Skip to content

Privacy

The information needed to run Ledger.

This overview explains the main categories of information used to provide, secure, and support the application.

Last updated August 11, 2026

Information members provide

  • Account and profile information, such as a name, email address, optional username and phone number, date of birth, country, state, city, and time zone.
  • Financial records entered into the application, including accounts, transactions, categories, budgets, goals, investments, and related notes.
  • Preferences and settings used to tailor how the application behaves and displays information.
  • Information shared through supported family or collaborative features.

Technical and security information

Ledger uses limited technical information to operate and protect accounts. This can include:

  • Sign-in, session, and activity timestamps.
  • IP address, browser or device information, and approximate location associated with a session.
  • Request identifiers, error details, and security or administrative audit events.
  • Performance measurements provided through Vercel Speed Insights and privacy-limited client error reports such as the page route, viewport size band, online state, and an error fingerprint.

Infrastructure and authentication providers may process a full network address as part of delivering and securing the service. When Ledger displays an IP address in the Active Sessions screen, it is designed to show a privacy-minimized, masked address with only coarse approximate location information when available.

Passwords and multi-factor authentication codes should never be sent through support messages.

Information on a member's device

To support offline use, Ledger may keep selected cached information and pending transactions in the browser's local database. Those stored values use a browser-generated encryption key that stays on that device.

This local protection is not end-to-end encryption and does not make an unsafe or shared device safe. Members should use a device lock, keep the browser and operating system current, and sign out when a device is no longer trusted.

Browser storage can also retain display preferences, guide completion, report filters, and the last selected workspace so the interface remains consistent between visits.

How information is used

  • Provide the finance features a member is authorized to use.
  • Authenticate members, manage sessions, and enforce access controls.
  • Maintain the service, diagnose errors, and respond to support or security concerns.
  • Preserve security and administrative history where needed to protect the application and its users.

Service providers and access

Ledger relies on service providers for infrastructure, including Supabase for authentication and database services, Vercel for application hosting and delivery, and an email delivery provider for account-related messages. These services process information as needed to perform those functions.

Financial records are not published on this website. Inside the application, information is available only according to the member's account, role, assigned services, and supported workspace permissions.

Exports, deletion, and retention

Signed-in members can export a JSON copy of the profile, settings, personal finance records, supported balance snapshots, and group-membership summary currently included by the Settings export. The export is not a copy of every provider authentication record, security/audit event, access-control record, or every record owned by another member in a shared workspace. The downloaded file is then the member's responsibility to protect.

Settings also provides controls to clear personal finance data or request permanent account deletion. Deletion can require shared-finance ownership to be transferred or removed first. If shared records still belong to an active shared workspace, ownership may transfer to a remaining member rather than removing information that person still needs.

Append-only security and audit events may remain after account deletion with identifying labels removed. Ledger does not currently publish fixed retention periods for every application log, provider backup, or security-incident record, so this notice does not promise a single deletion deadline for those systems.

To ask about access, correction, export, or deletion, contact the operator through the trusted channel used for your invitation. Do not include passwords, authentication codes, or full financial records in the request.

View contact guidance
Ledger

An invite-only personal and family finance manager operated by Yash Jobalia.

Ledger is not a cryptocurrency wallet and is not affiliated with Ledger SAS or ledger.com.

© 2026 Yash Jobalia. Ledger is a private, independently operated application.