Goshuin Ledger

No account, stored on the device: how to choose a goshuin record app

There are goshuin record apps you can use without signing in, but “no sign-in” does not go as far as saying your records never leave the phone. Before you choose, check four things: where the privacy policy says records are sent; whether the export is only a backup that goes back into the same app, or also a readable form such as CSV or PDF; the reason given for each permission it asks for; and how much works without a purchase. Decide first which of the four — no account, stored on the device, no advertising, no network — matters most to you, and you will know where to look.

Published: (last updated: ) by 友田 陽大 (the developer of Goshuin Ledger)

The key points of this article

  • “No account”, “stored on the device”, “no advertising” and “no network” are four separate claims: one of them being true tells you nothing about the other three
  • Before you ask whether it is a one-time purchase or a recurring one, ask whether you can get your records out after you stop paying
  • An export comes in two kinds — a backup that goes back into the same app, and a readable export such as CSV or PDF — and only the second lets you read your records outside the app
  • When you pick the shrine or temple from a built-in list, its location is attached to the record, so how much of the place you keep depends on how the app is designed
  • Four things to check: where the policy says records go, which kind of export there is, the reason for each permission, and how much works without a purchase

This article covers one thing: how to check where a goshuin record app keeps your records, and where it sends them. It does not compare named apps, so as not to assert what cannot be verified from outside.

Are there goshuin record apps you can use without signing in?

There are. But “no sign-in” and “your records never leave the phone” are not the same claim. Choose with those two run together and you end up with something other than what you thought you were getting.

A goshuin record is a list of when you went where, and for some people it is also a record of religious practice. It is natural that so many people care where that list is held, and plenty of apps say something reassuring about it. The trouble is that the words they use point at quite different things.

The four claims people run together are four different claims

“No account”, “stored on the device”, “no advertising” and “no network” can each be true on their own without making any of the other three true. Here is what each one actually says, and what can still be happening while it is true.

The claim What it says What can still happen
No account You can start using it without registering Records are sent out together with something that identifies your device
Stored on the device The records are on your phone It connects for some other purpose
No advertising No adverts are shown Records are sent to the developer
No network It never connects If the phone breaks, the records go with it

You do not need all four. What matters is deciding first which one you actually care about.

  • You don’t want anyone else seeing what is in your records → look at whether they are stored on the device
  • You don’t want the bother of registering → look at whether an account is required
  • You don’t want to be interrupted while you work → look at whether there is advertising
  • You want it to work with no signal → look at whether it needs a network

If one of them is your reason, there is only one thing to check.

The payment model changes it too

One-time or recurring, the first thing to check is whether you can get your records out after you stop paying. How you pay is not unrelated to how you hold the records.

A single payment is done once and nothing follows it, so the longer you use the app the less it has cost you. The other side of that is that the developer has no continuing income, and updates can thin out.

A recurring payment buys you a reason to expect updates for as long as you keep paying. The other side of that is that the app can stop working the moment you stop.

Where you cannot confirm that your records come out after you stop paying, the safer answer is to walk away, whatever the payment. Years of visits becoming unreadable the moment a payment stops is the one outcome worth choosing against.

The same fork arrives when you change phones. What to settle about getting your records out before you move to a new device is written up separately.

How much of the location do you keep?

In an app where you pick the shrine or temple from a built-in list, the location of the one you picked is attached to the record. If you want to decide record by record whether a location is kept at all, an app where you type the name yourself suits you better. This gets overlooked far more often than the question of where the records are held.

An app that lets you search and pick a place is carrying a list of shrines and temples with their locations. That is convenient for drawing a map, but it also means a list of when you went where, each entry with a location attached, is sitting on your phone.

A design with no built-in list is perfectly possible: you type the name of the shrine or temple, and only when you want a location do you tap the map to drop a pin. You lose the convenience of searching, and you gain a place that appears on no list, recorded by exactly the same steps.

Neither is the better design; they put different things first. What is worth looking at either way is whether an app that asks for location permission says what it needs the permission for.

