Ledgerly

Privacy Policy

Last updated August 31, 2026

Overview

This Privacy Policy explains how Ledgerly collects, uses, discloses, and safeguards information when you use our budgeting application. Ledgerly is built around a simple principle: your financial data belongs to you, is stored under your account with row-level access controls, and is never sold.

Information we collect

Account information. Your name, email address, and authentication credentials, handled by our authentication provider.

Financial data you provide or import. Accounts, transactions, categories, budgets, and savings pots that you manually enter, import (for example, via CSV), or bring in by connecting a bank account as described below.

Linked bank accounts. If you choose to connect a bank account, we use one of two providers to retrieve read-only balance and transaction data: Stripe Financial Connections, a hosted flow where you log into your bank directly inside Stripe's interface — Ledgerly never sees or stores your bank login credentials, and we request only balance and transaction access, not your account holder details or tokenized account/routing numbers; or SimpleFIN / SimpleFIN Bridge, where you provide a one-time setup token that we exchange for an access credential. That credential is encrypted at rest (AES-256-GCM) and used solely to fetch your balances and transaction history on your behalf. Connecting a bank account is optional — manual entry and CSV import remain available without it.

Receipt photos. If you use the receipt-scanning feature, the photo you capture is compressed on your device and sent to our OCR provider, OCR.space, solely to extract the merchant, amount, date, and category for the transaction you're creating. We do not retain the photo itself after that request completes; only the resulting transaction fields you save are stored in your account.

AI coach conversations. Messages you send to the AI coach and the coach's replies are stored so your conversation history persists between sessions. To answer your questions, the coach is given a compact summary of your financial data (balances, recent spending, budgets, and pots) for the duration of that request.

Usage data. Basic technical information such as device/browser type, collected through Vercel Analytics, which does not use cookies and reports usage in aggregated, anonymized form to help us understand how the app is used and improve reliability.

How we use your information

  • To provide, maintain, and secure your account and the features you use.
  • To retrieve and sync balances and transactions for any bank account you choose to connect.
  • To extract transaction details from a receipt photo you submit via the scanning feature.
  • To generate the AI coach’s responses to your questions, grounded in your own data.
  • To apply changes you explicitly approve (such as budget or pot updates proposed by the coach).
  • To detect, investigate, and prevent fraud, abuse, or security incidents.
  • To improve the Service through aggregated, de-identified analysis.

AI processing and third-party model providers

The AI coach's responses are generated through OpenRouter, a third-party AI model routing service, using your question and the financial summary described above. Data-training practices vary by the specific downstream model provider a given request is routed to; where OpenRouter offers a setting to exclude a request from a provider's training pipeline, we configure our account to use it. This data is transmitted solely to produce your answer and is not used by Ledgerly to build advertising profiles. Review OpenRouter's own privacy documentation if you have specific compliance requirements.

How we protect your data

  • Data is stored in a managed Postgres database with row-level security, so each account can only read or write its own records.
  • Passwords are never stored in plain text; authentication is handled by our identity provider using industry-standard hashing.
  • Bank-linking credentials obtained via SimpleFIN are encrypted at rest with AES-256-GCM; Stripe Financial Connections never exposes bank login credentials to Ledgerly at all.
  • Connections to the Service are encrypted in transit.
  • Access to production data is limited to what is required to operate the Service.

No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

Data retention and deletion

During your account: We retain your account and financial data for as long as your account is active. You may delete individual transactions, budgets, or pots at any time within the app, disconnect a linked bank account at any time (which stops future syncing but does not automatically delete transactions already imported), and clear your AI coach conversation history at any time. Receipt photos are not retained beyond the single scan request.

After account deletion: To request full account deletion, email privacy@ledgerly.loan. We will delete your personal and financial data within 30 days, except where retention is required by law. Backups containing your data may persist for up to 90 days as part of standard database backup practices, but will not be directly accessible or restored unless legally required.

Sharing of information

We do not sell your personal or financial information. We share data only with:

  • Service providers who host our database, authentication, and hosting infrastructure, solely to operate the Service on our behalf.
  • OpenRouter (and the AI model provider it routes a given request to), solely to generate AI coach responses.
  • OCR.space, solely to extract transaction details from a receipt photo you submit.
  • Stripe Financial Connections and/or SimpleFIN / SimpleFIN Bridge, solely to retrieve balances and transactions for bank accounts you choose to connect.
  • Authorities, when required to comply with a legal obligation, protect our rights, or ensure user safety.

Your rights and choices

General: You can exercise most rights directly within the app (editing or deleting accounts, transactions, budgets, and pots, or disconnecting a linked bank account). For requests the app does not support, email privacy@ledgerly.loan.

European Union (GDPR): If you are in the EU, you have the right to access, correct, export (data portability), and delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact privacy@ledgerly.loan. You also have the right to lodge a complaint with your national data protection authority.

California (CCPA): If you are a California resident, you have the right to access, delete, and opt-out of the sale of personal information. We do not sell personal information. To exercise CCPA rights, contact privacy@ledgerly.loan.

Children's privacy

The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children.

Data breaches

In the event of a confirmed or suspected data breach, we will notify affected users without unreasonable delay and in accordance with applicable law (GDPR, CCPA, state breach notification laws, and others). Notifications will be sent to the email address in your account and posted to the app.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

Contact

Questions or concerns about this Privacy Policy, your personal data, or privacy practices can be sent to: privacy@ledgerly.loan