Privacy Policy
This policy explains what Ledgerly collects, why we collect it, who we share it with, and the choices you have. Ledgerly is a personal bookkeeping app for individuals, freelancers, and side-business owners. The default language is English and the default currency is US dollars.
What we collect
Account data
- Email address.
- Password. We store it as an Argon2 hash and cannot read the original.
- Display name.
- Country code.
- Time zone.
- Default currency.
Financial data
- Accounts: name, type, currency, balance.
- Categories.
- Transactions: date, amount stored as integer cents, merchant name, description, notes, expense scope, and a tax-deductible flag.
- Budgets.
Import data
- CSV text that you paste or share into the app.
- Staged import rows.
- Merchant rules learned when you correct a category.
Subscription data
- Store name.
- Product identifier.
- Original transaction identifier.
- Subscription status.
- Period start and end dates.
- Environment (sandbox or production).
We do not collect or process card numbers. We do not integrate Stripe. We do not process credit cards ourselves.
Technical logs
- Request method, path, HTTP status code, duration, and request id.
We do not log request headers or request bodies. IP addresses are held briefly in memory only for rate-limit counting. We do not store them in a database and do not write them to logs.
What we do not collect
- Bank login credentials.
- Card numbers.
- Precise location.
- Address book (contacts).
- Camera access.
- Advertising identifiers.
We use no advertising SDK, no analytics SDK, and currently no crash-reporting SDK.
Why we collect it
We use this data to provide the bookkeeping service: to authenticate you, store your accounts and transactions, run budgets, process imports, and verify your subscription. We do not use your financial data for advertising or analytics.
Who we share data with
Optional AI categorization
AI categorization is an optional feature, and it is off until you agree to it. Before anything is sent, the app shows you exactly what would leave the device and asks for your consent; your answer is recorded on your account so you can see and change it later.
When you have agreed, we send the following to the AI provider only:
- A normalized merchant name.
- A description truncated to 200 characters.
- Direction (income or expense).
- An amount range (under 25 USD, 25 to 200 USD, or over 200 USD).
- Your own category names.
We never send the exact amount, your email, account ids, balances, transaction ids, or dates. AI results are suggestions only. They are written to your ledger only after you confirm them.
You can withdraw your consent at any time in Settings. Imports continue to work without it — rows simply arrive uncategorized, and the same is true if the AI provider is unavailable.
Apple App Store Server API
We use the App Store Server API to validate subscriptions. We send the transaction identifier to Apple for this purpose.
Hosting and database provider
We store data with our hosting and database provider at [TODO: hosting provider].
How long we keep data
We keep your data for as long as your account is active. When you request deletion, we apply a 30-day grace period and then remove your financial details and anonymize your account. See Account Deletion for details.
Your rights
Access and export
You can export all of your data at any time in CSV or JSON. See Data Export for what is included. Export is a Pro feature.
Correction
You can edit your accounts, categories, transactions, and budgets at any time in the app.
Deletion
You can request account deletion from inside the app. You must re-enter your password to confirm. After a 30-day grace period we delete your financial details and anonymize your account. See Account Deletion for the full process.
Contact
Questions about this policy can be sent to [TODO: privacy contact email].
Children
Ledgerly is not directed to children under 13, and we do not knowingly collect data from children under 13.
Changes
If we change this policy, we will post the updated version in this location and update the date below. For material changes we will notify you in the app.
Last updated: [TODO: effective date]