Lollet
Privacy policy
Encrypted and local by default. Cloud backup, sync and online rate lookup are optional.
Last updated 9 October 2026
Who provides Lollet
l2ita is a brand operated by Joe Al Sokhen, the developer and publisher of Lollet. This policy covers the web app at lollet.l2ita.com and its iPhone, iPad and Android apps.
Your wallet and recovery information
Lollet stores your encrypted wallet on your device. Your passphrase, recovery phrase and wallet decryption key are not sent to l2ita’s authorization service, Google or Apple. Lollet does not connect to banks or include advertising or wallet analytics. A compromised unlocked device or a weak passphrase can still expose your information.
Optional Google Drive connection
When you connect Google, Lollet requests your account identity and access to its hidden Drive app-data folder. It does not request access to your other Drive files. Google stores encrypted backup versions and encrypted synchronization revisions; it can see file sizes, timestamps and connection information.
The iOS app stores Google authorization credentials and the connected account’s identifier, email and display name inside the encrypted local vault and renews access when needed. The iOS app does not send these profile details to l2ita’s web authorization service. Google retains the account authorization connection, and Drive stores opaque backup and synchronization identifiers to provide the cloud functions you choose. Android uses Google Play services to obtain short-lived tokens from the permissions you have granted; it stores connection information in the encrypted vault and does not store a Google refresh token. On the web, l2ita’s authorization service stores an encrypted Google authorization grant, your Google account identifier, email and display name, and expiry and connection times. This lets the same browser renew access without asking you to sign in each hour. The browser receives a short-lived access token and an essential, secure session cookie; the refresh token remains on the server. The service does not receive your wallet content or decryption key. Sites hosts the website and service; its infrastructure and network providers can process request metadata such as your IP address.
Google data is used only to provide your chosen backup, recovery and synchronization functions. It is not sold, used for advertising, or used to train AI models. Lollet’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
iCloud and files
On supported Apple devices, iCloud uses the device’s Apple account without Sign in with Apple. Apple stores your encrypted cloud documents and associated file metadata. File exports go to your chosen location or recipient. Shared wallet copies use the password you choose and exclude other wallets and provider credentials.
Exchange rates
Online rate lookup runs when requested. Frankfurter receives currencies and a date to provide ECB reference rates or European Commission InforEuro monthly accounting rates. The service and its networks may see connection details, including your IP address. Lollet does not send transaction amounts, entries or wallet names. Manual and saved rates work offline. New estimates do not replace saved rates.
Downloaded public rate estimates are stored separately from your encrypted wallet for up to a year, with a 256-item limit. Clearing downloaded estimates does not change rates or source details already saved in your entries. Rate-review reminders are local and never contact rate providers.
Retention and removal
Your local wallets remain until you remove them. Cloud copies remain until you delete them through Lollet or your provider. Backup retention runs only after a successful new backup under the policy you choose. Lollet preserves the newest backup for each vault; sync history is kept separately. Disconnecting does not delete uploaded files or copies already shared.
Disconnecting Google on the web removes that browser’s server authorization record. Inactive web authorization records become unusable after 180 days and are removed during bounded maintenance on later connections. Routine infrastructure security logs may be retained under the hosting provider’s policies.
You can revoke Lollet’s Google access in your Google account connections. Removing a local wallet does not erase cloud copies. Removing browser cookies may require reconnecting Google. Provider revocation, account changes or provider policies can also require reconnection.
Deleting local wallets or clearing browser storage does not remove the web authorization record. To remove it immediately, disconnect Google in Backup & sync → Advanced before deleting your local wallets, or request removal at info@l2ita.com. Without disconnection, the inactive record follows the 180-day policy above.
Receipts, suggestions and reminders
Receipt attachments stay encrypted with their entries and are included in encrypted backups and sync. Name suggestions work offline; they do not connect accounts or detect subscriptions.
Optional notifications are scheduled on your device. Backup and rate-review reminders do not upload data. Trial and cancellation reminders hide service names and amounts. Notification permission and reminder choices are controlled separately on each device.
Support and privacy requests
Email info@l2ita.com for privacy questions and authorization-record removal requests. Support messages contain only what you choose to send and are used to address your request. Never send your passphrase, recovery phrase or decryption key. We cannot recover encrypted wallets without your recovery information.
For help using the app, email support@l2ita.com or visit Lollet support.
The web app is available now. The iPhone and iPad App Store release is coming soon. Open Lollet.