Lastly — Privacy Policy
Last updated: September 7, 2026
Every debt, payment, and preference you enter is stored in a local database on your own device. Lastly has no user accounts, no sign-up, and no server or backend of any kind — we never see your data. The only third party involved is Google: its AdMob service shows ads in the app. Nothing you enter is included in Google's cloud backup.
You can see all of this stated from the app itself, read from the version running on your phone, at Settings → Privacy → Privacy report.
Data you enter
Debts, scheduled payments, recorded charges, bills and subscriptions, sinking funds, your paydays — including the take-home amount, if you choose to enter one — and settings (currency, date format, debt ceiling) are saved in a local database on your device. The app itself never transmits this data anywhere: it has no server, and we have no way to see it.
What we don't collect: no bank credentials, no account or card numbers, no automatic transaction detection, no location, no contacts. Everything the app knows, you typed in yourself.
You can delete everything at any time via Settings → Clear all data, or by uninstalling the app.
Device backup
Nothing you enter is included in Google's cloud backup. Lastly opts out of it entirely — your debts, payments and settings are not copied to Google Drive or to any account, so a reinstall or a "restore from backup" during setup starts the app empty.
A direct phone-to-phone transfer during device setup does carry everything across; that copy never leaves the two devices involved.
Your own backup file
Settings → Backup → Back up saves everything to a file you choose the location of. That file is yours: we never see it, and where it goes is entirely your decision.
- Sealing it. You can set a passphrase in Settings → Backup → Passphrase. New backup files are then encrypted with it (PBKDF2-HMAC-SHA256 and AES-256-GCM), so a copy left in a shared or cloud-synced folder cannot be read without it. The passphrase never leaves your device and is never stored anywhere in readable form. There is no hint, no reset and no recovery: if you lose the passphrase, neither you nor we can open those files. Files you saved before setting or changing a passphrase are unaffected.
- Automatic backups. You can point Lastly at a folder on your device and it will write a backup there once a week. The app is granted access to that one folder and nothing else, it only ever deletes its own older backup files, and it never touches anything else in the folder. If the folder you pick is one that syncs to a cloud service, that is your choice and made outside this app — Lastly has no way to know where the folder ends up, and no involvement in it.
App lock
Settings → Privacy → App lock asks for your device's own screen lock — fingerprint, face, PIN or pattern — when you open Lastly. The app never creates or stores a PIN or password of its own, and no biometric data reaches Lastly: your phone answers yes or no, and that is all we receive. A phone with no fingerprint or face unlock is asked for its PIN, pattern or password instead. If you remove your phone's screen lock later, Lastly stops asking rather than locking you out; set one again and the lock resumes on the next open.
While the lock is on, the app's window is marked secure, so its contents do not appear in the app switcher and screenshots are blocked, and daily reminders show a placeholder on your lock screen instead of any debt, provider or amount.
This protects the app's own screens on a phone in someone else's hand. It does not encrypt the database — Android's own device encryption protects that while your phone is locked or powered off.
Advertising
Google AdMob serves ads in the app. To do this, Google's Mobile Ads SDK may process your device's advertising identifier, IP address, and general device/app information, under Google's own privacy practices:
We do not receive, store, or share any of this information ourselves.
Your choices (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you will be shown a consent form before any ad-related data processing begins. You can change your choices at any time via Settings → Privacy → Ad privacy options.
Your choices (United States)
Lastly itself does not collect, sell, or share your personal information. Ad-related data handled by Google's SDK is described above; you can limit ad personalization on your device via Android's Settings → Google → Ads (delete or reset your advertising ID), and where the in-app Settings → Privacy → Ad privacy options control is available in your region it applies here too.
Data ownership and deletion
Because nothing is stored on our servers, you keep full control of your information. Deleting the app's data (Settings → Clear all data) or uninstalling the app removes everything you entered, along with the app lock setting, the stored backup passphrase key and the automatic-backup folder. It does not reach backup files you have already saved — those are your copies, in a place you chose, and deleting them is done the same way you would delete any other file on your device.
Security
Your data is protected by your device's own security: the app's storage is sandboxed by Android, and Android encrypts it while your device is locked or powered off. We recommend using a screen lock — and if you have one, Settings → Privacy → App lock puts it in front of Lastly too. The app adds no accounts or passwords of its own; the only secret it can hold is the optional backup passphrase, which never leaves your device and which we have no copy of. There is nothing of yours on our side to breach.
Children
Lastly is intended for adults and is not directed at children under 13. We do not knowingly collect data from minors.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a new "Last updated" date.
Contact
Questions about this policy: bomeko.soft@gmail.com