Privacy Policy
Last updated 16 August 2026
Ledgr handles bank statements, invoices and receipts — some of the most sensitive material you own. This page explains exactly what we collect, where it is stored, who else can see it, and what we send to an AI model. It is written to be specific rather than reassuring.
1. Who we are
Ledgr is operated by Nexflow AI Labs, a sole proprietorship registered in India. Under India’s Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here. You can reach us at hello@nexflowailabs.com.
2. What we collect
From your Google account, when you sign in
Your name, email address, profile picture and Google account identifier. We do not receive your Google password, and we cannot read anything else in your Google account.
What you put into Ledgr
- Files you upload — bank statements, spreadsheets, invoices, receipts and screenshots — stored exactly as you provided them.
- Transactions read out of those files, or entered by hand: date, payee, amount, currency and category.
- Your workspaces, categories, classification rules, and the payee-to- category associations Ledgr learns as you confirm them.
- Share links you create, including when each was viewed. The document itself is not copied when you share it.
Generated by using the service
- Counts of AI requests and their estimated cost, per month, so we can enforce plan limits and you can see what you have used.
- A session cookie that keeps you signed in, and a cookie remembering which workspace you were last looking at.
- Standard request information — IP address, browser and page — logged by our hosting provider, and aggregate page counts from Vercel Web Analytics. We do not use advertising cookies and we do not track you across other websites.
What we never collect
We never see or store your card number, CVV, UPI PIN, net-banking credentials or bank login. When paid plans launch, payment details are collected directly by Razorpay and never pass through Ledgr. We also never ask for, and cannot obtain, access to your bank account.
3. Why we use it
We process your data on the basis of your consent, given when you create an account and each time you upload a file, for these purposes only:
- To run the service — reading your documents, filing transactions and showing you your own data.
- To improve accuracy for you, by remembering the categories you confirm.
- To enforce plan limits and, once paid plans launch, to bill you.
- To keep the service secure and to diagnose failures.
We do not sell your data, share it with advertisers, or use the contents of your financial documents to train any AI model.
4. Where your data lives
Your account, transactions and uploaded files are stored with Supabase in AWS Asia Pacific (Mumbai), ap-south-1. Files sit in a private bucket that is not publicly readable. Access is enforced in the database itself through row-level security: every query is filtered to the workspaces you belong to, so a bug in the application cannot show you someone else’s data.
5. What we send to an AI model — and what we don’t
This is the section most people actually want, so it is stated precisely rather than in general terms.
- Spreadsheets and CSV files never leave our servers. They are parsed by ordinary code. No AI is involved and nothing is sent to Anthropic.
- Images and PDFs are sent to Anthropic so the model can transcribe the transactions printed on them. This means the contents of that document — including any names, amounts and account numbers printed on it — are transmitted for processing.
- For categorisation, only the payee text is sent — the narration string from your statement, such as “UPI/BIGBASKET/402118”. Amounts, balances, dates, your name and your email are not included in that request. Bank narrations can themselves contain a counterparty’s name or a reference number, so we are not claiming that text is anonymous — only that we send the minimum needed to name a category.
- Anthropic processes this on our behalf as a service provider. Under Anthropic’s commercial terms, inputs submitted through their API are not used to train their models.
If you would rather no AI touched a document at all, upload it as a spreadsheet or CSV, or store it in your document vault without importing it — stored documents are kept as files and are never read by a model.
6. Who else can see your data
Only these service providers, each acting on our instructions and for the purpose shown:
We will also disclose data if we are legally required to — by a court order or a valid demand from a law-enforcement or regulatory authority. If that happens we will tell you, unless we are prohibited from doing so.
7. Share links
When you share a document, Ledgr creates a long, random, unguessable link. Anyone holding that link can view and download that one document without signing in — that is the point of it. Every link carries an expiry date, you can revoke it at any moment, and deleting the document revokes every link to it immediately. Shared pages are marked so that search engines do not index them.
Treat a share link like a key: whoever you send it to can forward it.
8. How long we keep it
- Your data is kept while your account is open, because it is the product — a ledger that deletes last year is not a ledger.
- Deleting a document removes it from every view and kills its share links at once. The underlying file is retained briefly so an accidental deletion can be reversed, then permanently removed.
- If you close your account, we delete your account, workspaces, transactions and uploaded files. Records we must keep by law — for example payment and tax records once paid plans launch — are retained for the period the law requires.
- Write to us at hello@nexflowailabs.com to close your account and we will action it and confirm.
9. Your rights
Under the Digital Personal Data Protection Act, 2023, you may:
- Ask what personal data we hold about you and how it has been used.
- Have inaccurate or incomplete data corrected or completed.
- Have your data erased, subject to legal retention requirements.
- Withdraw consent at any time — which means closing your account, since we cannot run the service without processing your data.
- Nominate someone to exercise these rights if you die or become incapacitated.
- Raise a grievance with us, and escalate to the Data Protection Board of India if we do not resolve it.
10. Grievance redressal
Our Grievance Officer is Nishit Sharma, reachable at hello@nexflowailabs.com. We aim to acknowledge every complaint within 48 hours and resolve it within 30 days.
11. Security
Traffic is encrypted in transit. Files are stored in a private bucket and served only through short-lived signed links. Database access is restricted per-user by row-level security rather than by application code alone. We hold no credential that would let us — or an attacker who compromised us — move your money.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the Data Protection Board as required.
12. Children
Ledgr is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
13. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.