Ledgerly
AboutPrivacyTermsSign in

Privacy at Ledgerly

Privacy Policy

This policy explains what Ledgerly handles, why it is needed, how the Gmail send integration works, and how you can access or delete your information.

Effective 30 August 2026Ledgerly

On this page

  1. Scope and operator
  2. Information Ledgerly handles
  3. How information is used
  4. Google OAuth and Gmail
  5. Sharing and service providers
  6. Storage, security, and retention
  7. Your choices and deletion
  8. Changes and contact

1. Scope and operator

This Privacy Policy applies when you use Ledgerly, including its account sign-in, the Supabase-backed TiLabs accounting workspace, invoice documents, private cost evidence, and optional Gmail delivery. Ledgerly is operated by the developer of the service, referred to as “Ledgerly,” “we,” or “us” in this policy.

Ledgerly is designed for people authorized to manage business and accounting records. It is not directed to children. If you enter information about customers, suppliers, staff, or other people, you are responsible for having an appropriate reason and permission to do so.

2. Information Ledgerly handles

Account and identity information

When you sign in, Ledgerly and its authentication provider process your email address, account identifier, session data, display name, and avatar supplied by Google. Ledgerly accepts only the authorized aloysius@talentintelligences.com Google Workspace identity; it does not offer password or public account registration.

Business and accounting information

Information you enter may include organization details, customer and supplier names and contact details, billing addresses, invoice and bill line items, dates, tax amounts, payments, references, notes, branding, invoice templates, and activity history. Some of this data concerns people at your customers or suppliers.

Cloud workspace and delivery information

The canonical workspace stores identity, membership, accounting records, and private cost evidence in Supabase. Browser storage is limited to session-activity coordination and temporary interface state such as filters. If Gmail delivery is enabled, Ledgerly also stores the connected sender identity, encrypted refresh-token material, granted scopes, connection status, templates, recipients, invoice document snapshots, scheduling information, delivery attempts, provider message IDs, and sanitized retry details.

Operational information

Hosting, authentication, and database providers may process routine request, device, IP address, cookie, diagnostic, and security information when operating the service. Ledgerly does not use this information for behavioral advertising.

3. How information is used

Ledgerly uses information to:

  • authenticate users and keep business routes account-gated;
  • provide the accounting, invoicing, reporting, and source-document features you request;
  • maintain organization roles and isolate tenant data;
  • create invoice documents and send or schedule invoice-related emails;
  • show delivery status, retry temporary failures, and preserve an audit trail;
  • protect the service, investigate errors or abuse, and meet legal obligations; and
  • respond to support, access, correction, and deletion requests.

Ledgerly does not sell personal information or Google user data, and does not use it to serve personalized or interest-based advertising.

4. Google OAuth and Gmail

Google sign-in

Google Workspace sign-in through Supabase Auth is the only way to authenticate to Ledgerly, and access is restricted to the authorized aloysius@talentintelligences.com identity. Sign-in remains separate from connecting Gmail for invoice delivery; signing in alone does not give Ledgerly permission to send Gmail messages.

Connecting Gmail for invoice delivery

An organization owner or administrator may separately connect a Gmail account. That flow asks for OpenID and email identity plus the narrow https://www.googleapis.com/auth/gmail.send scope. Ledgerly uses the identity scopes to confirm the connected sender and the Gmail scope only to send invoice and reminder messages chosen or scheduled in Ledgerly. Messages can include the organization’s invoice PDF attachment.

Ledgerly does not request permission to read, search, download, modify, or delete Gmail mailbox contents. It does not request Google Contacts, Drive, or Calendar access. Access tokens are used server-side for sending; the long-lived refresh token is encrypted with AES-256-GCM before it is stored and is not exposed to browser clients.

Google API Limited Use disclosure

Ledgerly’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the visible Gmail invoice-delivery feature and is not used for advertising, credit decisions, or sale to data brokers.

Disconnecting Gmail

An organization owner or administrator can disconnect Gmail from the cloud workspace. Ledgerly then attempts to revoke the Google token and marks the connection as revoked so it is no longer used. You may also remove Ledgerly from your Google Account’s third-party connections. Disconnecting stops future sends, but does not recall messages already sent or automatically remove invoice and delivery audit records.

5. Sharing and service providers

Ledgerly shares information only as needed to operate features you request, with your direction or consent, or when legally required. Current service categories include:

  • Supabase for authentication, session handling, and tenant-scoped cloud database storage;
  • Vercel for application hosting, server execution, scheduled delivery processing, and operational logs;
  • Google for required Workspace sign-in and, when enabled, sender identity, OAuth authorization, token exchange, and Gmail message delivery; and
  • your selected recipients when Ledgerly sends an invoice or reminder from the connected Gmail account.

We may disclose information to address fraud or security incidents, protect rights and safety, or comply with a valid legal obligation. We do not permit service providers to use Google user data for their own advertising.

6. Storage, security, and retention

Ledgerly uses account-gated routes, tenant membership checks, row-level database security, server-side authorization, encrypted Gmail refresh tokens, short-lived signed OAuth state, and organization-scoped records. No online system is completely secure, so you should protect your account, device, and connected Gmail account and notify us if you suspect unauthorized use.

Business, invoice, source-document, and delivery records are retained while needed to provide the workspace, preserve accounting and audit history, resolve issues, or meet legal obligations. We do not promise a fixed retention period where the appropriate period depends on the record and applicable obligations. Provider backups and security logs may persist for a limited period after active records are deleted.

7. Your choices and deletion

You can take the following actions:

  • disconnect Gmail in Ledgerly and revoke access in your Google Account;
  • correct business records through available product controls; and
  • request access to, a copy of, or deletion of your account and associated cloud data by email.

Send deletion or privacy requests to aloysius@talentintelligences.com. We may need to verify your identity and your authority over an organization before acting. Deletion may be limited where retention is required by law, needed for security or dispute resolution, or needed to protect other organization members. Deleting Ledgerly data cannot delete copies of an email already delivered to a recipient’s mailbox.

8. Changes and contact

We may update this policy as Ledgerly changes. The effective date at the top identifies the current version. Material changes will be presented through the service or another reasonable channel when appropriate.

Questions, privacy requests, and complaints can be sent to aloysius@talentintelligences.com.

Ledgerly

A calm accounting and invoice-delivery workspace.

AboutPrivacy PolicyTerms of ServiceContact