Privacy Policy
Last updated: July 4, 2026
Our Commitment to Privacy
OpenLedger is designed so that your financial data remains yours — always. We do not collect, sell, rent, or share your personal information or financial records. This policy explains what information is handled, how, and what choices you have.
Data Controller
OpenLedger is developed and maintained by Sparsh Sam. As the data controller for any personal information processed through the optional cloud backup feature, your data is handled in accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) where they apply.
Local-First Operation
In its default guest mode, OpenLedger stores all data — accounts, transactions, budgets, goals, categories, and settings — exclusively in your browser's localStorage. No data is transmitted to any server. You can export a complete JSON backup at any time from Settings.
Optional Cloud Backup
If you sign in with Google OAuth, you may optionally back up your ledger to Supabase, a SOC 2-compliant hosted PostgreSQL database. Key details:
- Manual only. Backups and restores are triggered by you. Nothing is uploaded automatically.
- What is stored. Only the data you explicitly upload: your accounts, transactions, budgets, goals, and settings.
- You retain control. Cloud backups can be deleted at any time from the Cloud Backup panel in Settings.
- Authentication data. When you sign in, Supabase Auth processes your Google account email and avatar URL. No financial data is involved in authentication.
Information We Collect
None. OpenLedger does not include analytics, telemetry, tracking pixels, heatmaps, session recording, or crash reporting. The application makes network requests only in these specific circumstances:
- Service worker caching — standard PWA assets are cached for offline functionality.
- Supabase Auth — if you sign in, authentication requests are sent to the Supabase Auth API.
- Cloud Backup — if you manually trigger a backup or restore, data is transferred to or from Supabase.
Legal Basis for Processing (GDPR)
For users in the European Economic Area, the legal basis for processing personal data through the optional cloud backup feature is your consent. You give consent by choosing to sign in and manually initiating a backup. You may withdraw consent at any time by deleting your cloud backup and ceasing use of the feature.
Data Retention
- Guest mode datapersists in your browser until you clear your site data or use the “Clear local data” option in Settings. No server-side copy exists.
- Cloud backup data is retained until you delete it via the Cloud Backup panel. You may also request deletion by emailing sparshsam@gmail.com; we will confirm and process the request within 30 days.
Third-Party Services
OpenLedger is deployed on Vercel. Vercel processes standard HTTP request metadata (IP address, user agent, request path, timestamp) as part of their hosting service. We do not access, store, or analyse these logs. See Vercel's Privacy Policy for details.
Supabase provides the optional cloud backup infrastructure. If you choose to use cloud backup, your data is stored on Supabase's SOC 2-compliant infrastructure in the United States. See Supabase's Privacy Policy for details.
Google OAuth is used solely for authentication. No financial data is shared with Google through this integration. See Google's Privacy Policy for details.
International Data Transfers
If you use the optional cloud backup feature, your data may be stored and processed in the United States. For users in the European Economic Area or the United Kingdom, we rely on Standard Contractual Clauses or equivalent safeguards to ensure an adequate level of data protection.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to access — request a copy of the data we hold.
- Right to rectification — correct inaccurate data.
- Right to erasure — request deletion of your data.
- Right to restrict processing — limit how we use your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing of your data.
To exercise these rights, email sparshsam@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Data Export
You can export your complete ledger as a JSON file at any time from Settings → Local data → Export JSON. The export includes all accounts, transactions, budgets, goals, categories, and import metadata. No additional requests are necessary — your data never leaves your device during export.
Changes to This Policy
If this policy is updated materially, the “Last updated” date will be revised. Material changes will be communicated through the application. We will never reduce your privacy rights under this policy without your explicit consent.
Contact
For privacy questions, data deletion requests, or to exercise any of your data rights, contact:
Sparsh Sam
Email: sparshsam@gmail.com
GitHub: github.com/sparshsam