Lollet

Lollet

Privacy policy

Who provides Lollet

l2ita is a brand operated by Joe Al Sokhen, the developer and publisher of Lollet. This policy covers the web app at lollet.l2ita.com and its iPhone, iPad and Android apps.

Your wallet and recovery information

Lollet stores your encrypted wallet on your device. Your passphrase, recovery phrase and wallet decryption key are not sent to l2ita’s authorization service, Google or Apple. Lollet does not connect to banks or include advertising or wallet analytics. A compromised unlocked device or a weak passphrase can still expose your information.

Optional Google Drive connection

When you connect Google, Lollet requests your account identity and access to its hidden Drive app-data folder. It does not request access to your other Drive files. Google stores encrypted backup versions and encrypted synchronization revisions; it can see file sizes, timestamps and connection information.

The iOS app stores Google authorization credentials and the connected account’s identifier, email and display name inside the encrypted local vault and renews access when needed. The iOS app does not send these profile details to l2ita’s web authorization service. Google retains the account authorization connection, and Drive stores opaque backup and synchronization identifiers to provide the cloud functions you choose. Android uses Google Play services to obtain short-lived tokens from the permissions you have granted; it stores connection information in the encrypted vault and does not store a Google refresh token. On the web, l2ita’s authorization service stores an encrypted Google authorization grant, your Google account identifier, email and display name, and expiry and connection times. This lets the same browser renew access without asking you to sign in each hour. The browser receives a short-lived access token and an essential, secure session cookie; the refresh token remains on the server. The service does not receive your wallet content or decryption key. Sites hosts the website and service; its infrastructure and network providers can process request metadata such as your IP address.

Google data is used only to provide your chosen backup, recovery and synchronization functions. It is not sold, used for advertising, or used to train AI models. Lollet’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

iCloud and files

On supported Apple devices, iCloud uses the device’s Apple account without Sign in with Apple. Apple stores your encrypted cloud documents and associated file metadata. File exports go to your chosen location or recipient. Shared wallet copies use the password you choose and exclude other wallets and provider credentials.

Exchange rates

Online rate lookup runs when requested. Frankfurter receives currencies and a date to provide ECB reference rates or European Commission InforEuro monthly accounting rates. The service and its networks may see connection details, including your IP address. Lollet does not send transaction amounts, entries or wallet names. Manual and saved rates work offline. New estimates do not replace saved rates.

Downloaded public rate estimates are stored separately from your encrypted wallet for up to a year, with a 256-item limit. Clearing downloaded estimates does not change rates or source details already saved in your entries. Rate-review reminders are local and never contact rate providers.

Retention and removal

Your local wallets remain until you remove them. Cloud copies remain until you delete them through Lollet or your provider. Backup retention runs only after a successful new backup under the policy you choose. Lollet preserves the newest backup for each vault; sync history is kept separately. Disconnecting does not delete uploaded files or copies already shared.

Disconnecting Google on the web removes that browser’s server authorization record. Inactive web authorization records become unusable after 180 days and are removed during bounded maintenance on later connections. Routine infrastructure security logs may be retained under the hosting provider’s policies.

You can revoke Lollet’s Google access in your Google account connections. Removing a local wallet does not erase cloud copies. Removing browser cookies may require reconnecting Google. Provider revocation, account changes or provider policies can also require reconnection.

Deleting local wallets or clearing browser storage does not remove the web authorization record. To remove it immediately, disconnect Google in Backup & sync → Advanced before deleting your local wallets, or request removal at info@l2ita.com. Without disconnection, the inactive record follows the 180-day policy above.

Receipts, suggestions and reminders

Receipt attachments stay encrypted with their entries and are included in encrypted backups and sync. Name suggestions work offline; they do not connect accounts or detect subscriptions.

Optional notifications are scheduled on your device. Backup and rate-review reminders do not upload data. Trial and cancellation reminders hide service names and amounts. Notification permission and reminder choices are controlled separately on each device.

Support and privacy requests

Email info@l2ita.com for privacy questions and authorization-record removal requests. Support messages contain only what you choose to send and are used to address your request. Never send your passphrase, recovery phrase or decryption key. We cannot recover encrypted wallets without your recovery information.

For help using the app, email support@l2ita.com or visit Lollet support.