1. Scope and operator
This Privacy Policy applies when you use Ledgerly, including its account sign-in, the Supabase-backed TiLabs accounting workspace, invoice documents, private cost evidence, and optional Gmail delivery. Ledgerly is operated by the developer of the service, referred to as “Ledgerly,” “we,” or “us” in this policy.
Ledgerly is designed for people authorized to manage business and accounting records. It is not directed to children. If you enter information about customers, suppliers, staff, or other people, you are responsible for having an appropriate reason and permission to do so.
2. Information Ledgerly handles
Account and identity information
When you sign in, Ledgerly and its authentication provider process your email address, account identifier, session data, display name, and avatar supplied by Google. Ledgerly accepts only the authorized aloysius@talentintelligences.com Google Workspace identity; it does not offer password or public account registration.
Business and accounting information
Information you enter may include organization details, customer and supplier names and contact details, billing addresses, invoice and bill line items, dates, tax amounts, payments, references, notes, branding, invoice templates, and activity history. Some of this data concerns people at your customers or suppliers.
Cloud workspace and delivery information
The canonical workspace stores identity, membership, accounting records, and private cost evidence in Supabase. Browser storage is limited to session-activity coordination and temporary interface state such as filters. If Gmail delivery is enabled, Ledgerly also stores the connected sender identity, encrypted refresh-token material, granted scopes, connection status, templates, recipients, invoice document snapshots, scheduling information, delivery attempts, provider message IDs, and sanitized retry details.
Operational information
Hosting, authentication, and database providers may process routine request, device, IP address, cookie, diagnostic, and security information when operating the service. Ledgerly does not use this information for behavioral advertising.
3. How information is used
Ledgerly uses information to:
- authenticate users and keep business routes account-gated;
- provide the accounting, invoicing, reporting, and source-document features you request;
- maintain organization roles and isolate tenant data;
- create invoice documents and send or schedule invoice-related emails;
- show delivery status, retry temporary failures, and preserve an audit trail;
- protect the service, investigate errors or abuse, and meet legal obligations; and
- respond to support, access, correction, and deletion requests.
Ledgerly does not sell personal information or Google user data, and does not use it to serve personalized or interest-based advertising.
4. Google OAuth and Gmail
Google sign-in
Google Workspace sign-in through Supabase Auth is the only way to authenticate to Ledgerly, and access is restricted to the authorized aloysius@talentintelligences.com identity. Sign-in remains separate from connecting Gmail for invoice delivery; signing in alone does not give Ledgerly permission to send Gmail messages.
Connecting Gmail for invoice delivery
An organization owner or administrator may separately connect a Gmail account. That flow asks for OpenID and email identity plus the narrow https://www.googleapis.com/auth/gmail.send scope. Ledgerly uses the identity scopes to confirm the connected sender and the Gmail scope only to send invoice and reminder messages chosen or scheduled in Ledgerly. Messages can include the organization’s invoice PDF attachment.
Ledgerly does not request permission to read, search, download, modify, or delete Gmail mailbox contents. It does not request Google Contacts, Drive, or Calendar access. Access tokens are used server-side for sending; the long-lived refresh token is encrypted with AES-256-GCM before it is stored and is not exposed to browser clients.
Disconnecting Gmail
An organization owner or administrator can disconnect Gmail from the cloud workspace. Ledgerly then attempts to revoke the Google token and marks the connection as revoked so it is no longer used. You may also remove Ledgerly from your Google Account’s third-party connections. Disconnecting stops future sends, but does not recall messages already sent or automatically remove invoice and delivery audit records.
6. Storage, security, and retention
Ledgerly uses account-gated routes, tenant membership checks, row-level database security, server-side authorization, encrypted Gmail refresh tokens, short-lived signed OAuth state, and organization-scoped records. No online system is completely secure, so you should protect your account, device, and connected Gmail account and notify us if you suspect unauthorized use.
Business, invoice, source-document, and delivery records are retained while needed to provide the workspace, preserve accounting and audit history, resolve issues, or meet legal obligations. We do not promise a fixed retention period where the appropriate period depends on the record and applicable obligations. Provider backups and security logs may persist for a limited period after active records are deleted.
7. Your choices and deletion
You can take the following actions:
- disconnect Gmail in Ledgerly and revoke access in your Google Account;
- correct business records through available product controls; and
- request access to, a copy of, or deletion of your account and associated cloud data by email.
Send deletion or privacy requests to aloysius@talentintelligences.com. We may need to verify your identity and your authority over an organization before acting. Deletion may be limited where retention is required by law, needed for security or dispute resolution, or needed to protect other organization members. Deleting Ledgerly data cannot delete copies of an email already delivered to a recipient’s mailbox.
8. Changes and contact
We may update this policy as Ledgerly changes. The effective date at the top identifies the current version. Material changes will be presented through the service or another reasonable channel when appropriate.
Questions, privacy requests, and complaints can be sent to aloysius@talentintelligences.com.
