Effective October 2, 2026 · v4

Your firm's data, your firm's data.

What we collect, why, who handles it for us, how long we keep it, and how to get it back or deleted. Plain English. The Security page covers the same ground in technical terms.

TL;DR

We keep what it takes to run your books: your bank lines, the reports you give us, your rules and decisions, and your account. We do not sell it, and we do not train AI on it. Plaid holds your bank sign-in; we never see it. To suggest categories we send parts of each bank line to OpenAI. Everything is stored in the United States by the providers listed below. You can export or delete everything yourself, in Settings.

§ 01

Who we are.

LedgerInbox is operated by Birzum (비즘), a sole proprietorship registered in Seoul, Republic of Korea. “We”, “us” and “LedgerInbox” on this page mean Birzum. We decide what personal data LedgerInbox collects and why.

For the books you keep in LedgerInbox, your firm decides what goes in and whose books they are; we handle that data on your behalf, only to run the service for you.

Privacy officer: the owner of Birzum. Write to support@ledgerinbox.com with the subject “Privacy”.

§ 02

What we collect.

About the people who use LedgerInbox, the businesses whose books they keep, the people who visit our website, and anyone you send a question to through us.

WhatWhat's in itWhere it comes from
Your accountName, email, role, profile photo, firm name and logo, billing address, and whether you asked for product-update emails. If you sign in with a password, our sign-in provider keeps it scrambled (hashed); we never see it.You, in sign-up and Settings
Sign-in recordsWhen you signed in, your browser and system, your internet address and the approximate city, region and country our host derives from it. A random device ID in a cookie, of which we store only a scrambled copy, so we can tell you about a new device.Your browser, when you sign in
Your booksBank lines (description, amount, date, vendor, memo) and each bank account's name, type and last four digits; your chart of accounts; your rules, decisions and notes; the category the AI suggested with its reason; and a numeric fingerprint of each line, used to find look-alike lines. Bank descriptions can name people — a payee on a transfer, for example.Plaid, QuickBooks Online, Toast, and the files you upload
Receipt photosThe photo, and the vendor, total, tax and lines read from it. The photo is read on your own device, then uploaded and stored with your books.You
Sales, cash and payroll reportsThe totals we read from point-of-sale, cash-drawer, delivery and payroll reports, and a fingerprint of each file to spot duplicates. We do not keep the file itself. For reports you forward by email, the sender's address, the subject and the attachment names go into your change history.Uploads, forwarded email, Toast
Manager questionsThe manager's email address, your question and their answer.You, and the manager who answers
Change historyWho changed what in your firm, and what it was before and after. A person's name stays on their past entries after they leave the firm.The app, as you work
BillingYour plan and the invoices we create: bill-to name, email and address, and the card's brand and last four digits. Never the full card number.Lemon Squeezy, our merchant of record
Website visitorsIf you run the cash check: your email, your three answers and the estimate we sent you. If you ask for access or write to us through the contact form: your name, email, firm and message. With each: your browser and a scrambled copy of your internet address.You, on ledgerinbox.com
Free diagnosticThe bank link or bank file and the one sales report you give it, held in a temporary account with no name attached.You, on /diagnose
Usage and logsPage views and a few product events (for example, whether a cash check was finished), counted without cookies. Server logs, with emails scrambled and secrets removed. Short-lived request counters keyed by internet address, to stop abuse.Your browser

We do not collect bank passwords, full card numbers, or your browsing history, and we never ask for anyone's Social Security number.

§ 03

Why we use it.

Only to run the product, and only for these purposes:

  • To keep your books — bring in bank lines and reports, suggest categories, match receipts, reconcile cash, tips and deposits, and post to QuickBooks Online when you tell it to.
  • To remember your decisions — your choices become your firm's rules and examples for next time. They are never shared with another firm.
  • To keep your account safe — sign-in checks, two-step codes, new-device notices, and limits that stop password guessing.
  • To bill you — through Lemon Squeezy, which charges the card and handles sales tax.
  • To email you — sign-in codes, invites, notices about your account and your books, invoices, the cash-check result you asked for, and product updates only if you turned them on in Settings.
  • To answer you — when you write to us.
  • To see whether the website works — page views and a few events, counted without cookies.
What we don't doWe do not train or fine-tune any AI model on your data. We do not sell it or share it with data brokers, lead generators or ad networks, and there are no advertising trackers on our site or in the app.
§ 04

Who handles it.

Your team

People in your firm see your firm's books, according to the role an owner gives them. A manager you send a question to sees that question, nothing else.

