Privacy notice
Ledger of Life is a private-beta personal finance ledger. This page explains, in plain language, what data it keeps and who can see it.
What's stored
The financial data you provide or connect: transactions, account balances, holdings, budgets and plans, and any documents you share for import (bank and brokerage exports, tax documents). Your account itself is just a name, an email address, and a password hash.
Where it lives
Each household has its own database, separate from every other household's, encrypted at rest with SQLCipher. The databases live on a private server operated by Ledger of Life, with encrypted off-site backups.
Who can access it
You, the household members you invite, and the operator — for support and troubleshooting. Operator access to a household is recorded in an audit log.
AI-assisted support
When you ask for help, or a problem in your ledger is investigated, that work is done with Claude, Anthropic's AI tooling — so the data involved can pass through it. That content isn't used to train models. You agree to this when you accept your invite, and the consent is recorded.
Onboarding doesn't involve sending your files to anyone: you connect your own accounts, and the balance-history importer runs inside the app.
Bank connections (Plaid)
Ledger connects to your banks and brokerages through Plaid. You choose which accounts to connect, and that connection is governed by Plaid's end-user privacy policy. Nothing is connected on your behalf, and you can disconnect an institution at any time — your accounts and imported transactions stay in your ledger when you do.
No selling, no sharing
Your data isn't sold, shared, or used for advertising. It exists so your ledger works — nothing else.
Beta caveats
This is a beta: features may change, and occasionally data models evolve with them. You can request an export of your data, or full deletion of your household, at any time.
Contact
Questions or requests? Reply to your invite email.
Last updated: July 2026