Privacy Policy

Effective 30 September 2026

Ledger is a personal-finance record-keeping app operated by Shreyansh Jain (“we”, “us”). This policy covers the Ledger web app and its connector for AI assistants such as Claude and ChatGPT. Ledger records what you tell it: it never moves money, connects to your bank, or initiates a payment.

What we collect

  • Account details — your username, a bcrypt hash of your password (never the password itself), your optional UPI ID, and your preferences such as theme, amount masking and default accounts.
  • Ledger content you enter — accounts and categories, transactions with their amounts, descriptions and dates, tags, templates, tax classifications, and any files you attach to a transaction.
  • Linked-account data — when an account in your ledger is linked to another user, the shared lines of a transaction (amount, description and date) are copied into both ledgers, together with the approval requests between you.
  • AI connector data — when you connect an AI assistant, we store its client registration and hashed access and refresh tokens tied to your account. We receive only the tool calls the assistant makes for you: the arguments it sends and the results we return. We never receive or read your conversation, the assistant’s memory, or your chat history.
  • Push notifications — if you turn them on, your browser’s push subscription (an endpoint address and encryption keys), plus a record of each notification sent to it — when it was sent, and whether your device showed and opened it — which the person whose request it was can see, kept for 30 days.
  • Technical data — your IP address, used only for rate limiting and held in our cache for at most an hour; per-request performance measurements (the page, timings and database query counts) linked to your account ID; page-speed measurements with no account attached; and error reports.

There are no advertising or analytics trackers. The only cookie is ledger_token, an HTTP-only session cookie that keeps you signed in.

How we use it

Only to run Ledger for you: storing your entries and computing balances, net worth, returns and tax figures; showing shared transactions to the user they are linked with; sending the notifications you turn on; protecting accounts through rate limiting and session revocation; and diagnosing errors and slow pages. We do not sell your data, use it for advertising, or use it to train AI models.

Who receives it

  • Service providers that run Ledger — Vercel (application hosting and private file storage), Neon (PostgreSQL database), a managed Redis service (short-lived cache), Sentry (error monitoring, configured to collect no request bodies, headers, cookies, IP addresses, query parameters or variable values), and GitHub (private storage for nightly database backups). They process data on our behalf, possibly outside your country.
  • Other Ledger users — only as described under linked accounts. Another user who knows your exact username can look up your account in order to link it.
  • AI assistants you connect — results of the tools the assistant calls go to that assistant’s provider (for example Anthropic or OpenAI) and are governed by its privacy policy. You choose whether to connect one, and can disconnect it at any time.
  • Push services — your browser vendor’s push service delivers notifications; their contents are encrypted end to end to your browser.
  • Market-data sources — Yahoo Finance and AMFI are queried by ticker or scheme to price assets. No personal data is sent.
  • Authorities — when the law requires it.

How long we keep it

  • Your account, ledger entries and performance records: until you delete them or ask us to delete your account.
  • Database backups: 30 days, so deleted data is gone from backups within 30 days.
  • Attachments: removed from storage when deleted; a weekly job clears anything left behind.
  • AI connector tokens: access tokens expire after 1 hour and refresh tokens after 90 days, rotating on each use. Attachment upload links expire after 10 minutes and work once.
  • Rate-limit counters: at most one hour. Error reports: up to 90 days, per Sentry’s retention.

Your choices

  • Export your data at any time from Settings → Data (CSV, Excel or SQL).
  • Correct or delete any entry in the app or through the connector. To delete your whole account, contact us and we will do so within 30 days.
  • Disconnect an AI assistant from that assistant’s own connector settings; it then stops receiving new tokens.
  • Turn off push notifications in Settings → Preferences or in your browser.

Depending on where you live you may have further rights — for example to access, correct or erase your data under India’s Digital Personal Data Protection Act, 2023. Contact us to exercise them.

Security

All traffic uses HTTPS. Passwords are stored as bcrypt hashes; OAuth codes, access and refresh tokens, and attachment upload links are stored only as SHA-256 hashes. Attachments sit in a private store and are served only to their owner, and every database query is scoped to the signed-in user.

Children

Ledger is not intended for anyone under 18.

Changes

When this policy changes we update the effective date above, and for material changes we tell you in the app.

Contact

Questions or requests: the operator of this Ledger instance. See also the connector documentation.