Security

Small attack surface. Honest limits.

The founding beta avoids accounts, cloud sync, advertising SDKs and external AI services. That keeps the first security model understandable.

Local-first architecture

Operational data is written to the app's private container on the iPhone. The app is designed to use iOS file protection and atomic local writes so an interrupted save does not replace a good record with a partial one.

No hidden transfer

There is no app account, remote database, analytics SDK or background customer-data upload in the first beta. A file leaves the app only through a share or export action that you start.

Your part

  • Use a device passcode and current supported iOS release.
  • Review recipients before sharing customer or commercial data.
  • Keep independent records for statutory and contractual duties.
  • Create readable exports where useful; v1 cannot restore them into the app.

Reporting a problem

Send security concerns to security@getleccy.com. Do not send live customer data or an exploit in the first message.

Before cloud features

Any later team sync will require tenant-isolation tests, encryption and key-management decisions, retention and deletion controls, audited subprocessors, restore testing and an updated privacy assessment before release.