Ledgerly
AboutPrivacyTermsSign in

Privacy at Ledgerly

Privacy Policy

This policy explains what Ledgerly handles, why it is needed, how the Gmail send integration works, and how you can access or delete your information.

Effective 19 July 2026Ledgerly

On this page

  1. Scope and operator
  2. Information Ledgerly handles
  3. How information is used
  4. Google OAuth and Gmail
  5. Sharing and service providers
  6. Storage, security, and retention
  7. Your choices and deletion
  8. Changes and contact

1. Scope and operator

This Privacy Policy applies when you use Ledgerly, including its account sign-in, local accounting workspace, Supabase-backed cloud workspace, invoice documents, exports, and optional Gmail delivery. Ledgerly is operated by the developer of the service, referred to as “Ledgerly,” “we,” or “us” in this policy.

Ledgerly is designed for people authorized to manage business and accounting records. It is not directed to children. If you enter information about customers, suppliers, staff, or other people, you are responsible for having an appropriate reason and permission to do so.

2. Information Ledgerly handles

Account and identity information

When you sign in, Ledgerly and its authentication provider process your email address, account identifier, session data, display name, and avatar supplied by Google. Ledgerly accepts only the authorized aloysius@talentintelligences.com Google Workspace identity; it does not offer password or public account registration.

Business and accounting information

Information you enter may include organization details, customer and supplier names and contact details, billing addresses, invoice and bill line items, dates, tax amounts, payments, references, notes, branding, invoice templates, and activity history. Some of this data concerns people at your customers or suppliers.

Browser-local information

The main accounting workspace stores its local ledger, preferences, invoice-document settings, and delivery workflow state in browser storage under your signed-in account identifier. This local workspace is not automatically uploaded into the cloud ledger. Clearing site data or using Ledgerly’s reset controls removes that browser-local copy from the current browser.

Cloud delivery information

The cloud workspace stores organization memberships and accounting records in Supabase. If your organization enables Gmail delivery, it also stores the connected sender identity, encrypted refresh-token material, granted scopes, connection status, email templates, recipients, subject and message bodies, invoice document snapshots, scheduling information, delivery attempts, provider message IDs, and sanitized error details needed for retries and audit history.

Operational information

Hosting, authentication, and database providers may process routine request, device, IP address, cookie, diagnostic, and security information when operating the service. Ledgerly does not use this information for behavioral advertising.

3. How information is used

Ledgerly uses information to:

  • authenticate users and keep business routes account-gated;
  • provide the accounting, invoicing, reporting, and export features you request;
  • maintain organization roles and isolate tenant data;
  • create invoice documents and send or schedule invoice-related emails;
  • show delivery status, retry temporary failures, and preserve an audit trail;
  • protect the service, investigate errors or abuse, and meet legal obligations; and
  • respond to support, access, correction, and deletion requests.

Ledgerly does not sell personal information or Google user data, and does not use it to serve personalized or interest-based advertising.

4. Google OAuth and Gmail

Google sign-in

Google Workspace sign-in through Supabase Auth is the only way to authenticate to Ledgerly, and access is restricted to the authorized aloysius@talentintelligences.com identity. Sign-in remains separate from connecting Gmail for invoice delivery; signing in alone does not give Ledgerly permission to send Gmail messages.

Connecting Gmail for invoice delivery

An organization owner or administrator may separately connect a Gmail account. That flow asks for OpenID and email identity plus the narrow https://www.googleapis.com/auth/gmail.send scope. Ledgerly uses the identity scopes to confirm the connected sender and the Gmail scope only to send invoice and reminder messages chosen or scheduled in Ledgerly. Messages can include the organization’s invoice PDF attachment.

Ledgerly does not request permission to read, search, download, modify, or delete Gmail mailbox contents. It does not request Google Contacts, Drive, or Calendar access. Access tokens are used server-side for sending; the long-lived refresh token is encrypted with AES-256-GCM before it is stored and is not exposed to browser clients.

Google API Limited Use disclosure

Ledgerly’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the visible Gmail invoice-delivery feature and is not used for advertising, credit decisions, or sale to data brokers.

Disconnecting Gmail

An organization owner or administrator can disconnect Gmail from the cloud workspace. Ledgerly then attempts to revoke the Google token and marks the connection as revoked so it is no longer used. You may also remove Ledgerly from your Google Account’s third-party connections. Disconnecting stops future sends, but does not recall messages already sent or automatically remove invoice and delivery audit records.

5. Sharing and service providers

Ledgerly shares information only as needed to operate features you request, with your direction or consent, or when legally required. Current service categories include:

  • Supabase for authentication, session handling, and tenant-scoped cloud database storage;
  • Vercel for application hosting, server execution, scheduled delivery processing, and operational logs;
  • Google for required Workspace sign-in and, when enabled, sender identity, OAuth authorization, token exchange, and Gmail message delivery; and
  • your selected recipients when Ledgerly sends an invoice or reminder from the connected Gmail account.

We may disclose information to address fraud or security incidents, protect rights and safety, or comply with a valid legal obligation. We do not permit service providers to use Google user data for their own advertising.

6. Storage, security, and retention

Ledgerly uses account-gated routes, tenant membership checks, row-level database security, server-side authorization, encrypted Gmail refresh tokens, short-lived signed OAuth state, and organization-scoped records. No online system is completely secure, so you should protect your account, device, and connected Gmail account and notify us if you suspect unauthorized use.

Browser-local data remains in the browser until you reset it, clear site data, or the browser removes it. Cloud business, invoice, and delivery records are retained while needed to provide the workspace, preserve accounting and audit history, resolve issues, or meet legal obligations. We do not promise a fixed retention period where the appropriate period depends on the record and applicable obligations. Provider backups and security logs may persist for a limited period after active records are deleted.

7. Your choices and deletion

You can take the following actions:

  • export supported ledger records from Ledgerly before deleting them;
  • reset account-scoped local demo data or clear Ledgerly site data in your browser;
  • disconnect Gmail in Ledgerly and revoke access in your Google Account;
  • correct business records through available product controls; and
  • request access to or deletion of your account and associated cloud data by email.

Send deletion or privacy requests to aloysius@talentintelligences.com. We may need to verify your identity and your authority over an organization before acting. Deletion may be limited where retention is required by law, needed for security or dispute resolution, or needed to protect other organization members. Deleting Ledgerly data cannot delete copies of an email already delivered to a recipient’s mailbox.

8. Changes and contact

We may update this policy as Ledgerly changes. The effective date at the top identifies the current version. Material changes will be presented through the service or another reasonable channel when appropriate.

Questions, privacy requests, and complaints can be sent to aloysius@talentintelligences.com.

Ledgerly

A calm accounting and invoice-delivery workspace.

AboutPrivacy PolicyTerms of ServiceContact