Your firm's data, your firm's data.
What we collect, why, who handles it for us, how long we keep it, and how to get it back or deleted. Plain English. The Security page covers the same ground in technical terms.
TL;DR
We keep what it takes to run your books: your bank lines, the reports you give us, your rules and decisions, and your account. We do not sell it, and we do not train AI on it. Plaid holds your bank sign-in; we never see it. To suggest categories we send parts of each bank line to OpenAI. Everything is stored in the United States by the providers listed below. You can export or delete everything yourself, in Settings.
Who we are.
LedgerInbox is operated by Birzum (비즘), a sole proprietorship registered in Seoul, Republic of Korea. “We”, “us” and “LedgerInbox” on this page mean Birzum. We decide what personal data LedgerInbox collects and why.
For the books you keep in LedgerInbox, your firm decides what goes in and whose books they are; we handle that data on your behalf, only to run the service for you.
Privacy officer: the owner of Birzum. Write to support@ledgerinbox.com with the subject “Privacy”.
What we collect.
About the people who use LedgerInbox, the businesses whose books they keep, the people who visit our website, and anyone you send a question to through us.
| What | What's in it | Where it comes from |
|---|---|---|
| Your account | Name, email, role, profile photo, firm name and logo, billing address, and whether you asked for product-update emails. If you sign in with a password, our sign-in provider keeps it scrambled (hashed); we never see it. | You, in sign-up and Settings |
| Sign-in records | When you signed in, your browser and system, your internet address and the approximate city, region and country our host derives from it. A random device ID in a cookie, of which we store only a scrambled copy, so we can tell you about a new device. | Your browser, when you sign in |
| Your books | Bank lines (description, amount, date, vendor, memo) and each bank account's name, type and last four digits; your chart of accounts; your rules, decisions and notes; the category the AI suggested with its reason; and a numeric fingerprint of each line, used to find look-alike lines. Bank descriptions can name people — a payee on a transfer, for example. | Plaid, QuickBooks Online, Toast, and the files you upload |
| Receipt photos | The photo, and the vendor, total, tax and lines read from it. The photo is read on your own device, then uploaded and stored with your books. | You |
| Sales, cash and payroll reports | The totals we read from point-of-sale, cash-drawer, delivery and payroll reports, and a fingerprint of each file to spot duplicates. We do not keep the file itself. For reports you forward by email, the sender's address, the subject and the attachment names go into your change history. | Uploads, forwarded email, Toast |
| Manager questions | The manager's email address, your question and their answer. | You, and the manager who answers |
| Change history | Who changed what in your firm, and what it was before and after. A person's name stays on their past entries after they leave the firm. | The app, as you work |
| Billing | Your plan and the invoices we create: bill-to name, email and address, and the card's brand and last four digits. Never the full card number. | Lemon Squeezy, our merchant of record |
| Website visitors | If you run the cash check: your email, your three answers and the estimate we sent you. If you ask for access or write to us through the contact form: your name, email, firm and message. With each: your browser and a scrambled copy of your internet address. | You, on ledgerinbox.com |
| Free diagnostic | The bank link or bank file and the one sales report you give it, held in a temporary account with no name attached. | You, on /diagnose |
| Usage and logs | Page views and a few product events (for example, whether a cash check was finished), counted without cookies. Server logs, with emails scrambled and secrets removed. Short-lived request counters keyed by internet address, to stop abuse. | Your browser |
We do not collect bank passwords, full card numbers, or your browsing history, and we never ask for anyone's Social Security number.
Why we use it.
Only to run the product, and only for these purposes:
- To keep your books — bring in bank lines and reports, suggest categories, match receipts, reconcile cash, tips and deposits, and post to QuickBooks Online when you tell it to.
- To remember your decisions — your choices become your firm's rules and examples for next time. They are never shared with another firm.
- To keep your account safe — sign-in checks, two-step codes, new-device notices, and limits that stop password guessing.
- To bill you — through Lemon Squeezy, which charges the card and handles sales tax.
- To email you — sign-in codes, invites, notices about your account and your books, invoices, the cash-check result you asked for, and product updates only if you turned them on in Settings.
- To answer you — when you write to us.
- To see whether the website works — page views and a few events, counted without cookies.
What the AI sees.
Category suggestions come from OpenAI's GPT-4o-mini. For each bank line it receives only the vendor name and description, the amount and whether the money came in or went out, the memo when there is one, and the names of that location's categories that can take that money, so it can only pick one of yours. While “Use past decisions” is on, it also receives up to 8 lines your firm already categorized that look most like it — vendor, description and the category chosen — from any of your locations.
To find those look-alikes, OpenAI's embedding model reads each line's vendor, description, amount and the location's business type, and returns the numeric fingerprint we store with the line.
Never sent: the date, account balances, location, firm or client names, receipt photos, or anything from books you have not connected.
