Overview
DebtLens handles sensitive financial-planning information only when you enter it. It does not connect to banks or creditors, retrieve transactions or credit reports, or operate a developer server that receives your DebtLens financial records. Storage differs by installed version: the published 1.0 implementation and the reviewed 1.0.4 code are both covered below. Optional Sign in with Apple and iCloud features use Apple services. The app contains no third-party advertising, cross-app tracking, or developer analytics SDK. Brent Gaddis is responsible for the practices described here. DebtLens is a general-audience app and is not directed to children under 13. Privacy questions or requests can be sent through the site form or to support@brentgaddis.com.
Information you provide and why it is used
DebtLens can store the information you enter: account or creditor names, debt types, balances, statement balances, annual percentage rates, credit limits, minimum and target payments, due days, autopay choices, monthly snapshots, optional notes, planner choices, currency, theme, reminder, App Lock, sync, and PDF preferences. It uses that information to show your dashboard and account history, calculate informational payoff illustrations, schedule requested reminders, create requested reports, apply settings, and perform optional sync. DebtLens does not request bank credentials, automatically import bank transactions, access a credit report, initiate a payment, or verify the accuracy of what you enter.
Local storage and security
Storage behavior depends on the installed version. Version 1.0 stores app information in DebtLens’s local app container. The reviewed 1.0.4 code migrates the local financial file to AES-GCM encryption using a random 256-bit key held in the device Keychain, applies complete file protection, restricts file permissions, and excludes that financial file from ordinary device backup. Older local data can remain in its prior format until an update completes migration. Optional App Lock asks the operating system to authenticate with Face ID, Touch ID, or the device passcode; DebtLens does not receive biometric templates. These safeguards reduce risk but no device, software, storage, or transmission method can be guaranteed completely secure.
Optional Sign in with Apple and iCloud sync
DebtLens can be used without a DebtLens account. If you choose Sign in with Apple, Apple supplies a stable user identifier and can supply a name or private-relay email the first time you authorize the app. The reviewed 1.0.4 code stores that Apple identity in the local Keychain and uses a one-way SHA-256 value derived from the Apple identifier to scope the sync record. Version 1.0 can place an optional sync snapshot in Apple’s iCloud key-value service. The reviewed 1.0.4 code moves the active financial snapshot to a record in the user’s private CloudKit database and places the financial payload in CloudKit’s encrypted-values field. A hashed account scope, schema version, modification time, deletion state, and nonfinancial generation metadata can remain outside that encrypted field; limited key-value metadata can also remain during compatibility or deletion. Apple processes identity, private-cloud storage, network, and App Store information under Apple’s terms and privacy policy. Brent Gaddis does not operate a separate app-data server and does not use Apple identity or synced financial information for advertising, tracking, or analytics.
Permissions and your choices
Sign in with Apple and iCloud sync are optional. DebtLens asks for notification permission only if you enable reminders and asks for device authentication only if you enable App Lock. You can disable reminders, App Lock, or sync in DebtLens and can manage notification, iCloud, biometric, and Sign in with Apple access in Apple system settings. Disabling a feature can stop its future use but does not recall a PDF you already shared or by itself complete an account-deletion request. DebtLens does not request Contacts, Photos, location, microphone, camera, Health, or bank-account permissions for its reviewed features.
Notifications
Reminder scheduling and delivery occur through the device’s notification system. The monthly check-in reminder is generic. A payment reminder can include the account name and amount, which may be visible on a lock screen or other notification surface according to your system preview settings. Reminders are device-specific and are not guaranteed. In the current version, selected due days 29 through 31 are scheduled on day 28, so a “due today” message can appear early. Verify every due date with the creditor and adjust notification previews or disable reminders if account details should not appear.
Website, support, service providers, requests, and policy changes
DebtLens contains no third-party advertising SDK, developer analytics SDK, cross-app tracking, or sale of personal information. Its brentgaddis.com pages use first-party aggregate analytics operated through Cloudflare. The site counts page views and allowlisted actions and keeps coarse source, country, device, browser, operating-system, engagement, performance, and reliability totals. It does not store raw analytics event rows, visitor or session identities, IP or hashed-IP identifiers, cookie or local-storage visitor IDs, full user agents, full referrers or URLs, form contents, arbitrary text, or a person’s raw click history. Country and source cells below five are suppressed, and aggregates are retained for up to 24 months. Cloudflare still processes request and network metadata to deliver and protect the site. If you contact support, the site and its email service process the reply email, app selection, request type, subject, message, security-challenge result, and delivery metadata you submit. The website does not write message contents to its analytics database; the message is delivered to Brent’s monitored mailbox and retained only as reasonably needed to respond, maintain support and security records, resolve disputes, and meet legal obligations, then deleted or de-identified when no longer needed. Cloudflare Turnstile processes security and network signals to prevent abuse. Apple, Cloudflare, and email providers process information under their own terms and privacy commitments, and service providers used on Brent’s behalf are authorized only for the described functions. Because the site does not use cross-site behavioral advertising or sell or share personal information for that purpose, browser Do Not Track and Global Privacy Control signals do not change its behavior. Depending on where you live, applicable law may provide access, correction, deletion, or appeal rights; submit a request through the support form or support@brentgaddis.com. Identity may be verified, and requests will be handled as applicable law requires. Material policy changes will be posted on this page with a new effective date, and additional notice or consent will be provided when required.
Questions
Contact Brent Gaddis with privacy questions about DebtLens.