers
This policy applies to the CarerLedger Android app and the CarerLedger AI service. CarerLedger is developed and operated under the Digident developer name (“Digident”, “we”, “us”). Contact us at digidentai@proton.me.
2. Information kept on your device
CarerLedger can store a private job alias, pay-cycle settings, contract rates, date of birth and apprenticeship dates, work entries, visit and travel times, mileage, work-only notes, imported payslip files, locally produced OCR text, payslip figures, AI suggestions, user corrections, audit history and app settings.
This information is stored in the app's private storage and encrypted with a key protected by Android Keystore. Android cloud backup and device-transfer backup are disabled. We do not receive this local information merely because you use the app.
PDF and CSV evidence exports are different: they are ordinary, unencrypted document files. CarerLedger creates its working copy inside app-private storage, but a copy you save or share is protected only by the destination you choose. Delete all removes the app's own export copies, but it cannot remove copies already shared, downloaded or saved elsewhere.
Please use aliases and never enter a care recipient's name, address, medical information, care notes or other confidential care information. Your employer's own rules may also restrict what can be copied into a personal device.
3. Optional payslip OCR and AI analysis
On-device OCR
When you deliberately import a payslip image or PDF using Android's document picker, Google ML Kit reads up to four pages on your device. The image, document and recognised text are not sent to Google for OCR processing. CarerLedger automatically redacts common sensitive patterns, but redaction can miss unusual names or identifiers. You must review and edit the text before sending it.
What is sent
Only when you accept the in-app disclosure and tap Analyse with AI, CarerLedger sends:
- the payslip text you reviewed;
- the relevant pay-period start and end dates as context.
Before that request, the app asks Google Play Integrity to verify that it is the recognised, licensed Play build on a qualifying device. Google receives the app package/version, a request hash bound to a newly generated installation public key, and the normal Play Integrity app, account/licence and device signals. The hash contains no payslip text, document hash, work log or other app content. Our server uses the verified installation to derive its own app-scoped pseudonym for safety and rate limiting; the app cannot choose or send that identifier.
The original photo or PDF, your local work log, date of birth, apprenticeship record and care notes are not included in the AI request. Our Worker performs a second redaction pass and sends the reviewed text to the OpenAI Responses API using store: false. OpenAI returns organised fields; CarerLedger's deterministic on-device code performs the pay estimate. AI output must be checked against the original payslip.
4. Limited technical data and feedback
- ML Kit metrics: the bundled Google ML Kit library may send Google limited app and device information, a per-install identifier, API configuration, performance metrics, event types, feature input/output sizes and error codes for diagnostics and SDK usage analytics. Google states that OCR images, text and outputs remain on device.
- Play Integrity: when you request an online action, Google processes technical app, licence/account and device-integrity signals plus a content-free request hash. Our server receives Google's verdict and keeps an app-scoped public key record so short-lived credentials can be verified and revoked. We do not receive your Google identity.
- Network and security metadata: Cloudflare and OpenAI necessarily process IP address, request time, TLS and basic request metadata to deliver and protect the optional online service. CarerLedger does not request device location or use IP-derived location as an app feature.
- Categorical feedback: if you flag an AI result, we receive only the category, affected field, request ID and the server-derived app-scoped pseudonym. The app does not offer a free-text feedback field and does not include payslip content in a flag.
- Support: if you email us, we receive the address and content you choose to send through your email provider.
We do not include Digident advertising, cross-app tracking, profiling or behavioural analytics, and we do not access the Android advertising ID.
5. Why we process information
We process optional reviewed payslip text to provide the analysis you request, and limited integrity, pseudonymous and technical metadata to authenticate, secure, rate-limit and troubleshoot that service. Where UK data-protection law applies, we rely on your explicit choice for optional AI processing, performance of the service you request, and our legitimate interests in security and abuse prevention, as appropriate. You can use manual logging and pay checks without the AI service.
Do not send health information, trade-union information, care-recipient information, bank details, National Insurance numbers, tax codes or other unnecessary sensitive data. Remove them from reviewed text before analysis.
6. Service providers and transfers
We use Google ML Kit for on-device OCR, Google Play Integrity for app/device verification, Cloudflare to host and protect the Worker, and OpenAI to organise reviewed payslip text. They process data for the purposes described above under their own service and data-protection terms. Processing may occur outside the UK; where required, we use the contractual and organisational safeguards available through those providers.
We do not sell personal data, provide it to data brokers, or share it for advertising. We may disclose limited information if required by law or necessary to protect users, our service or legal rights.
7. Retention
- On device: the encrypted ledger and attachments remain until you delete them in Settings, clear app storage or uninstall the app. Ordinary PDF/CSV export copies remain until deleted; Delete all removes copies still held by the app but cannot reach copies saved or shared elsewhere.
- CarerLedger Worker: reviewed payslip content and extracted fields are processed in memory for the request and are not placed in our database, object storage, cache, analytics system or application logs. A strongly consistent rate-limit gate keeps only a server-derived pseudonym and counters for the current one-minute window. Proof nonces are kept only until their short-lived credential can no longer be used. The authentication registry keeps the app ID, opaque app-scoped subject, public key/thumbprint, status and revocation epoch while the online service operates, and we plan to delete it within 30 days after the service is permanently withdrawn. It contains no payslip content or Google identity.
- OpenAI: requests use
store: false. OpenAI states that API inputs and outputs are not used to train its models by default, but content may be held in abuse-monitoring logs for up to 30 days unless longer retention is legally required. - Feedback and operations: categorical feedback and limited security metadata may be kept in provider operational logs for up to 30 days.
- Support email: normally kept only while handling your enquiry and for up to 12 months afterwards where needed to maintain a support record.
8. Security and your choices
We use encryption for the local ledger and attachments, app-private staging for ordinary PDF/CSV exports, HTTPS, strict request limits, redaction, access controls and data minimisation. No system is perfectly secure. Keep your device locked, review every export destination, and remove unnecessary personal information before using AI.
You can avoid Play Integrity and all payslip-text transmission by not using online AI or categorical AI feedback. You can delete the complete local ledger and its encryption key from Settings. Delete all also attempts to revoke the online installation credential; if the network is unavailable, the credential expires within ten minutes and deletion of the non-exportable local key prevents another valid proof. The server retains the revoked pseudonymous security record to prevent reactivation of that key. Because there is no account and we do not keep a payslip database, we normally cannot retrieve or identify your local data. For an online-service privacy request, email us with any CarerLedger request ID you still have and an approximate date; do not email a payslip.
9. Your UK data-protection rights
Depending on the circumstances, you may have rights to ask for access, correction, deletion, restriction, portability or objection, and to withdraw consent for future optional processing. Contact digidentai@proton.me. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
10. Age, changes and contact
CarerLedger is intended for adults and is not directed to children under 18. We may update this policy when the app, providers or law changes. We will change the effective date and provide an appropriate in-app notice for material changes.
Privacy questions: digidentai@proton.me.