← Back to Ledger & Co.Privacy policy

Ledger & Co.Privacy Policy

Last updated Account-based · financial data, never bank credentials

Ledger & Co. handles financial information, which we treat as sensitive. Critically, it never asks for and never holds your banking credentials.

The short version

You paste in bank alerts you already received; the app parses them and stores the resulting entries against your account so they sync across devices. We never ask for your net-banking login, card numbers or UPI PIN, and the app has no ability to move money.

What we never ask for

Banking credentials. Ledger & Co. does not ask for, does not accept and cannot use your net-banking username or password, your card number, CVV, or your UPI PIN. It has no connection to your bank and no ability to initiate a transaction.

The app reads text you paste in. That is the entire mechanism. If anything ever asks you for a banking credential in the name of this app, it is not this app.

Who we are

Ledger & Co. is operated by Divyansh Karan, trading as Stelr Studio (Remote · India), the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.

Account information

DataWhyRequired
Email addressTo create your account, sign you in and send password resetsYes
PasswordStored only as a salted hash by our authentication provider — we never see itYes
Display nameShown in the appOptional

Financial information

All of it comes from what you enter or paste in:

This is financial information. It is used only to build your own monthly view. It is never sold, never used for advertising, and never shared with a lender, insurer, credit bureau or data broker.

  • Transaction entries — amount, date, merchant name and the account label they were filed against, parsed from alerts you paste in or entered by hand
  • Your monthly plan — income, commitments, budgets and categories
  • The account labels you create (for example 'Salary account' or 'Credit card') — these are names you choose, not account numbers
  • Notes you attach to an entry

SMS, specifically

The app does not request the SMS read permission and does not have access to your messages. You paste an alert in yourself, which means you choose exactly what the app ever sees.

This is slower than automatic SMS ingestion, and it is deliberate: the permission that would automate it also grants access to every other message on the device, including one-time passcodes.

What we never collect

None of the following is collected, by design:

  • Advertising identifiers, or any data used for advertising or profiling
  • Contacts, calendar, SMS or call logs
  • Data bought from, or shared with, data brokers
  • Any cross-app or cross-site tracking

How we use it

Your data is used to run the app and nothing else:

We do not use your data for advertising, we do not sell it, and we do not share it with data brokers or credit reference agencies.

  • Parse the alerts you paste and file the resulting entries
  • Build your monthly plan, budgets and category views
  • Sync your ledger across the devices you sign in on
  • Sign you in and keep you signed in
  • Respond when you contact support

Who we share data with

We use these processors, and share your data with no one else except where legally required.

ProcessorWhat it handlesTheir policy
SupabaseDatabase, authentication and edge functions — account and ledger datasupabase.com/privacy
Expo / EASApp builds and updates. No personal data.expo.dev/privacy

Where your data is stored

Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.

How long we keep it

  • While your account exists — as long as you keep it. Delete any individual entry at any time.
  • When you delete your account — your profile, entries, plans and categories are permanently deleted.
  • Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.

Security

The protections actually in place:

No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.

  • All traffic between the app and our servers uses HTTPS/TLS.
  • Passwords are stored only as a salted hash by the authentication provider — we never see them.
  • Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
  • Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
  • Sign-in uses the PKCE authorization-code flow.

Your rights

Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.

To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.

  • Access — everything we hold is visible inside the app.
  • Correct — edit any entry or profile field directly.
  • Export — request a machine-readable copy of your data.
  • Delete — delete individual entries, or your whole account, from inside the app.
  • Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
  • Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).

Deleting your account

Settings → Delete account permanently erases your profile, every transaction entry, your plans, budgets and categories.

If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.

Children

Ledger & Co. is not intended for children under 18. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.

Changes to this policy

If this policy changes, the updated version ships with the Ledger & Co. release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.

Contact

Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).

This policy covers Ledger & Co. only. Other Stelr apps have their own policies, listed on the apps page.