1. What we collect
When you create an account, we collect your email address, display name, and a hashed version of your password. We never store plaintext passwords; all credentials are processed through Argon2id before touching storage.
When you use LedgerCore, we store the financial data you enter: customers, vendors, invoices, bills, payments, journal entries, bank activity, chart of accounts, and organization settings. This data is scoped to your organization and is never shared with other tenants.
2. How we use your data
Your financial data is used exclusively to provide the LedgerCore service to you. We do not mine, analyze, or monetize your accounting data. We use the data we hold to:
- Operate and maintain the service
- Authenticate your sessions and enforce access controls
- Send transactional emails, such as team invitations and billing notices
- Process receipt images through the receipt-scanning feature. Images are transmitted to a third-party OCR provider for extraction, and the image itself is stored with your organization’s records so that the resulting bill retains its supporting document.
- Operate subscription billing and, where you connect a bank account, receive transaction data through Stripe Financial Connections
3. Data isolation
LedgerCore enforces per-tenant isolation in the database itself. PostgreSQL row-level security is applied to every ledger table, so queries made on behalf of one organization cannot see another organization’s rows. There is no mechanism in the application to cross that boundary, and no administrative backdoor that bypasses it.
4. Security measures
- Encryption in transit: all connections to the service use TLS
- Encryption at rest: provided by the managed database and object-storage infrastructure the service runs on
- Password hashing: Argon2id, with hashes upgraded automatically at sign-in as parameters strengthen
- Two-factor authentication: TOTP with recovery codes
- Session management: cryptographically random session tokens with expiry
- Access controls: organization roles over a granular permission catalogue, with per-book access and segregation-of-duties rules enforced in the database
5. Third-party services
We use a limited number of third-party services:
- Cloud hosting: for application, database, and object-storage infrastructure
- SMTP provider: for transactional email
- OCR provider: for receipt scanning; images are transmitted for processing under the provider’s data-processing terms
- Stripe: for subscription billing and, where you choose to connect a bank account, for bank feeds via Stripe Financial Connections
We do not use analytics trackers, advertising pixels, or any form of behavioral monitoring on the application.
6. Data retention
Your financial data is retained for as long as your organization exists, including while it is in a read-only state after a trial or subscription lapses. If you close your account, we will delete all associated data within 30 days; copies in backups age out on a rolling cycle after deletion.
7. Your rights
You can, at any time:
- Export your data in CSV format
- Update or correct your personal information
- Delete your account and all associated data
- Request a copy of all data we hold about you
8. Cookies
LedgerCore uses a session cookie for authentication. We do not use tracking cookies, third-party cookies, or any form of cross-site tracking.
9. Children’s privacy
LedgerCore is a business application not directed at individuals under 16. We do not knowingly collect data from minors.
10. Changes to this policy
We will notify you of material changes via the email address associated with your account at least 30 days before the changes take effect.
Contact
For privacy-related inquiries, email privacy@ledgercore.app.