Privacy Policy

Last updated August 2026

Template — have a lawyer review
This is a plain-English starting draft, not legal advice. Have your attorney review and adapt it before you rely on it.

The short version

We collect what we need to run LedgerOS — your account, the documents your store scans, and what we work out from them. Some of it is about your staff, and that section is worth reading. We don't sell your data or use it for advertising, and every store's records are walled off from every other store.

What we collect

  • Account: your name and email. Passwords are handled by our authentication provider and stored hashed.
  • Documents you scan: store closes, till reports, vendor invoices, fuel delivery tickets, tank gauge printouts, cigarette counts, scratch-off books and lottery terminal reports. We keep the image as well as the figures read from it, so you can always check a number against the paper it came from.
  • What we derive: your daily ledger, inventory built from invoice lines, unit costs and margins, fuel volumes and deliveries, cash reconciliation from drawer to safe to deposit, and shrink between counts.
  • Staff:each clerk's name, a hashed PIN, the shifts and counts they run, and failed PIN attempts.
  • Devices: a browser fingerprint and user-agent for each device used at the counter, so an unrecognised one can be spotted.
  • Billing: handled by Stripe. We keep a customer reference, never your card number.
  • Contact details for alerts: the phone number and email you set for texts and summaries.

Your staff

This is the part most owners skip, and it is the part with a person on the other end of it.

LedgerOS records which clerk ran which shift and count, and scores each one for risk over a recent window using patterns in your own documents — repeated shortages, unusual voids or refunds, odd payout ratios. Those scores and the shift history behind them are visible to you as the owner. They are not shared with anyone outside your store, are not used to build any profile beyond it, and never leave your store's data.

You decide what happens next. We provide the pattern and the evidence behind it; whether it means anything is a judgement only you can make, and telling your staff they are being monitored is your responsibility under your own local law.

How we use it

  • To read your documents into figures, and to reconcile them against each other.
  • To build your inventory, margins and books from what you scan.
  • To send the alerts and summaries you turn on.
  • To bill you and support your account.

We do not sell your data, share it for advertising, or use one store's figures to inform another store's.

Reading documents with AI

When you scan a report or an invoice, the image is sent to Anthropic to be read into figures and text. It is processed to return that result and is not used to train their models under the commercial terms we use. We keep the image, the text read from it and a record of the request so a figure can always be traced back to its source.

Who we share it with

Only the providers that make LedgerOS work: Supabase (database and file storage), Stripe (billing), Anthropic (reading documents), Resend (email) and Twilio (text messages). Each receives only what it needs to do its part.

Isolation

Every store's records are separated at the database level, not just in the interface. An owner can only read the stores they belong to, and a clerk only ever reaches their own store through the counter flow.

Retention

We keep your data while your account is active, including the document images, because they are the evidence behind your figures. If you cancel, everything stays available for 90 days so you can export it, then it is deleted.

Your choices

  • Export your counts, ledger, books and accountant pack to CSV any time.
  • Turn text and email alerts on or off in alert settings.
  • Turn a clerk off, which stops them signing in at the counter. Their past shifts and counts stay on the record, because the figures those shifts produced are part of your books.
  • Ask us to delete your account and everything in it by emailing hello@ledgeros.app.

Contact

Privacy questions? Email hello@ledgeros.app.