Security

How Quilleaf keeps your money private

The safest place for your money data is one nobody else can reach. So Quilleaf keeps it on your device, and sends it only to your own Google Drive, if you ask it to. Here is how that works, exactly what leaves your device and when, and the limits we can’t fix for you.

In short

  • Your ledger lives on your device

    There is no Quilleaf account, and no Quilleaf server that holds your data.

  • The app sends your data to one place only: your own Google Drive, as a backup, if you turn that on

    Its only other trip online is asking Google Play about updates.

  • Backups can be locked with your password

    They’re then encrypted on your phone, with AES-256-GCM, before they’re uploaded.

  • No ads, analytics, crash reporting or trackers are in the app.

  • App lock, a secure screen and hidden amounts keep people near you from seeing your money.

Where your data lives

On your Android phone

  • Your ledger is a database in Quilleaf’s private storage on your phone. Android keeps other apps out of it.
  • Bank SMS records are kept in a separate database beside it. That one never goes into any backup.
  • Quilleaf doesn’t add a second layer of encryption to the database on your phone. It relies on Android’s storage encryption, which every phone that came with Android 10 or newer has.
  • Deleted SMS text is overwritten by SQLite in the database file, not just marked as free.

In the web app

  • Your ledger is a database in your browser’s storage, on that device only.
  • The web app has no server side that takes your data. Its code sends your ledger nowhere, and its security policy tells your browser to refuse connections to any site except app.quilleaf.com and Google’s sign-in and Drive addresses. Google sign-in and Drive aren’t switched on at app.quilleaf.com.
  • It sets no cookies, it can’t be shown inside another website’s page, and it has no access to your camera, microphone or location.

Not with us

We run no server that receives your ledger, your bank SMS or your backups. With no account and no copy of your data, there’s nothing of yours for us to look at, lose or hand over.

What leaves your device, and when

On Android, this is the complete list.

WhatWhere it goesWhen
Your backup: the ledger database, encrypted if you’ve set a backup passwordYour own Google Drive, in a folder called “Passbook backups”Only if you turn on Drive backup. When you leave the app and once a day, if something changed
The backup’s file name and labels: the date, a random install ID and your phone’s model nameYour Google Drive, with the backupWith each backup
Requests to list, download or delete the backups Quilleaf made, and nothing else in your DriveGoogle DriveWhen you restore or look at your Drive backups, and when older backups are cleared
A request for your Google account’s email addressGoogle DriveWhen you connect Drive, to show which account it uses
Google sign-in, to connect DriveGoogle Play services on your phoneWhen you connect Drive. Before each upload, it quietly renews that access
“Is there a newer version?”The Google Play Store app on your phoneEach time you open the app or come back to it. Nothing from your ledger
A request to remove Quilleaf’s access to your Google accountGoogleOnly when you ask for it while turning Drive off or erasing all data
Files you exportWherever you save themOnly when you export

Things that never leave your phone

  • Bank SMS records

    Never uploaded, and never in any backup. They leave only in files you export yourself: the SMS activity log export always lists what was read from each message, and message text goes only if you tick the box to include it.

  • Your backup password

    Never sent anywhere and never stored.

  • Your fingerprint, face and PIN

    Android checks them. Quilleaf never sees them.

  • The daily copies of your ledger, kept on your phone.

Android’s own backup is separate from Quilleaf’s. Backup to your Google account is off, and when you turn it on, Quilleaf’s data goes only if Android encrypts that backup end to end with your screen lock (Android 9 or newer). Phone-to-phone transfer is on, so a new phone set up from this one with a cable or over Wi-Fi gets your ledger (Android 9 or newer). Bank SMS records never go in either. You can change both in Settings → Privacy. Details

Encryption

How backups are encrypted

Set a backup password in Settings → Backups, and Quilleaf encrypts its backups before they leave your phone: Google Drive backups and the backup files you export.

  • CipherAES-256-GCM, done on your phone before upload. Every file gets a fresh random 12-byte nonce, and a 128-bit tag, so a file that’s been changed, or the wrong password, fails to open instead of opening wrong.
  • KeyMade from your password with PBKDF2-HMAC-SHA256, 310,000 iterations and a random 16-byte salt.
  • Your passwordAt least 8 characters, never sent and never stored. The key made from it is kept on your phone, itself encrypted with a key in the Android Keystore. That Keystore key can’t be copied off the phone, so on a new phone you type the password again.
  • No plain fallbackWhile a password is set, Quilleaf never uploads an unencrypted backup. If it can’t use the saved key, Drive backups pause until you type the password again.
  • Same format everywhereThe web app reads and writes the same encrypted files, using your browser’s built-in cryptography. A backup locked on your phone opens in the web app with your password.
  • Forgotten passwordNobody can open those backups. Not us, and not Google.

