LODI is local-first by design. Your friends, utang records, vouches, and identity are stored on your device. LODI does not have user accounts, does not run analytics or advertising, and does not sell or share your data with third parties. Because utang and vouch records involve two people, LODI uses Firebase (Google) as a relay to sync and confirm those records between your device and your friend's, and to deliver push notifications for things like payment confirmations and reminders. Firebase only handles what's needed to make that two-way sync and push delivery work — it is not used for analytics, advertising, or tracking.
LODI is an independent app developed and maintained by Bryan (Works of Bryan), a Filipino solo developer. LODI is built to make casual utang tracking among friends honest, simple, and private.
This policy applies to the LODI mobile application available on the Apple App Store and any successor versions ("the app"). It explains how the app handles information you create or provide through it.
UT-XXX-XXX) and an Ed25519 cryptographic keypair on your device when you first launch the app. These stay on your device.The app creates and stores the following kinds of data:
Data described above as "stored on your device" is kept in the app's private storage (the iOS app sandbox). Other apps on your device cannot read it, and the developer cannot read it directly. Data described as synced through Firebase passes through Google-operated infrastructure as described in Section 4 and Section 5.
Information from the app leaves your device in these circumstances:
When you create an utang request, mark a bayad, give a vouch, or share a receipt, the app generates a link (or an image, for receipts) and presents the iOS share sheet. You choose the destination — Messages, Messenger, Mail, AirDrop, or any other app you have installed. The data goes wherever you send it. The developer does not see, log, or proxy this data.
If a friend sends you a LODI link (via any messaging app), tapping it opens LODI and processes the encoded information locally. The link itself is data you received from a friend, not from any LODI service.
Because an utang or vouch involves two people, LODI uses Firebase (Firestore and Cloud Functions) to relay specific record updates — for example, when you mark an utang paid, resend a confirmation, or receive an acknowledgment — to your counterparty's device, and Firebase Cloud Messaging to deliver the push notification that alerts them. This happens automatically as part of using the app's core features (it is not gated behind a separate Share tap), because it's how confirmations reach the other person. Only the fields needed to identify the utang/vouch and route the notification are sent (record IDs, status, counterparty user IDs, and the push token) — not your full local record set, keypair, or friend list.
The app includes a Backup & restore feature in your Profile. Tapping it generates a JSON file containing your LODI data, saved temporarily in the app's sandbox. You then choose, via the iOS share sheet, where to send it — typically Mail, Files, or iCloud Drive. The temporary file is automatically deleted from the sandbox after sharing or when you close the sheet. The developer never receives a copy.
LODI uses Firebase, a set of backend services operated by Google, to make the syncing and push notifications described in Section 4 possible. Specifically:
The developer configures and operates this Firebase project, but the underlying infrastructure is run by Google, and Google's own privacy practices apply to how it processes data on the developer's behalf. You can review Firebase's privacy and security documentation and Google's Privacy Policy for details on Google's side of this.
Firebase is used here strictly as sync/relay and push infrastructure. It is not configured for Firebase Analytics, Google Analytics, advertising, or audience/behavioral tracking, and the developer does not use it to build a profile of you.
A few standard iOS features may also interact with the app's data outside of the app itself. These are controlled by Apple and by your device settings, not by the app:
If you want to limit these flows, manage them in your device's Settings → Privacy & Security, or in your Apple ID iCloud settings.
LODI sends two kinds of notifications:
You can revoke notification permission at any time in your device's Settings → Notifications → LODI. Turning notifications off does not affect the underlying utang records themselves — you'll still see updates when you open the app.
The app is rated for users aged 12 and older on the App Store. It is not directed to children under 13. The developer does not knowingly collect data from anyone, of any age, beyond what's described in this policy for making the app's core sync and notification features work. If you are a parent or guardian and you believe a child has been using the app in a way you'd like to address, you can delete the app from the device, which removes all locally stored data, and contact the developer (Section 12) to request deletion of any corresponding synced records.
Locally stored data is controlled directly by you:
Data synced through Firebase (Section 4.3) is retained only for as long as needed to complete the relay/confirmation it supports, and is not treated by the developer as a permanent record of your utang history — your device is the source of truth for that. If you'd like the developer to confirm deletion of any record still held in Firebase (for example, after uninstalling the app), contact the developer using the details in Section 12.
The app is intended to be respectful of users' rights under applicable privacy laws, including (where applicable) the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Philippines Data Privacy Act.
Most "data subject rights" requests (access, deletion, portability, correction) are self-service because the large majority of your data lives on your device:
If you'd still like to contact the developer about a privacy-related concern that isn't covered by the self-service options, see Section 12 below.
If this policy changes materially (for example, if the app adds a feature that involves data leaving your device in a new way), the developer will update this page with a new "Last updated" date and, where appropriate, surface a notice within the app.
For privacy-related questions, concerns, or requests, please reach out:
This policy is written in plain language because that's how policies should be. If something here is unclear, that's a bug in the policy, not in your reading — please email me and I'll fix it.