Sole Trader: Tax & Invoices

Privacy policy

Effective 10 September 2026. The Privacy screen inside the app is a summary of this policy and says nothing it does not.


The short version

Your records are stored on your phone, encrypted. Expenses, income, mileage, receipt photographs and your business details go into a database on the device. The key to it is held by the device's own secure store, backed by hardware where the device provides it.

Signing in is optional and off until you choose it. If you do sign in, a copy of your records is also kept with your account on our servers in the EU, so you can pick up on another phone. If you never sign in, the app makes no network requests at all.

No advertising, no analytics, no crash reporting. Not a reduced amount — none. There is no advertising library in the build, no telemetry, and no identifier collected for either.

The app does not connect to your bank. There is no bank account to link and no open banking connection. Statements are files you download yourself, and they are read on the phone.


Who is responsible

Afrasiyab Afrasiyab, trading as One App Company, is the data controller for this app and for the copy of your records held with an account, if you have one.

Questions about this policy: hello@oneappcompany.com


What the app stores, and where

Everything below lives in the app's private storage on your device. No other app can read it.

WhatWhy it exists
ExpensesThe costs you record, with the category each is claimed under
IncomeWhat you invoiced or were paid, kept apart from expenses
MileageTrips and their distances, for the mileage allowance
Receipt photographsThe image behind an expense, as evidence for a claim
Attached invoices and documentsFiles you attach to an entry yourself
Invoices you raiseIncluding the customer details you typed on them
Your trade and tax setupProfession, tax year, whether you are in Scotland, the accounting basis
Recurring templatesCosts you told the app repeat, so they can be offered
Reminders and app settingsNotification times, the display options you chose
App lock and passcodeHeld as a hash, on the device, and never transmitted

The database is encrypted with AES-256. The key is generated on the device on first launch, is never derived from anything you type, and is held in the Android Keystore or the iOS Keychain. On iOS it is readable after the first unlock following a restart, so reminders and background work still function while the phone is locked.

Receipt photographs and attached files are kept in the app's private storage alongside the database.

Some of this may be included in the device's own backup — Google Drive on Android, iCloud on iPhone and iPad — if you have device backup switched on. That is a setting on the phone rather than something this app controls.


Permissions, and what each is for

Camera — to photograph receipts. Images are saved on the device.

Location — only while a trip is actively recording, and only to measure the distance travelled. While it records, the phone shows a permanent notification, so it is never running without your knowledge. The app does not request background location, so it cannot record a trip you did not start. Nothing about your position is transmitted, and location is never attached to an expense.

Notifications — for the recording notification above, and for the reminders you switch on yourself.

Biometrics — only to unlock the app, if you turn the lock on. Your fingerprint or face data is handled entirely by the operating system. The app never receives it and only ever learns whether the check passed.

Internet — used to sign in to an account if you choose to, to keep that copy in step, and to upload a backup to your own Google Drive if you turn that on. With no account and no Drive backup, the app makes no network requests.


Reading receipts

When you photograph a receipt, the app reads the text on it to suggest an amount, a date and a merchant. This happens on the device. The image is not uploaded to be processed, and no receipt is sent anywhere to be read.

The suggestions are only suggestions. Nothing is saved until you confirm it.


Bank statements

The app can read a statement you have downloaded from your bank, as a PDF or a CSV, and offer the entries for you to sort into categories.

It does not connect to your bank. There is no open banking link, no bank credentials are asked for, and there is nothing in the app that could sign in to an account on your behalf. The file is one you fetched yourself, it is read on the phone, and it is not uploaded.

Entries you do not keep are discarded. Only the ones you accept become records in the app.


account

Signing in is off by default and is never required to use the app.

When you sign in, we store your email address — or the address Apple or Google vouched for — and a copy of your expenses, income, mileage, tax setup, recurring templates and receipt files, so they can be restored on another device. The copy is held in the EU, in London, or Ireland if London is not available, by our processor Supabase. Row-level security means one account cannot read another's records.

We do not use this data for advertising, analytics or profiling. We can see it in the way any account host can — it is not end-to-end encrypted on the server — and we will not look at it except to operate the service, to fix a fault you have asked us about, or where the law requires it.

Sign in with Apple and Sign in with Google pass us an identifier and an email address. They give us no access to anything else in your Apple or Google account.

You can sign out at any time and the records on the phone stay. Settings → Delete all my data removes the phone copy and the server copy together.

Your passcode, the database encryption key, the app lock and your subscription are never sent to us.


Google Drive backup

This is off by default and only runs if you switch it on.

The app asks Google for the drive.file scope, which is deliberately the narrowest available: it can see and manage only the files it created itself. It gives no access to anything else in your Drive — no other documents, no photos, nothing you did not create through this app.

Backups go to a folder in your own Google account. We have no access to them and hold no copy. The ten most recent are kept and older ones removed, so backups do not grow without limit.

Google's handling of your Google account is governed by Google's own privacy policy: <https://policies.google.com/privacy>. Disconnect the account in Settings at any time, and revoke access entirely at <https://myaccount.google.com/permissions>.

