LocLedger

Privacy

Plain-English notes on how LocLedger handles your data. Last updated 2026-06-13.

Whose data lives here

LocLedger today is single-tenant. One loctician's data lives in one LocLedger instance, on infrastructure she controls. Client records, session notes, and photos belong to her — not to LocLedger, not to a third party, not to a parent company.

What we collect

What we don't do

Where data lives

The application database and uploaded photos live on a virtual private server administered by the project operator. Square sync data flows over Square's own API, signed with a per-deployment secret. Backups are the operator's responsibility.

Biometric photos

Photos of clients' hair, scalp, and (sometimes) face are sensitive. LocLedger treats them with the same care a working loctician would: stored privately, not shared without consent, and deletable on request. Full biometric-data retention infrastructure (including BIPA-jurisdiction conformance for Illinois and Texas clients) is in active development and will land before the project takes on clients from those jurisdictions.

Your right to walk away

A working data export and a one-click delete will land before LocLedger is offered to any peer loctician. Until then, the project operator can produce a full database export and physical-file dump on request, within a working day.

Contact

Privacy questions go to the project operator. Email is on the About page.