Companies that run parts of LedgerInbox for us

These providers process data on our behalf, only for the task listed. All of them process it in the United States.

WhoWhat they do · which dataWhere · how long
SupabaseOur database, sign-in and file storageEverything in your account: books, receipts, sign-in records, team membersUnited States (AWS, Virginia)Until deleted; encrypted backups roll off after 7 days
VercelHosts the website and app; cookieless page-view analyticsEvery request (internet address, browser), short-lived server logs, page views and a few product eventsUnited StatesLogs about a day; analytics under Vercel's policy
OpenAISuggests categories and finds look-alike past linesA bank line's vendor, description, amount, direction and memo; your category names; up to eight past linesUnited StatesNot used for training; may be kept up to 30 days for abuse monitoring
AnthropicAI assistant our engineer uses when fixing a problem or building the product; an alternate category model (off)The records involved in the problem being worked onUnited StatesUnder Anthropic's policy
InngestRuns background jobs (syncs, suggestions, posting, nightly checks)What each job works on, including transaction text, amounts, memos and suggestionsUnited StatesJob history about a day
ResendSends our emails; receives the reports you forward to a location's addressRecipient addresses and email contents: sign-in codes, invites, notices, invoices, manager questions, the cash check, product updates you opted intoUnited StatesUnder Resend's policy
Lemon Squeezy (a Stripe company)Merchant of record: checkout, card payments, sales taxName, email, billing address and cardUnited StatesUnder Lemon Squeezy's policy
UpstashCounts requests to stop abuseYour internet address, or a hashed emailUnited States (AWS, Virginia)At most one hour
Google WorkspaceOur support mailbox (support@ledgerinbox.com)Messages you send us; notices of new sign-ups, cash checks and contact-form messagesUnited StatesUntil deleted; ask and we delete

Where your data comes from

When you connect them, these services send us your data under their own privacy policies. Banks connect through Plaid: Plaid collects your bank data under its End User Privacy Policy. Lemon Squeezy processes your payment under its privacy policy.

WhoWhat they do · which dataWhere · how long
PlaidConnects your bank (read-only)Sends us transactions and each account's name, type and last four digitsUnited StatesUnder Plaid's End User Privacy Policy
Intuit QuickBooks OnlineYour booksWe read the chart of accounts, transactions and company name; we write categories, expenses, deposits, transfers and journal entriesUnited StatesUnder Intuit's policy
ToastPoint-of-sale sales, when you connect itWe read each business day's orders and cash-drawer entries and keep the day's totalsUnited StatesUnder Toast's policy

Sending data abroad

LedgerInbox is run from Korea, and everything above is stored and processed in the United States by the providers listed. Your data travels to them over encrypted connections whenever you use the service, because that is where the service runs. They keep it for as long as the tables say. You can refuse by not using LedgerInbox — we cannot run it any other way — and you can delete your firm at any time.

Us

LedgerInbox is a small business: only the people who run it — today, its owner — can reach production systems. We look at a firm's data only to fix a problem you report, to keep the service running and secure, or when the law requires it. While doing that work we may use an AI assistant (Anthropic's, listed above), which then sees the records involved. If a court or authority orders us to hand over your data, we will tell you unless the law forbids it.

§ 05

What the AI sees.

Category suggestions come from OpenAI's GPT-4o-mini. For each bank line it receives only the vendor name and description, the amount and whether the money came in or went out, the memo when there is one, and the names of that location's categories that can take that money, so it can only pick one of yours. While “Use past decisions” is on, it also receives up to 8 lines your firm already categorized that look most like it — vendor, description and the category chosen — from any of your locations.

To find those look-alikes, OpenAI's embedding model reads each line's vendor, description, amount and the location's business type, and returns the numeric fingerprint we store with the line.

Never sent: the date, account balances, location, firm or client names, receipt photos, or anything from books you have not connected.

Under OpenAI's API terms this data is not used to train OpenAI's models. OpenAI may keep it for up to 30 days to watch for abuse, then deletes it. We do not keep a log of prompts: we store the suggested category, its confidence and its one-line reason on the bank line, as part of your books.

§ 06

How long we keep it.

