Ledger & Co.Privacy Policy
Ledger & Co. handles financial information, which we treat as sensitive. Critically, it never asks for and never holds your banking credentials.
The short version
You paste in bank alerts you already received; the app parses them and stores the resulting entries against your account so they sync across devices. We never ask for your net-banking login, card numbers or UPI PIN, and the app has no ability to move money.
What we never ask for
Banking credentials. Ledger & Co. does not ask for, does not accept and cannot use your net-banking username or password, your card number, CVV, or your UPI PIN. It has no connection to your bank and no ability to initiate a transaction.
The app reads text you paste in. That is the entire mechanism. If anything ever asks you for a banking credential in the name of this app, it is not this app.
Who we are
Ledger & Co. is operated by Divyansh Karan, trading as Stelr Studio (Remote · India), the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.
Account information
| Data | Why | Required |
|---|---|---|
| Email address | To create your account, sign you in and send password resets | Yes |
| Password | Stored only as a salted hash by our authentication provider — we never see it | Yes |
| Display name | Shown in the app | Optional |
Financial information
All of it comes from what you enter or paste in:
This is financial information. It is used only to build your own monthly view. It is never sold, never used for advertising, and never shared with a lender, insurer, credit bureau or data broker.
- Transaction entries — amount, date, merchant name and the account label they were filed against, parsed from alerts you paste in or entered by hand
- Your monthly plan — income, commitments, budgets and categories
- The account labels you create (for example 'Salary account' or 'Credit card') — these are names you choose, not account numbers
- Notes you attach to an entry
SMS, specifically
The app does not request the SMS read permission and does not have access to your messages. You paste an alert in yourself, which means you choose exactly what the app ever sees.
This is slower than automatic SMS ingestion, and it is deliberate: the permission that would automate it also grants access to every other message on the device, including one-time passcodes.
What we never collect
None of the following is collected, by design:
- Advertising identifiers, or any data used for advertising or profiling
- Contacts, calendar, SMS or call logs
- Data bought from, or shared with, data brokers
- Any cross-app or cross-site tracking
How we use it
Your data is used to run the app and nothing else:
We do not use your data for advertising, we do not sell it, and we do not share it with data brokers or credit reference agencies.
- Parse the alerts you paste and file the resulting entries
- Build your monthly plan, budgets and category views
- Sync your ledger across the devices you sign in on
- Sign you in and keep you signed in
- Respond when you contact support
Legal bases for processing (GDPR)
If you are in the UK or EEA:
- Contract — providing the account and ledger you signed up for.
- Consent — optional profile details and notifications, withdrawable at any time.
- Legitimate interests — keeping the service secure and working.
Where your data is stored
Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.
How long we keep it
- While your account exists — as long as you keep it. Delete any individual entry at any time.
- When you delete your account — your profile, entries, plans and categories are permanently deleted.
- Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.
Security
The protections actually in place:
No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.
- All traffic between the app and our servers uses HTTPS/TLS.
- Passwords are stored only as a salted hash by the authentication provider — we never see them.
- Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
- Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
- Sign-in uses the PKCE authorization-code flow.
Your rights
Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.
To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.
- Access — everything we hold is visible inside the app.
- Correct — edit any entry or profile field directly.
- Export — request a machine-readable copy of your data.
- Delete — delete individual entries, or your whole account, from inside the app.
- Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
- Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).
Deleting your account
Settings → Delete account permanently erases your profile, every transaction entry, your plans, budgets and categories.
If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.
Children
Ledger & Co. is not intended for children under 18. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.
Changes to this policy
If this policy changes, the updated version ships with the Ledger & Co. release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.
Contact
Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).
This policy covers Ledger & Co. only. Other Stelr apps have their own policies, listed on the apps page.