Privacy Policy
Ledger AI is a business copilot: it connects to the tools you already run your business on and answers questions about your own data. This page explains, plainly, what we collect, why, where it lives, who else touches it, and how to get rid of it.
What we collect, and why
We only collect what's needed to run the features you turn on. Every connection below requires your explicit OAuth consent — nothing connects itself.
- Account & billing — your name, email, and subscription status, so you can sign in and we know your plan is active. Card details are handled entirely by Stripe; they never reach our servers.
- QuickBooks Online — invoices, customers, and sales/P&L data, so the assistant can answer questions about your books and, when you ask it to, draft invoices or expenses. Nothing posts to QuickBooks without your confirmation.
- Gmail — read access to find supplier receipt and invoice emails for the Receipt Radar feature, so incoming costs get captured automatically instead of you forwarding them by hand.
- Google Calendar — read and create access, so the assistant can tell you what's booked and add appointments you ask it to schedule.
- Google Business Profile — your business reviews, so the assistant can surface and help you respond to them.
- Receipt photos — images you snap of paper receipts, stored privately and accessed only through signed, time-limited URLs.
- Conversations with the assistant — what you type or say, plus the business data needed to answer it, so the assistant can hold a conversation and remember context within a session.
- Usage metering — token counts and cost per request, so we can enforce your plan's monthly AI allowance.
Where it lives
Your account data, receipts, and conversation history are stored with Supabase (database, authentication, and file storage), running in their cloud infrastructure. Receipt images are kept in private storage and served only through signed URLs that expire — they are not publicly accessible.
Who processes it
We don't build our own AI models or payment rails — we use a small number of named processors to run the service:
- Anthropic (Claude models) — receives your conversation content and the business data needed to answer it, as the processor behind the AI assistant's text responses.
- OpenAI (Realtime API) — receives audio/conversation content when you use voice mode, as the processor behind spoken conversations.
- Supabase — hosts our database, authentication, and file storage.
- Stripe — processes subscription payments. Your card number never touches Ledger AI's servers.
- Google (Gmail, Calendar, Business Profile) and Intuit (QuickBooks Online) — the source systems you connect; we read from and, where you direct us to, write to their APIs under the OAuth permissions you grant.
What we never do
- We do not sell your data to anyone.
- We do not use your data to train AI models — yours or anyone else's.
- We do not share your data beyond the named processors above, and only for the purpose of running the service.
Retention
We keep your workspace data — receipts, conversations, and connected-account data — for as long as your account is active. If you delete your account, that data is permanently removed rather than archived. Usage metering records are kept for billing and support purposes for the life of the account.
Deletion
You can delete your account and all associated data two ways:
- In-app — Settings → Delete account.
- By email — write to supportteam@heyledger.ai and ask us to delete your account.
Either path permanently removes your workspace, receipts, conversations, and connected-account tokens. This cannot be undone.
Gmail and Google user data
Ledger AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about this policy or your data: supportteam@heyledger.ai.
Ledger AI, Calgary, Alberta, Canada.