DataHow longWhen you delete the firm
Your account, books, receipts, reports, manager questions, invoices, exportsFor the life of the firm. If you stop paying (a plan ends or a trial ends without one), read-only for 90 days, then deleted — with 7 days' notice to every owner. If we end the agreement, 30 days to download, then deleted.Deleted within 7 days
Sign-in recordsInternet address and place erased after 90 days; the rest for the life of the firmDeleted within 7 days
Change historyRoutine entries (a line accepted, a category picked) deleted after 2 years; the rest for the life of the firmDeleted within 7 days
Cash check, access requests, contact-form messagesDeleted 24 months after the last time that email address contacted usNot tied to a firm
Free diagnosticDeleted after 24 hours, unless you sign up and keep it—
Server logs, job history, request countersAbout a day; counters at most an hourAlready gone
BackupsEncrypted daily backups roll off after 7 daysGone from backups within 7 days of deletion
Emails you send to supportIn our support mailbox until we no longer need them; ask and we delete themNot tied to a firm

Deleting means the rows and files are removed from our database and storage, and we ask Plaid, Intuit, Lemon Squeezy and our email provider to drop the connection, grant, subscription and mailing-list entry. Payment records Lemon Squeezy must keep as the seller stay with them under their policy.

§ 07

Cookies and browser storage.

Every cookie is ours and does a job for you. There are no advertising or tracking cookies, and our page-view counting uses none.

NameWhat it doesHow long
sb-…Keeps you signed inUntil you sign out
li_devA random device ID, so we can tell you when a new device signs in400 days
li_mfa, li_mfa_ticket, li_step_up, li_email_change, ledger-reset-tokenTwo-step sign-in, confirming a sensitive action, changing your email, resetting a passwordMinutes, or the sign-in
qbo_oauth_nonceProtects the QuickBooks Online connection stepMinutes
li_cash_checkCarries your three cash-check answers into sign-up (not your email)1 hour
li_diagFinds your free diagnostic again24 hours

Your browser also stores a few preferences for us — theme, keyboard tips you have seen, dismissed notices — which never leave your device. You can block or clear cookies in your browser; signing in needs them, the rest can go.

§ 08

How we protect it.

  • Everything is encrypted in transit and at rest by our database host. Bank and QuickBooks Online access tokens and two-step secrets are encrypted again by our own code (AES-256-GCM).
  • Firms are kept apart by our server code, and the public database interface is locked so it can read nothing.
  • Every change in a firm is recorded in its change history.
  • If a breach affects your data, we will email the owners of the affected firm within 72 hours of confirming it, say what happened and what to do, and report it where the law requires.
§ 09

Your rights.

Wherever you are, you can ask to see, correct, delete, or stop us using your personal data. Most of it you can do yourself:

  • See and take it — Settings → Danger zone → Download everything: a JSON and CSV bundle with your receipt photos, sent to your account email.
  • Correct it — most fields are yours to edit in Settings.
  • Delete it — Settings → Danger zone → Delete firm. Everything is deleted within 7 days; any owner can call it off until then.
  • Stop it — disconnect a bank or QuickBooks Online company, turn off past decisions or product updates in Settings, or ask us to stop any other use.

For anything else — including data about you that someone else's firm keeps, or your cash-check or contact-form details — email support@ledgerinbox.com with the subject “Privacy”. We reply within 10 days, may ask you to confirm it is you, and tell you plainly if the law stops us doing something. If the data belongs to a firm's books, we may pass your request to that firm, which decides.

If you are not satisfied, you can complain to your local data-protection authority. In Korea: the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the KISA privacy report center (privacy.kisa.or.kr, 118).

§ 10

Children.

LedgerInbox is a business tool for bookkeepers and the businesses they serve, and accounts are for adults. We don't knowingly collect data about anyone under 16. If you believe we have, email support@ledgerinbox.com and we will delete it.

§ 11

When this changes.

We announce meaningful changes 30 days ahead by email and in our changelog. A correction that makes this page match what the product already does takes effect when it is published. If you need an earlier version, ask us.

  • v4 · October 2, 2026 — rewritten to match exactly what the product does: names the operator, lists every provider and data source, adds retention for each kind of data, cookies, sending data abroad and how to use your rights; removes statements that were not true (a zero-retention AI agreement, a 14-day prompt log, extra column encryption, keystroke telemetry, a 7-year billing archive).
  • v3.1 · May 19, 2026 — previous version.
§ 12

Reach a human.

  • Email: support@ledgerinbox.com — for privacy requests, use the subject “Privacy”. We read everything.
  • Who: Birzum (비즘), Seoul, Republic of Korea. We do not publish a street address; if a request needs one, email us first and we will give you the right channel.
Privacy v4 · effective October 2, 2026 · supersedes v3.1 (May 19, 2026)Terms → · Security →