Privacy Policy

Last updated: 20 September 2026

LedgerPilot AI is an AI-assisted double-entry bookkeeping service, operated by CyberProMedia. This policy explains what information the service processes, why it is processed, which providers process it on our behalf, and the choices you have.

It describes how the service works today. Where something is optional or not yet switched on, we say so rather than implying it is already in use.

1. Who this policy covers

This policy covers visitors to ledgerpilotai.com and people who use the LedgerPilot AI application. If your organization created the workspace you use, that organization controls the accounting records inside it, and we process those records on its behalf.

2. Information we process

Account and authentication information
The email address you sign up with and the authentication records held by our authentication provider. When you sign up, the service automatically creates an organization and records you as its owner.
Organization and membership information
Your organization, the people who belong to it, and the role each person holds. Roles determine what each member can see and do.
Accounting and financial records
Your chart of accounts, transactions, ledger entries, and the reports generated from them, such as trial balance, profit and loss, balance sheet, and cash movement.
Receipts and uploaded documents
Receipt files you upload, in JPEG, PNG, WebP, or PDF format, together with the fields read from them, such as vendor, date, total, currency, and line items. Receipt files are held in private storage and are shown to you through short-lived signed links rather than public URLs.
Bank statement imports
CSV bank statement files you upload and the transactions read from them. The service does not connect to your bank and never asks for banking credentials.
Activity and audit records
The service writes an audit record for sensitive actions, such as signup, categorization review, and account changes. These records are append-only, as described in section 9.
Diagnostic and technical information
Your IP address is used to apply upload rate limits. When something goes wrong, the service collects error and performance information so we can diagnose the fault.

3. How we use information

  • To provide the service: authentication, workspaces, bookkeeping records, and reports.
  • To read receipts you provide and suggest an accounting categorization for your review.
  • To keep the service secure and available, including rate limiting and abuse prevention.
  • To diagnose faults and improve reliability.
  • To communicate with you about your account, such as email confirmation.
  • To meet legal, tax, accounting, and record-keeping obligations.

We do not sell personal information, and we do not use your accounting records or receipts for advertising.

4. AI-assisted processing

Receipts you upload, and the transaction details used for categorization, are sent to Anthropic and processed by Claude models so the service can read the document and suggest an accounting category. Only the content needed for that step is sent.

AI output is always a suggestion. A person in your organization reviews it, and nothing is posted to your ledger until someone approves it.

5. Google Account and Gmail integration

This section applies only when you connect a supported Gmail account to LedgerPilot AI for receipt and document intake. The integration is optional and is not connected by default. If you never connect a Google account, LedgerPilot AI does not access your Google account or your Gmail data at all.

Authorization

Connecting the integration sends you to Google, where Google shows you the access being requested. Access begins only if you approve it there, and is limited to what you approve.

The permission we request

LedgerPilot AI requests a single, read-only Gmail permission:

https://www.googleapis.com/auth/gmail.readonly

This permission is read-only. LedgerPilot AI cannot send email, delete email, modify email, apply or change labels, or otherwise manage your mailbox.

What we access and why

We access only the Gmail information needed for the intake workflow you enabled, and only to the extent that workflow requires, in order to identify receipts and invoices and bring them into your workspace. We do not browse your mailbox for unrelated purposes.

Google API Services User Data Policy

LedgerPilot AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the intake feature you enabled.
  • We do not use Google user data for advertising.
  • We do not sell Google user data.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
  • We do not transfer Google user data to others except as necessary to provide or improve the feature, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • People do not read your Google user data except where you have given specific consent, where it is necessary for security purposes such as investigating abuse, where the law requires it, or where the data has been aggregated and anonymized for internal operations.

Withdrawing access

You can withdraw LedgerPilot AI’s access to your Google account at any time from your Google account permissions page at myaccount.google.com/permissions. Withdrawing access there stops any further Gmail access. If you also want us to delete information already brought into your workspace, please contact us, subject to the limits described in section 9.

6. Service providers

We use the following providers. Each processes information only to provide its part of the service.

ProviderRoleWhat it processes
SupabaseDatabase, authentication, file storageAccount and authentication records, organizations and memberships, accounting records, receipt files, audit records
AnthropicAI extraction and categorizationReceipt files and the transaction details submitted for categorization
VercelApplication hosting and deliveryRequests to the service, including IP address and request logs
SentryError monitoring and performance tracingError reports, diagnostic context, and performance trace data
UpstashRate limitingA counter keyed to your IP address, used to limit uploads

Our domain name is managed through Cloudflare DNS, which resolves the domain but does not proxy or inspect traffic to the service. Information may be processed in the United States and in other countries where these providers operate.

7. Error monitoring and performance tracing

We use Sentry to record application errors and performance traces so we can diagnose faults and keep the service reliable. Error reports may include technical context about the request in which the error occurred.

LedgerPilot AI does not use Sentry Session Replay or any other session or screen recording for application monitoring. We do not record a replay of your use of the application.

8. Cookies and sessions

We set cookies that are strictly necessary to sign you in and keep your session active. We do not use advertising cookies, and the application does not currently run product analytics or marketing trackers.

9. Retention, deletion, and immutable records

Some records in a bookkeeping system are deliberately permanent. We would rather be precise about that than promise erasure we cannot perform.

  • There is no self-service delete. The application does not currently provide a way for you to delete your account or erase your workspace yourself. Deletion requests are handled by contacting us, as described in section 12.
  • Audit records are append-only. The database rejects attempts to change or remove them, so that changes to financial data stay traceable. We cannot delete individual audit records on request.
  • Posted transactions are immutable. Once a transaction is posted it cannot be edited or deleted. Corrections are made by posting a reversing entry, which is standard double-entry accounting practice.
  • Backups. The service is backed up on a regular basis. Information you delete may remain in backups for a limited period until those backups expire.
  • We keep your information for as long as your workspace is active, and afterwards where we need it to meet legal, tax, or accounting obligations, or to resolve disputes.

10. Storage and security

These are measures the service applies. They are a description of our practices, not a guarantee against every risk.

  • Row-level security on database tables, scoping records to your organization.
  • Receipt files kept in private storage, reachable only through short-lived signed links.
  • An append-only audit trail for sensitive actions.
  • Administrative database credentials confined to server-side code, never exposed to the browser.
  • HTTPS for traffic to the service, with standard security response headers.
  • Rate limiting on upload endpoints.

No service can promise perfect security. LedgerPilot AI does not hold a security or privacy certification, and we make no claim of certification or audit status.

11. Your choices

Depending on where you live, you may have rights to access, correct, export, or delete personal information, or to object to or restrict certain processing. To ask about any of these, contact us as described below. Where your organization controls the records in question, we may refer your request to that organization. Please note the limits described in section 9, and that you can withdraw Google account access yourself as described in section 5.

LedgerPilot AI is intended for business use.

12. Contact

For privacy questions, or to make an access or deletion request, contact us at shullyemmasinc.ledger@gmail.com. If your workspace was created by your organization, you can also contact the administrator who manages it.

13. Changes to this policy

We may update this policy as the service changes. When we do, we will update the date at the top of this page, and for significant changes we will take reasonable steps to let you know.