Effective August 7, 2026
Privacy Policy
This Privacy Policy explains how Apphibian LLC handles information for Ledge, a personal finance app for tracking transactions, receipts, statements, budgets, savings, and related review workflows.
Information we collect
Ledge collects the information needed to provide the app, including account identifiers, app preferences, transactions, merchants, categories, budgets, savings goals, receipt details, statement import records, statement rows, email receipt imports, Gmail connection records when you connect Gmail, and support messages you choose to send.
Financial records may include dates, amounts, merchants, categories, transaction types, notes, receipt line items, statement metadata such as bank or card names, account or card suffixes, billing periods, review states, and duplicate or learning decisions you confirm.
Receipts, emails, and statements
Ledge uses parser workflows to turn receipts, forwarded receipt emails, Gmail receipt imports, and statement PDFs into reviewable app records. New parser paths do not retain raw OCR text, raw email text, raw statement text, Gemini prompts, or Gemini responses. Normalized records needed for app functionality remain stored until you delete them.
Receipt images and statement PDFs are handled as temporary S3 ingestion artifacts. The app saves an app-controlled local copy for later viewing, confirms that local copy to the backend, and the backend then deletes the temporary S3 object after parsing is complete or the import reaches a terminal failure. Statement PDFs may remain temporarily while a statement-type confirmation flow still needs the original PDF for reparse.
Local receipt and statement copies are stored on your device for app viewing. They may not survive reinstall or use on a new device unless a future encrypted backup or sync feature is added.
How we use information
We use your information to operate Ledge, authenticate requests, show and edit your records, parse imports, detect possible duplicates, support merchant and category learning, generate budgets and savings views, provide exports and account controls, troubleshoot issues, protect the service, and communicate with you about support or product access.
AI processing
Ledge may send the minimum necessary receipt, email, or statement content to AI parsing providers when local or deterministic parsing is not enough. AI output is validated before saved records are created. Ledge does not store raw Gemini prompts or responses in the checked parser paths, but normalized app records created from parsing are stored for the product features you use.
Gmail and email imports
If you connect Gmail, Ledge stores the connection details needed to search and import receipt emails you choose to bring into the app. Gmail access tokens are encrypted before storage and decrypted only for server-side Gmail calls. You can disconnect Gmail from Ledge, which deletes the stored connection and attempts to revoke the refresh token.
Forwarded receipt emails are received through Apphibian-controlled infrastructure and parsed into pending review records. Raw email bodies are used for parsing and are not written into the current email import storage path.
Device permissions
Ledge may request camera or photo-library access so you can scan or select receipts and documents. The current mobile configuration also includes broader permissions that are being narrowed before public release so store disclosures and app behavior stay aligned.
How we protect information
Ledge uses Clerk authentication, authenticated backend routes, user ownership checks, private S3 objects, short-lived signed URLs where file access is needed, shared-secret protection for system ingestion routes, rate limiting, sensitive-log cleanup, and database encryption at rest. User note fields and Gmail tokens are encrypted before database storage by app code.
Ledge is not currently a zero-knowledge or fully end-to-end encrypted finance app. Some server workflows still need readable normalized financial data to support review, duplicate matching, budgets, reporting, insights, and transaction creation.
Sharing
We do not sell your personal information. We share information with service providers that help operate Ledge, such as hosting, database, authentication, storage, email, analytics or monitoring, and AI parsing providers. We may also disclose information if required by law, to protect users or the service, or as part of a business transfer.
Your choices
You can edit or delete individual records in the app, export transaction data to CSV, disconnect Gmail, remove transactions, delete user-created app data, or delete your account. Account deletion is designed to remove app data, email inbox records, Gmail connection records, stored statement PDFs, stored receipt images, import traces, and the associated Clerk account.
Retention
Ledge keeps normalized app records while your account is active or until you delete them. Temporary receipt images and statement PDFs uploaded to S3 are deleted after their final required parsing use and app-local-copy confirmation, with retry and reconciliation tracking. Some legacy referenced PDFs may remain until reset or account deletion cleanup.
Future privacy plan
Apphibian plans to keep reducing backend-visible sensitive data. The next planned privacy work for statements is practical end-to-end encryption for lower-query account metadata, including account or card suffixes, bank or card names, billing periods, and warning acceptance identity tokens. The intended design uses a device-held master key, encrypted server-stored key material, device-generated blind tokens for equality checks, and client-side decryption for display.
A later, larger redesign may move more statement PDF extraction to the device so the original PDF can stay local. That is a future plan, not current behavior.
Children
Ledge is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes
We may update this Privacy Policy as Ledge changes. When we do, we will update the effective date on this page.
Contact
For privacy questions, email hello@apphibian.app.