Privacy Policy

Last updated: 2026-08-01

This Privacy Policy explains what information Simpler Ledger ("we," "us") collects when you use our bookkeeping service (the "Service"), how we use and protect it, and the choices you have. By using the Service you agree to this policy.

1. Information we collect

Information you provide

  • Account information: name, email address, and password (stored as a secure hash by our authentication provider).
  • Financial records you enter: business entities, transactions (dates, descriptions, amounts, categories, notes), receipts you upload, tax settings, and saved reports.
  • Team information: email addresses of people you invite to your entities and the roles you assign them.

Information from integrations you choose to connect

  • Payments (Stripe): when you subscribe, Stripe processes your card details. We never see or store your full card number — we store only your Stripe customer reference, subscription status, and plan.
  • Bank connections (Plaid): if you link a bank account, Plaid provides transaction data (dates, amounts, merchant descriptions) and account metadata (institution name, account mask). We never receive or store your bank username or password.

Information collected automatically

  • Usage analytics: anonymized page-view and performance metrics via Vercel Analytics (no cross-site tracking cookies, no ad networks).
  • Log data: standard server logs (IP address, browser type, timestamps) for security and debugging.

2. How we use your information

  • To provide the Service: storing your books, generating reports, syncing data across your devices and team.
  • To process AI features you invoke — e.g., a receipt photo you upload is sent to our AI provider (Anthropic) to extract the transaction details, and bank-file headers are sent to suggest column mappings.
  • To process billing and manage your subscription.
  • To secure the Service, prevent abuse, and maintain an audit log of changes to your books.
  • To communicate with you about your account (invites, security, service changes).

We do not sell your personal information or your financial data, and we do not use your financial data for advertising.

3. How your data is protected

  • Encryption in transit: all traffic uses HTTPS/TLS.
  • Encryption at rest: sensitive fields — transaction amounts, descriptions, notes, entity names, bank access tokens, and saved report contents — are additionally encrypted with AES-256-GCM field-level encryption before they reach the database.
  • Access controls: your data is isolated per account and per entity with database-level row security. Team members see only the entities they are invited to, limited by their role.
  • Audit trail: changes to financial records are logged append-only.

No system is perfectly secure; we cannot guarantee absolute security, but we design for it in layers.

4. Who we share data with (subprocessors)

We share data only with the service providers required to operate Simpler Ledger, each bound by their own security and privacy obligations:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and anonymized analytics.
  • Stripe — payment processing.
  • Plaid — bank connections you explicitly link.
  • Anthropic — AI processing of content you submit to AI features (receipt images, import file headers).

We may also disclose information if required by law, to protect our rights, or as part of a business transfer (in which case this policy continues to apply to your data).

5. Data retention and deletion

  • Your records are retained while your account is active so your books remain available across tax years.
  • Deleting an entity permanently deletes its transactions, receipts, rules, reports, and team associations.
  • To delete your entire account and all associated data, contact us at kyleklintworth@simplerledger.com — we will complete deletion within 30 days, except records we are legally required to keep (e.g., billing records).
  • We recommend exporting your data (CSV) before deletion; deletion is irreversible.

6. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to certain processing. You can exercise most of these directly in the app (your books are editable and exportable at any time); for anything else, email kyleklintworth@simplerledger.com and we will respond within 30 days.

7. Cookies

We use only essential cookies: authentication session cookies that keep you signed in. We do not use advertising or cross-site tracking cookies.

8. Children

The Service is for business use by adults. We do not knowingly collect information from anyone under 18.

9. Changes to this policy

If we make material changes, we will update the date above and ask you to review and accept the new version in the app.

10. Contact

Privacy questions or requests: kyleklintworth@simplerledger.com. See also our Terms of Service and Disclaimer.