Without a password, Drive backups are plain database files, protected only by your Google account. The app labels them “Not encrypted” so you always know.

On your phone: lock, screen and notifications

  • App lock

    Off until you turn it on in Settings → Security. It uses Android’s own prompt: your fingerprint or face, or your phone’s PIN, pattern or password. Where Android allows it, only fingerprint and face unlock that Android rates as strong are accepted. Turning app lock on or off asks for them too.

  • Locks again on time

    Right away, or after 1, 5 or 30 minutes in the background. The timer counts from when the phone started, so changing the phone’s clock doesn’t skip it.

  • Secure screen

    On while app lock is on, unless you change it in Settings → Privacy. Quilleaf stays out of screenshots, screen recordings and screen casting, and Recents shows a blank card instead of your balances.

  • Hide amounts

    Tap the eye on Home, and every amount shows as ₹ ••••, in notifications too. Exports and backups keep the real figures.

  • Notifications

    When your phone hides sensitive notification content on the lock screen, Quilleaf’s notifications show there only as “New bank message read” or “Bills due soon”. With Hide amounts on, amounts are left out of notifications, locked or not.

  • Other apps

    Quilleaf reads notifications only from SMS apps and ignores every other app’s. New SMS reach the SMS edition only from Android itself. Text another app shares with Quilleaf never adds an entry on its own: it waits for you to check it.

What isn’t in the app

  • No advertising, analytics, crash-reporting or tracking code

    Besides Android’s own libraries, the app uses just two others, both Google’s: Google Play’s in-app updates, and the Google sign-in that connects Drive.

  • No access to your location, contacts, camera, microphone, phone calls, files or advertising ID

    Quilleaf doesn’t ask for them.

  • No way to move your money

    Quilleaf can’t make payments or send SMS. It never asks for your bank login, card number or UPI PIN.

The limits, plainly

No app can promise perfect security. Here is what Quilleaf can’t protect, so you can decide for yourself.

  • What Google sees when you use Drive

    Google stores your backups, so it sees their names, sizes, dates and labels, including your phone’s model name. Your Google account also shows that you gave the app access to your Drive. Without a backup password, Google, and anyone who gets into your Google account, can read the backups. With one, they see only encrypted data. Google’s privacy policy covers your Google account, Drive and Google Play.

  • What Cloudflare sees for our websites

    Quilleaf.com and app.quilleaf.com reach you through Cloudflare. Cloudflare decrypts and re-encrypts the connection, so it can see the requests and the pages themselves: your IP address, the pages and files you ask for (an APK download, say), and your browser’s details. It never sees your ledger, because the web app keeps it in your browser. Our own server keeps no access logs.

  • A rooted or compromised phone

    Quilleaf relies on Android’s protections. If your phone is rooted or has malware, or an app you don’t trust has Accessibility or Notification access, that app may be able to read your screen, your notifications or Quilleaf’s storage. Quilleaf can’t stop it. Keep Android up to date, and check which apps have those permissions.

  • Your SMS inbox

    Your bank SMS also sit in your messages app. Quilleaf only reads them, so they stay there, and other apps with SMS access can read them too.

  • Someone who knows your phone’s PIN

    App lock uses your phone’s own lock, so anyone who can unlock your phone can unlock Quilleaf. If the phone’s screen lock is removed, Quilleaf has nothing to check against. It says so, and lets you open it without a lock, since removing a screen lock already needs the old PIN.

  • The web app on a shared computer

    The web app has no app lock, and Quilleaf doesn’t encrypt the copy in your browser. Anyone who can use that browser can open it. Use your own device and browser profile, and use Settings → Erase everything when you’re done on someone else’s.

  • Copies you make

    Exports without a password can be read by anyone who gets them. Daily copies on the phone are protected by Android’s storage encryption, not by Quilleaf’s.

  • Downloads from our website

    Installing an APK means trusting the file. Check its SHA-256 before you install.

Report a security issue

Found a weakness in the app, the web app or this website? Please tell us.

Email support@quilleaf.com

Our security.txt has the same details. For anything else, see Contact us.

  • Email support@quilleaf.com with “Security” in the subject line.
  • Say what you found, how to make it happen, and which app version or web address it affects.
  • Please don’t send real bank SMS, balances or backup files, yours or anyone else’s. Made-up examples are all we need.
  • Give us a fair chance to fix it before you tell anyone else. We usually reply within a few days.