Under OpenAI's API terms this data is not used to train OpenAI's models. OpenAI may keep it for up to 30 days to watch for abuse, then deletes it. We do not keep a log of prompts: we store the suggested category, its confidence and its one-line reason on the bank line, as part of your books.
How long we keep it.
| Data | How long | When you delete the firm |
|---|---|---|
| Your account, books, receipts, reports, manager questions, invoices, exports | For the life of the firm. If you stop paying (a plan ends or a trial ends without one), read-only for 90 days, then deleted — with 7 days' notice to every owner. If we end the agreement, 30 days to download, then deleted. | Deleted within 7 days |
| Sign-in records | Internet address and place erased after 90 days; the rest for the life of the firm | Deleted within 7 days |
| Change history | Routine entries (a line accepted, a category picked) deleted after 2 years; the rest for the life of the firm | Deleted within 7 days |
| Cash check, access requests, contact-form messages | Deleted 24 months after the last time that email address contacted us | Not tied to a firm |
| Free diagnostic | Deleted after 24 hours, unless you sign up and keep it | — |
| Server logs, job history, request counters | About a day; counters at most an hour | Already gone |
| Backups | Encrypted daily backups roll off after 7 days | Gone from backups within 7 days of deletion |
| Emails you send to support | In our support mailbox until we no longer need them; ask and we delete them | Not tied to a firm |
Deleting means the rows and files are removed from our database and storage, and we ask Plaid, Intuit, Lemon Squeezy and our email provider to drop the connection, grant, subscription and mailing-list entry. Payment records Lemon Squeezy must keep as the seller stay with them under their policy.
Cookies and browser storage.
Every cookie is ours and does a job for you. There are no advertising or tracking cookies, and our page-view counting uses none.
| Name | What it does | How long |
|---|---|---|
sb-… | Keeps you signed in | Until you sign out |
li_dev | A random device ID, so we can tell you when a new device signs in | 400 days |
li_mfa, li_mfa_ticket, li_step_up, li_email_change, ledger-reset-token | Two-step sign-in, confirming a sensitive action, changing your email, resetting a password | Minutes, or the sign-in |
qbo_oauth_nonce | Protects the QuickBooks Online connection step | Minutes |
li_cash_check | Carries your three cash-check answers into sign-up (not your email) | 1 hour |
li_diag | Finds your free diagnostic again | 24 hours |
Your browser also stores a few preferences for us — theme, keyboard tips you have seen, dismissed notices — which never leave your device. You can block or clear cookies in your browser; signing in needs them, the rest can go.
How we protect it.
- Everything is encrypted in transit and at rest by our database host. Bank and QuickBooks Online access tokens and two-step secrets are encrypted again by our own code (AES-256-GCM).
- Firms are kept apart by our server code, and the public database interface is locked so it can read nothing.
- Every change in a firm is recorded in its change history.
- If a breach affects your data, we will email the owners of the affected firm within 72 hours of confirming it, say what happened and what to do, and report it where the law requires.
Your rights.
Wherever you are, you can ask to see, correct, delete, or stop us using your personal data. Most of it you can do yourself:
- See and take it — Settings → Danger zone → Download everything: a JSON and CSV bundle with your receipt photos, sent to your account email.
- Correct it — most fields are yours to edit in Settings.
- Delete it — Settings → Danger zone → Delete firm. Everything is deleted within 7 days; any owner can call it off until then.
- Stop it — disconnect a bank or QuickBooks Online company, turn off past decisions or product updates in Settings, or ask us to stop any other use.
For anything else — including data about you that someone else's firm keeps, or your cash-check or contact-form details — email support@ledgerinbox.com with the subject “Privacy”. We reply within 10 days, may ask you to confirm it is you, and tell you plainly if the law stops us doing something. If the data belongs to a firm's books, we may pass your request to that firm, which decides.
If you are not satisfied, you can complain to your local data-protection authority. In Korea: the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the KISA privacy report center (privacy.kisa.or.kr, 118).
Children.
LedgerInbox is a business tool for bookkeepers and the businesses they serve, and accounts are for adults. We don't knowingly collect data about anyone under 16. If you believe we have, email support@ledgerinbox.com and we will delete it.
When this changes.
We announce meaningful changes 30 days ahead by email and in our changelog. A correction that makes this page match what the product already does takes effect when it is published. If you need an earlier version, ask us.
- v4 · October 2, 2026 — rewritten to match exactly what the product does: names the operator, lists every provider and data source, adds retention for each kind of data, cookies, sending data abroad and how to use your rights; removes statements that were not true (a zero-retention AI agreement, a 14-day prompt log, extra column encryption, keystroke telemetry, a 7-year billing archive).
- v3.1 · May 19, 2026 — previous version.
Reach a human.
- Email: support@ledgerinbox.com — for privacy requests, use the subject “Privacy”. We read everything.
- Who: Birzum (비즘), Seoul, Republic of Korea. We do not publish a street address; if a request needs one, email us first and we will give you the right channel.