Financial Ledger Back to home

Privacy Policy

Effective date: July 10, 2026  ·  Version: 1.1

This Privacy Policy describes how Financial Ledger (“Financial Ledger,” “we,” “us,” “our”) collects, uses, and protects your personal and financial information when you use our Service. Because we handle your financial data, we are subject to the Gramm-Leach-Bliley Act (GLBA). Please also read our separate GLBA Financial Privacy Notice.

1. Information We Collect

1.1 Information You Provide

  • Account registration: name, email address, password (hashed)
  • Business profile: business name, entity type, tax year
  • Uploaded documents: PDF bank statements (deleted after 30 days)

1.2 Financial Data via Plaid

When you connect a bank account via Plaid, we receive:

  • Account name, type, and last 4 digits (mask)
  • Transaction history: date, amount, merchant name, category
  • Encrypted Plaid access token (not your bank credentials)

We never receive or store your bank username, password, or security questions.

1.3 Automatically Collected Data

  • IP address (hashed for consent records, not stored in raw form)
  • Browser/device type (user agent)
  • Usage logs (pages visited, features used)
  • Stripe payment metadata (we never see your card number)

1.4 Consent Records

We record when you consent to our Terms, Privacy Policy, GLBA Notice, Plaid data access, and statement uploads. This is required for GLBA compliance and audit purposes.

2. How We Use Your Information

  • Provide and operate the Service (expense categorization, tax estimates, exports)
  • Process payments via Stripe
  • Send transactional emails (account confirmation, billing receipts, renewal reminders)
  • Apply your corrections to your ledger so reports reflect the categories you approve (your data is never used to train external AI models)
  • Comply with legal obligations (GLBA, CCPA, IRS recordkeeping)
  • Detect fraud and protect security

We do not use your financial data for advertising or sell it to third parties.

3. Data Sharing & Subprocessors

We share data with the following service providers only to operate the Service:

SubprocessorPurposeData Shared
Plaid Inc.Bank connectivityUser ID, access tokens
Stripe Inc.Payment processingEmail, billing address, subscription status
Supabase Inc.Database & file storageAll account and transaction data (encrypted at rest)
Anthropic PBCAI transaction extraction & categorizationContents of uploaded statements and receipts, and transaction descriptions (not used to train Anthropic's models per our API agreement)
Resend (Plus Five Five, Inc.)Transactional email deliveryEmail address, name, and the contents of emails we send you (e.g. weekly summaries)
Vercel Inc.Hosting & CDNRequest logs (IP, user agent)

We may disclose your information if required by law, court order, or to protect our legal rights. We will notify you of such requests where legally permitted.

4. Data Retention

  • Uploaded PDFs: Automatically deleted 30 days after upload
  • Transaction data: Retained while your account is active
  • Account data: Deleted within 30 days of account deletion request
  • Consent records: Retained for 7 years (GLBA requirement)
  • Audit logs: Retained for 3 years
  • Stripe billing records: Retained per Stripe's policy (7 years)

5. Data Security (GLBA Safeguards Rule)

We implement the following security measures required by the GLBA Safeguards Rule:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 via Supabase)
  • Row-Level Security policies — users can only access their own data
  • Access tokens encrypted in database storage
  • Private storage buckets with per-user access controls
  • IP address hashing before storage
  • Audit logging of sensitive actions (connections, uploads, exports)
  • Regular dependency updates and vulnerability monitoring

6. California Consumer Privacy Act (CCPA / CPRA)

If you are a California resident, you have the following rights:

  • Right to Know: Request what personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale: We do not sell personal information, so this right is not applicable
  • Right to Non-Discrimination: We will not discriminate against you for exercising these rights

To exercise your rights, email support@financialledger.app or use Settings → Privacy & Data.

Do Not Sell or Share My Personal Information: We do not sell or share your personal information with third parties for advertising. No opt-out required.

7. Other State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states with privacy laws may also have rights to access, correct, or delete their data. Contact us at support@financialledger.app to exercise these rights.

8. Cookies

We use essential cookies for authentication and functional cookies for user preferences. See our Cookie Policy for details.

9. Children's Privacy (COPPA)

The Service is not directed at children under 13. We do not knowingly collect information from children under 13. If we become aware of such data, we will delete it immediately.

10. Data Breach Notification

In the event of a data breach that may affect your personal information, we will notify affected users without unreasonable delay and within the timeframes required by applicable federal and state law, via email and/or notice on our website.

11. Changes to This Policy

We will provide 14 days' notice of material changes by email. The current version and effective date are shown at the top of this page.

12. Contact

Financial Ledger  ·  Privacy inquiries: support@financialledger.app