Legal

Privacy Policy

Last updated: July 2026

Your data is never used for model training

LedgerShift does not use your financial data, usage data, or any personally identifiable information to train, fine-tune, or improve any AI or machine learning model — ours or any third party's. This is a foundational commitment, not an opt-out setting.

Overview

LedgerShift ("we," "our," or "us") provides AI Financial Intelligence software for AI-native SaaS companies. This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights as a user.

By using LedgerShift, you agree to the practices described in this policy. If you have questions, contact us at privacy@ledgershift.ai.

Your Data Is Never Used for Model Training

LedgerShift does not use your financial data, usage data, or any personally identifiable information to train, fine-tune, or improve any AI or machine learning model — ours or any third party's.

Your data exists solely to power your own LedgerShift experience. It is never aggregated, anonymized, or repurposed for model development. This is a foundational commitment, not a setting you need to opt out of.

What We Collect

We collect only what is necessary to deliver the service:

  • Account information — work email address, name, and company name provided during registration or early access requests.
  • Financial data you upload — AI vendor invoices, cost exports (e.g., OpenAI, Anthropic, AWS Bedrock, Azure OpenAI, Vertex AI), and any data you import into the AI Economics Ledger. This data is yours and is processed solely to generate your ledger, reports, and analytics.
  • Usage data — pages visited, features used, session duration, and interaction events. Used to improve product reliability and identify issues. Never sold or shared with third-party advertisers.
  • Technical data — browser type, operating system, IP address, and device identifiers. Used for security, fraud prevention, and service delivery.

We do not collect payment card data directly. Payment processing is handled by our payment provider and governed by their privacy policy.

How We Use Your Data

We use your data exclusively to:

  • Deliver and operate the LedgerShift platform and AI Economics Ledger
  • Normalize and categorize your AI vendor spend using the FOCUS 1.4 standard
  • Generate financial reports, COGS waterfalls, and margin analyses within your account
  • Send transactional communications (account setup, security alerts, product updates you've opted into)
  • Investigate security incidents and prevent fraud
  • Comply with legal obligations

We do not sell your data. We do not use your data for advertising. We do not share your financial data with other customers or third parties except as described in the "Data Sharing" section below.

Data Storage & Infrastructure

LedgerShift is built on Supabase, which provides our database, authentication, and storage infrastructure. Data is stored in encrypted PostgreSQL databases with row-level security (RLS) enforced at the database layer — meaning your data is isolated from other customers' data by design, not just by application logic.

  • Encryption at rest — all data stored in LedgerShift is encrypted at rest using AES-256.
  • Encryption in transit — all data transmitted between your browser and LedgerShift servers is encrypted via TLS 1.2 or higher.
  • Data residency — data is stored in the United States by default. Contact us if your organization requires a specific data residency region.
  • Backups — data is backed up automatically. Backups are encrypted and retained for 30 days.

Data Sharing

We share data only in the following limited circumstances:

  • Infrastructure providers — Supabase (database and auth), and other sub-processors necessary to operate the service. All sub-processors are contractually bound to data protection standards consistent with this policy.
  • Legal requirements — if required by law, court order, or government authority, we will notify you to the extent permitted before disclosing.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, your data may transfer to the acquiring entity. We will notify you before your data becomes subject to a materially different privacy policy.

We do not share your financial data with AI vendors (OpenAI, Anthropic, AWS, Azure, Google, etc.) or any third party for any purpose other than operating the service you have requested.

Data Retention

We retain your data for as long as your account is active or as needed to provide the service. If you close your account, we will delete your personal data and financial data within 30 days, except where we are required to retain it for legal or regulatory compliance purposes.

Anonymized, aggregated usage statistics (with no connection to your identity or financial data) may be retained indefinitely for product analytics.

Your Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate or incomplete data.
  • Deletion — request deletion of your personal data ("right to be forgotten").
  • Portability — request your data in a structured, machine-readable format.
  • Objection — object to certain types of processing, including direct marketing.
  • Restriction — request that we restrict processing of your data in certain circumstances.

To exercise any of these rights, email privacy@ledgershift.ai. We will respond within 30 days.

Cookies & Tracking

LedgerShift uses a minimal set of cookies:

  • Essential cookies — required for authentication and session management. Cannot be disabled without breaking the service.
  • Analytics cookies — used to understand how the product is used (page views, feature usage). No cross-site tracking. You can opt out by contacting us.

We do not use advertising cookies, retargeting pixels, or third-party tracking scripts that share your data with ad networks.

Security Practices

We take the security of financial data seriously. Our current security practices include:

  • Row-level security (RLS) enforced at the database layer — your data is isolated from other tenants
  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Authentication via Supabase Auth with support for multi-factor authentication
  • Regular dependency audits and security patching
  • Access controls limiting which team members can access production data

If you discover a security vulnerability, please report it responsibly to security@ledgershift.ai.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address associated with your account) and update the "Last updated" date at the top of this page. Continued use of LedgerShift after the effective date of a revised policy constitutes acceptance of the changes.

Contact

For privacy-related questions, data requests, or concerns:

© 2026 LedgerShift. All rights reserved. · Home