Drive backup is a separate Google sign-in from signing in to an account. Doing one does not do the other.


Invoicing, and your customers' details

When you raise an invoice you type in somebody else's name, address and contact details. That is different from everything else in this app, which is about you, so it is worth setting out plainly.

Those details are yours, not ours. They are stored on your phone in the same encrypted database as your own records, and they behave the same way: no analytics, no advertising, nothing sold. If you have signed in to an account, the invoice is copied there with the rest of your records so it restores on another device.

They leave the phone when you send the invoice. The document is created on your device and handed to whichever app you choose to send it with. From that point it is subject to that app's handling and wherever you sent it, which is outside our control and outside this policy.

We never contact your customers. We do not email them, we do not chase your unpaid invoices, and we do not add them to anything. The only person who ever sends your customer an invoice is you.

Deleting works the same way. Settings → Delete all my data removes your invoices along with everything else, from the phone and from the server copy if you have an account. A single invoice can be deleted on its own.

What this means if you are the customer on one of these invoices

The trader who invoiced you decides what they hold about you and for how long, not us. Under UK GDPR they are the data controller for it and we are processing it on their behalf. Ask them, and they can delete it here.


Filing to HMRC

Not yet available. The app does not connect to HMRC and does not file anything. This section describes what filing will involve when it arrives. None of it happens in the version you are using today.

Filing will be something you switch on. If you never switch it on, the app behaves exactly as described everywhere else in this policy.

What HMRC requires of the software

HMRC requires every product that connects to its APIs to send a set of fraud prevention headers with each request. They are how HMRC separates a genuine submission from a fraudulent one. They are not optional, and software that omits them, or sends inaccurate ones, is refused access.

For an app that files directly from a phone, those headers describe the device rather than your records:

What we do with it

Signing in to HMRC

You sign in on HMRC's own page, not in this app. We never see your Government Gateway user ID or password. HMRC returns a token that lets the app act for you, which is stored encrypted on your device with everything else.

You can disconnect HMRC at any time in Settings. That removes the token and the device identifier described above. You can also revoke the app's access from your own HMRC account.

Who is responsible for what

Once a submission reaches HMRC, HMRC is the controller of it and handles it under its own privacy notice at <https://www.gov.uk/government/publications/data-protection-act-dpa-information-hm-revenue-and-customs-hold-about-you>. We remain responsible for what is on your device and, if you have signed in to an account, for the copy held there.


Exports and sharing

When you export a CSV or a PDF, or send entries from the log, the file is created on the device and handed to whichever app you choose to send it with. From that point it is subject to that app's handling and wherever you sent it, which is outside our control and outside this policy.

The app does not choose a recipient and does not keep a copy.


The subscription

Paid features are sold through the store the app was installed from — Google Play on Android, the App Store on iPhone and iPad — using that store's own billing.

Payment details are handled by Google or Apple and never reach the app. It is told only whether an active subscription exists for the store account, and nothing about who you are or how you paid.

Manage or cancel it in the Play Store, or in iOS Settings → Apple ID → Subscriptions, matching the store that billed you.


What we do not do


Children

The app is for adults running a business or working self-employed. It is not directed at children and is not intended for anyone under 18.


Deleting your data

Settings → Delete all my data erases everything: the database, every stored receipt image and attachment, your settings, and the signed-in copy on our servers if you have an account. It is immediate and cannot be undone.

Uninstalling the app removes the copy on the device. It does not remove the signed-in copy — sign in on another device, or use Delete all my data while signed in, if you want that gone too.

Backups already uploaded to your Google Drive are not removed by either. They are in your account rather than ours. Delete them from Drive yourself.


Your rights

Under UK GDPR you have rights over personal data an organisation holds about you: access, correction, erasure, portability, and others.

In this app those rights are mostly exercised on the device. You can read, change and export every record in the app, and delete both the device copy and the server copy from Settings. If you would rather ask us, or you disagree with anything here, write to hello@oneappcompany.com.

You can also complain to the Information Commissioner's Office at <https://ico.org.uk/make-a-complaint/>.


Changes to this policy

If what the app does with your data changes, this policy is updated before that version is published, and the effective date at the top changes with it. Any new permission is visible on the store listing.


Contact

Questions about this policy, or about your data: hello@oneappcompany.com


For the store data-safety forms

The declarations follow from the above, recorded here so the Play Data safety form and the App Store privacy questions are answered the same way each time they are revisited.

Both stores separate collected — sent off the device — from what the app merely stores locally. Everything the app holds while you are signed out is stored, not collected.

Data typeCollectedShared
Email addressYes, if you sign inNo
Names and addresses of your customers, from invoicesYes, if you sign inNo
Financial info: expenses, income, mileageYes, if you sign inNo
Photos: receipt imagesYes, if you sign inNo
Files and documents: attachmentsYes, if you sign inNo
Payment infoNoNo
LocationNoNo
App interactions, diagnostics, crash logsNoNo
Device or other IDsNoNo

The Device or other IDs row becomes collected, not shared on the day HMRC filing ships, because the fraud prevention headers carry a device identifier. Nothing else on the table moves.