Privacy Policy
Effective July 28, 2026
This policy explains what LedgerMeAI collects, why, who processes it, and how to get rid of it. LedgerMeAI is operated by Stefan Graham (LedgerMeAI) (“we”, “us”). It applies to the LedgerMeAI mobile app and to ledgermeai.com.
We are not a bank, a lender, or a financial adviser. LedgerMeAI reads your financial information so it can show it back to you clearly. It does not move money, and its guides explain and organise — they do not give financial or investment advice.
What we collect
Your account. Your email address and a securely hashed password, or the details from a third-party sign-in if you use one. We never store your password in a readable form.
Your bank connections. If you connect a bank, our provider Plaid asks for your banking credentials on its own screens. We never see or store your banking username or password. Plaid returns, and we store: the institution name, each account’s name, type and last four digits, current balances, and your transaction history — date, description, amount and merchant. For credit cards we also store statement balance, minimum payment, payment due date and APR where your bank reports them. Plaid also gives us an access token, which is stored on our servers only and is never sent to your phone.
What you create in the app. Categories, budgets, manually added accounts and transactions, edits and notes, and any spreadsheet or CSV file you import. Statement files you upload are processed to extract their transactions.
Your conversations with the guide. Messages you send to the in-app guide and its replies, so the conversation is still there next time you open it.
Basic technical records. Server logs needed to keep the service running and to diagnose failures, including records of bank-connection attempts.
What we do not collect
We do not collect your location. We do not use advertising identifiers. There are no advertising SDKs and no third-party analytics or tracking SDKs in the app. We do not build a profile of you for marketing, and we do not sell your data — to anyone, for any purpose.
Who processes your data
We use a small number of service providers who process data on our behalf and under contract, not for their own purposes:
- Plaid — connects your bank and retrieves account and transaction data.
- Supabase — hosts our database and runs our server functions.
- Anthropic — powers automatic transaction categorisation, statement import, and the in-app guide. What is sent for these purposes: transaction descriptions, amounts and dates; category and budget summaries and relevant individual transactions when you chat with your guide; and the contents of bank or card statements you upload for import. What is never sent: your name, your email, your account names, or your banking credentials. Your data is not used to train Anthropic’s models.
- Google Play — processes subscription payments. We never see your card details.
That is the complete list. We do not share your data with anyone else, and we do not disclose it for advertising or marketing. We will disclose data if legally compelled to, and will tell you unless we are prohibited from doing so.
How it is protected
All data is encrypted in transit using TLS, and encrypted at rest by our hosting provider. Access to your records is enforced at the database level, so one account cannot read another’s data. Bank access tokens are held server-side only and are never transmitted to your device.
No system is perfectly secure, and we will not pretend otherwise — but we do not hold what we do not need, and we never hold your banking credentials.
How long we keep it
We keep your data for as long as your account exists. When you delete your account, we delete your data within 30 days, and we instruct Plaid to end the connection to your banks. Backups are purged on their normal cycle. We may retain a minimal record of the deletion itself where we are legally required to.
Your choices
You can disconnect any bank at any time from inside the app, which ends our access to that institution.
You can delete your account and all associated data — from the app, or at https://www.ledgermeai.com/delete-account.
You can export your data from inside the app at any time.
Depending on where you live — including under the California Consumer Privacy Act and the Texas data privacy law — you may have the right to know what we hold, to correct it, to delete it, to obtain a copy, and not to be discriminated against for exercising those rights. Email stefan@ledgermeai.com and we will respond within the time the law allows.
Children
LedgerMeAI is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, email us and we will remove it.
Changes
If we change this policy we will update the date at the top and, for anything significant, tell you in the app before it takes effect.
Contact
Stefan Graham (LedgerMeAI)
Email: stefan@ledgermeai.com