Running the business
Is it safe to keep business records only on your phone?
Safer than most people assume from a privacy angle, and riskier than they assume from a loss angle. The fix for the second is a backup, not a cloud account.
Modern phones encrypt app storage at rest and sandbox apps from each other. An app that writes only to its own storage is, in practice, well protected against other software on the device.
The real risk is not theft of the data, it is loss of the device. Phones get dropped, stolen and replaced. Any record that exists in exactly one place is one accident from gone — which is true of a filing cabinet too.
Export a backup monthly and store it somewhere else. That single habit converts the main weakness of local storage into a non-event.
What the actual risks are
"Safe" bundles four different questions that have four different answers.
- Can someone else read it? Only if they can unlock your phone.
- Can it be stolen remotely? Not from a device with no account and no server behind it — there is nothing to breach at the other end.
- Can I lose it? Yes. This is the real risk and it is much larger than the other two.
- Is it legally acceptable as a record? Yes, in every major tax system, provided you can produce the documents.
People worry about the second and neglect the third, which is exactly backwards.
Why a phone is better protected than most offices
Modern phones encrypt storage at rest by default, tied to your passcode and biometrics. App data is sandboxed so other apps cannot read it. Both platforms support remote wipe. That is a stronger baseline than a filing cabinet, an unencrypted laptop, or a shoebox of paper — which is what this is actually competing with for most sole traders.
It compares well against cloud storage too, in one specific way: a breach of a service exposes everyone on it at once, and you have no say in the matter. Data that never leaves your device is not in anyone's breach.
The real risk is loss, not theft
Phones get dropped, stolen, drowned and replaced. Any of those wipes out records held only on the device. This is the genuine exposure and the only reason a paper system was ever safer.
It is also completely solvable in under a minute: export a backup and keep it somewhere else. Moving to a new phone covers the mechanics, and losing a phone with your records on it covers what to do if you left it too late.
What tax authorities require
Broadly the same everywhere: keep records for a set number of years, and be able to produce them on request in a legible form. Five to seven years is typical, ten in places like Germany, France and Italy.
Two points people get wrong. Digital records are accepted — nowhere requires paper originals of invoices you issued. And "produce them" means the document itself, not a summary, which is why a spreadsheet of totals is not sufficient on its own. How long to keep invoice records covers the detail.
A five-minute hardening pass
- Use a real passcode. Six digits or an alphanumeric, not 0000. This is the entire lock on your business records.
- Turn on biometrics, which makes a strong passcode tolerable to live with.
- Enable find-my-device so remote wipe is available.
- Set a short auto-lock. A phone left unlocked on a counter is the realistic threat, not a hacker.
- Export a backup and put it somewhere else. The one that matters most.
Your clients' data is also your responsibility
An invoice app holds other people's names, addresses and contact details, which in most countries is personal data you are accountable for. Keeping it on one encrypted device you control is a defensible position and a simple one to explain. It is considerably easier to answer "where is my data held?" when the answer is "on my phone, and nowhere else".
EstimateBill does this on your phone with no account and no internet — the invoice is built, the PDF is made and the record is kept entirely on the device. See how it works, or build one in your browser first.