Ledgr

Privacy Policy

1. Who we are

Ledgr is operated by Nexflow AI Labs, a sole proprietorship registered in India. Under India’s Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here. You can reach us at hello@nexflowailabs.com.

2. What we collect

From your Google account, when you sign in

Your name, email address, profile picture and Google account identifier. We do not receive your Google password, and we cannot read anything else in your Google account.

What you put into Ledgr

Generated by using the service

What we never collect

We never see or store your card number, CVV, UPI PIN, net-banking credentials or bank login. When paid plans launch, payment details are collected directly by Razorpay and never pass through Ledgr. We also never ask for, and cannot obtain, access to your bank account.

3. Why we use it

We process your data on the basis of your consent, given when you create an account and each time you upload a file, for these purposes only:

We do not sell your data, share it with advertisers, or use the contents of your financial documents to train any AI model.

4. Where your data lives

Your account, transactions and uploaded files are stored with Supabase in AWS Asia Pacific (Mumbai), ap-south-1. Files sit in a private bucket that is not publicly readable. Access is enforced in the database itself through row-level security: every query is filtered to the workspaces you belong to, so a bug in the application cannot show you someone else’s data.

5. What we send to an AI model — and what we don’t

If you would rather no AI touched a document at all, upload it as a spreadsheet or CSV, or store it in your document vault without importing it — stored documents are kept as files and are never read by a model.

6. Who else can see your data

Only these service providers, each acting on our instructions and for the purpose shown:

We will also disclose data if we are legally required to — by a court order or a valid demand from a law-enforcement or regulatory authority. If that happens we will tell you, unless we are prohibited from doing so.

7. Share links

When you share a document, Ledgr creates a long, random, unguessable link. Anyone holding that link can view and download that one document without signing in — that is the point of it. Every link carries an expiry date, you can revoke it at any moment, and deleting the document revokes every link to it immediately. Shared pages are marked so that search engines do not index them.

Treat a share link like a key: whoever you send it to can forward it.

8. How long we keep it

9. Your rights

Under the Digital Personal Data Protection Act, 2023, you may:

10. Grievance redressal

Our Grievance Officer is Nishit Sharma, reachable at hello@nexflowailabs.com. We aim to acknowledge every complaint within 48 hours and resolve it within 30 days.

11. Security

Traffic is encrypted in transit. Files are stored in a private bucket and served only through short-lived signed links. Database access is restricted per-user by row-level security rather than by application code alone. We hold no credential that would let us — or an attacker who compromised us — move your money.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the Data Protection Board as required.

12. Children

Ledgr is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.

13. Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.