Privacy Policy
Last updated: 2 June 2026
BillBook Lanka is a record-keeping app for Sri Lankan small businesses. It is local-first: by default your data stays on your device and nothing is uploaded. This policy explains what we collect, what we deliberately do not, and the choices you control.
Local-first by default
Your invoices, receipts, cashbook entries, orders, stock and customer records are saved in the app's storage on your own device. Unless you turn on optional cloud sync, none of it is sent to us or anyone else. Because the data lives on your device, clearing the app's data or uninstalling it will remove it — so please keep your own backups (you can export your data at any time).
Signing in with Google (optional)
Signing in is optional — BillBook Lanka works fully without an account. If you choose “Continue with Google”, Google shares a limited part of your Google profile with us: your name, your email address and your profile picture. We use these solely to create and secure your account and to sync your records into your own private, per-user, row-level-secured space. We never use them for marketing, and never sell or share them.
BillBook Lanka's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect BillBook from your Google Account's security settings at any time, and delete your account and data from within the app (Account & cloud).
Optional cloud sync
If you enable cloud sync, your records are stored in our secure cloud (Supabase) under per-user Row Level Security, so only you can ever read or write your own data. The app uses only a public key — never a secret key. You can export your data or permanently delete it whenever you like.
What we store
Only what you enter to run your business — invoices, receipts, cashbook entries, orders, stock, customers, and, if you sign in, your account email. Some of this is sensitive (for example, customer phone numbers) and is treated carefully and never sold.
What we deliberately do not do
- Not a payments product. BillBook does not connect to any bank, card processor or payment gateway, and never stores card, bank-account or payment-token details. Any LankaQR shown is your own bank-issued code, displayed for your customer to scan.
- On-device assistant. The optional Business Assistant runs entirely on your device — it makes no external or model-provider call, and sends none of your business or customer data anywhere.
- No selling, no ads. We never sell your data or your customers' contact details, and we don't show third-party advertising.
Your controls
You can export your data at any time, and permanently delete your account and data from Account & cloud. You can disconnect Google from your Google Account settings.
Children
BillBook Lanka is intended for business owners and is not directed at children.
Changes to this policy
We may update this policy as the app evolves; the “last updated” date above reflects the current version. Sinhala and Tamil versions are maintained inside the app.
Contact
Privacy questions or requests: [email protected]. General support: [email protected].