The three promises
Every way money reaches your Lekhio is read only. On iPhone the Wallet feed is read on your own phone. On Android, Lekhio catches the payment notification your bank already shows you, on the phone. A statement is a file you send us. Nothing in Lekhio can move money out of any account, because there is no code for it: no payment door, no transfer, no card in your name.
The one payment Lekhio ever takes is its own subscription, through Stripe or your app store. That is a payment to us for Lekhio, and it never touches your bank feed. Card payment on your invoices is switched off in the code until your money can go straight to you and never through us.
A payment lands in your Lekhio unconfirmed. It waits for your yes, on the notification or in the pile in the app. The only lines Lekhio files by itself are from shops you have already told it about, and a line that looks like a benefit, a refund, or your own money moving between accounts always asks, however well we know the shop.
Your figures are prepared for you to check. Nothing reaches HMRC until you have looked at it and said yes, and HMRC keeps you responsible for your tax. That never changes.
An invoice you make in the app is a link you send your customer yourself, from your own phone or email. Lekhio does not send it for you. Nothing in Lekhio posts, emails or messages anyone on your behalf without your yes. A thumbs up does not count as a yes, and silence does not count.
Lekhio holds no way to change a setting, a payee or a limit at your bank, and no way to write into your accounts at all. Read only means read only.
What we read and what we keep
Each way money reaches your Lekhio reads a different thing, so here is each one on its own. Which of these is switched on for you today is shown on the connect screen in the app. The statement always works, for any bank.
We read: The payments on the cards you have added to Wallet, read on your phone through Apple's own connection to your bank.
We keep: The shop, the description your bank gives it, the amount, which way the money went, the date, the category code the card scheme gave it, which account it came from, and an id so the same payment never lands twice. Not your balance, and your card number is not something we ask for or hold.
We read: The payment notification your bank or Google Pay already shows you, read on the phone as it arrives.
We keep: The shop, the amount, the time, which app it came from, and the words of the notification as your bank wrote them, with any balance taken out before they are stored. A notification that only tells you your balance is not kept. Every other app's notifications are ignored. There is no history on this route, so for the past, send a statement.
We read: Receipts and invoices only, whether you forward them to your Lekhio address or point an inbox at Lekhio.
We keep: The attachment and the figures on it: the shop, the amount, the date, the VAT. We never keep the message it came in, and we keep nothing from any other email.
We read: The lines in the file you sent, on WhatsApp or the upload page.
We keep: Each line, unconfirmed, waiting for your yes. The file itself is not kept once the lines are in.
We read: The receipt in the photo, and the words in the voice note.
We keep: The photo, in a private store that only your account can reach, and the figures read from it. A voice note is turned into text on our own machine, never by an outside service, and the audio is deleted the moment it has been read.
What you can undo
The Wallet feed and the Android catch are permissions on your phone, and you take them back in one tap on the phone. Where Lekhio holds a key to an account of yours, disconnecting deletes our copy of it. The lines already in your books stay yours until you say otherwise.
You, then Delete your account, then one press and one confirm. It cancels a card subscription first (one bought through the app is held by the store on your phone, so you end it in the subscription settings there, and the delete screen says so), then removes your rows from every table that holds your data, and your receipt photos with them. A test in our build fails if a table is ever left out of that list.
One link hands you everything we hold about you in one file, whether or not you are paying. That is your right under UK GDPR, Article 15, and it is a door in the product rather than a request you have to make.
The security facts, as they stand today
Your rows are yours. Row level security is on for every table in the database, so one person can never read another person's figures, and a test in our build fails if a table is ever created without it.
The keys to a connected bank or to HMRC are encrypted a second time by our own code before they reach the database, under a key that lives only on the hosting side. A copy of the database on its own cannot reach your bank.
Everything travels over HTTPS. The site tells every browser never to use plain HTTP to reach it.
In the app, your books can sit behind Face ID or your phone's own unlock, and connecting your bank from the app asks for your face or your passcode first, every time.
The accounts that hold the keys, at the host, the database, the code and the payments, sign in with a second factor.
Payments are handled by Stripe and the app stores. We never see or hold your card number.
We have not earned one yet, so we do not show one. When we do, it goes here with its date. Until then, every claim above points at a line of code, and we would rather you could check that than trust a logo.
Lekhio Ltd is registered with the Information Commissioner's Office as a data controller, reference ZC198977. If you have a question about your data, email info@lekhio.app.