What changes when a record is not built for sharing

In an app built around posting and publishing, keeping a record to yourself means finding the private setting — and where public is the default, you can end up visible to other people without ever noticing. A record in an app with no sharing mechanism cannot be published inside the app at all.

Some people want to show their goshuin records to others; some have no wish to at all. Neither is the right answer, but which one you are is worth settling before you choose. Even when you do want to show them, there are things to take out before anyone else sees them: your own notes to yourself, and anything that gives away where you live.

The checklist you can run yourself

Four things: where the privacy policy says records go, which kind of export there is, the reason for each permission, and how much works without a purchase. The store description will not answer any of them, so go through them one at a time.

  1. Does the privacy policy say where records are sent? If nothing is sent, it should say that nothing is sent. Silence is not evidence that nothing is sent.
  2. Is there an export? With one, your records stay in your hands even after you stop using the app. But an export comes in two kinds: a backup meant to go back into the same app, and a readable export — CSV, PDF — for a spreadsheet or for paper. If the backup opens in that app and nowhere else, the second kind is the only one that lets you read your records after you leave.
  3. Can each permission it asks for be explained by a feature? Location and photos alike: there should be an answer to what it is for.
  4. How much works without a purchase? Better to know that up front than to build a pile of records and then find out that a purchase is required.

How the app I make handles this

The app I develop, Goshuin Ledger, needs no sign-in and no account registration, and keeps records and photos on the device. In exchange, it does not sync records between devices. For reference, here it is in the order of the checklist above.

Records and photos are never sent out of the app, and no advertisements are shown. It is not the case that it never connects, though: it does when it draws the map, and when a purchase is made or restored through the App Store. What is sent and where it goes is set out in the privacy policy.

The records on the device are included in the standard iOS backup and transfer (iCloud Backup and Quick Start). Separately from that, you can export an encrypted file — the backup — with a passphrase, and import it on a new phone. Its contents cannot be read by opening it, and if you forget the passphrase, nothing can be brought back from that file. The form that makes your records readable outside the app is the PDF / CSV export.

It never asks for location permission and stores no addresses. Keeping a location is optional; when you keep one, you tap the map to drop a pin. It only receives the photos you chose in the iOS photo picker, and never asks for permission to read your whole photo library.

Without a purchase, the first book records as many entries as you like, and exporting and importing the backup work as well. A second book and beyond, adding two or more imported photos to a book in one action, and the PDF / CSV export come with the one-time Ledger Full. There is no subscription. What the purchase covers is set out on the pricing section, and the App Store shows the current price.

The run from importing the photos to seeing them settle into books and pages is in how to organise the goshuin photos piled up on your phone into a record afterwards.

Frequently asked questions

If I delete the app, what happens to the records stored on the device?
On iPhone, deleting an app deletes the records it kept on the device along with it. If all you want is the storage back, go to Settings → General → iPhone Storage, pick the app and use “Offload App”: the app itself goes and its documents and data stay. Before you delete anything, make a backup and a readable export, and put both somewhere outside the phone.
What difference does it make that the records are stored on the device?
They are not held on the developer’s servers, so they cannot disappear along with a server that stops running. In exchange, carrying them to a new phone is something you do yourself, and the photos take up space on the device.
If I cancel a subscription app, can I still read my records?
An App Store subscription normally keeps working until the period you have already paid for runs out. Whether you can still open or export your records after that differs from app to app, and the store description does not always say. Make an export you can read — in a spreadsheet, or on paper — before you cancel, and your records stay in your hands either way.
Why does an app ask for location permission?
It needs it if it offers to find shrines and temples near you, or to record where you visited on a map for you. If you do not want either, you can choose an app that never asks. When you are asked, you can pick “Allow Once”, “Allow While Using App” or “Don’t Allow”, and you can change your answer later in Settings → Privacy & Security → Location Services.
Can I judge an app from the App Privacy section on the App Store alone?
It is a useful guide, but not enough on its own. The “App Privacy” section on a product page is what the developer declared, and it shows either “Data Not Collected” or the kinds of data that are collected. What is sent, where it goes and when is in the privacy policy, so read both and check that the two do not contradict each other.