Privacy Policy
Last updated: September 2026
This privacy policy reflects how the product actually handles data, but it has not yet been reviewed by legal counsel. It will be reviewed before public launch.
What data we collect
- Account information — name, email address, hashed password, login history.
- Company financial data — chart of accounts, ledger entries, commits, staging rows, vendors, customers, staff records and notes, scoped to your company.
- Document uploads — bank statements, receipts, invoices and other evidence files uploaded through the platform, stored in managed object storage.
- Usage logs — authentication events, audit-log entries recording actions taken in the platform, and page views for error monitoring.
How it is used
Your data operates the close workflow: intake, staging, classification, review, evidence matching, finalization and reporting.
Models. LedgerDock uses machine models to read statements and to propose account assignments. Every one of those models is self-hosted and runs on our own hardware. No client data is sent to any third-party AI provider. We do use your uploaded documents and your coding corrections to improve those in-house models; that data never leaves our hardware, is never sold, and is never given to a third party.
Sensitive identifiers — Social Security numbers, EINs, tax IDs and full bank account numbers — are encrypted at rest and are read by deterministic code, not by a model.
Who has access
- You — full access to your own account and to any company you are assigned to.
- Your firm members — access is controlled by role. Firm owners and senior accountants can see every company in the firm; staff accountants see only the companies assigned to them.
- LedgerDock staff — access to your data only for support, and only with your explicit consent, except where it is required to maintain the integrity of the system or to comply with a legal obligation.
Data retention
Financial data is retained while your account is active. Audit-log entries are retained indefinitely, because they are the record of what happened.
Your rights
- Export — your ledger data, chart of accounts and commit history can be exported at any time, in one click.
- Deletion — you can request deletion of your account and its associated data by contacting us. There is no self-service account closure today.
- Correction — profile information is editable directly. Financial data is corrected through the normal workflow: work that is not yet finalized is editable, and finalized work is corrected with a reversing entry, so the history stays intact.
Cookies
LedgerDock uses a small number of functional cookies and nothing else:
- Session cookie — the server-side session identifier. Required to stay logged in.
- CSRF token — prevents cross-site request forgery. Required for forms.
- Device-trust cookie — set after you pass the one-time-code check, so that browser is not asked again for 30 days.
We do not use tracking pixels, third-party analytics cookies, or advertising trackers.
Third-party services
- Railway — managed PostgreSQL hosting for the application database.
- Amazon Web Services (S3) — object storage for uploaded documents, with server-side encryption enabled on every upload.
- Plaid — read-only bank and card transaction feeds, when you connect one.
- Email provider — transactional email for verification, login codes and invitations.
There is no third-party AI provider in this list, and that is deliberate.
Contact
Privacy questions and data requests: admin@ledgerdock.com
An accountant's close tool. Month-end, year-end, closed right.