Security & Privacy

Where does your client's data go?

That's a fair question before uploading financial records. Here's the complete answer — no marketing language.


🔒
Encrypted in Transit
All data transferred over HTTPS/TLS 1.2+. No unencrypted connections.
🗑️
Auto-Deleted at 30 Days
Uploaded files are automatically purged after 30 days. Delete anytime manually.
🔐
Your Files Only
Download endpoints require authentication. No one else can access your files.

What happens to your uploaded file

When you upload a bank statement or ledger file, here's exactly what happens — step by step.

Who can access your files

Every file is tied to your account. Download links require a valid session token — they cannot be accessed by anyone who isn't logged in as you.

No public file URLs. If someone finds or guesses a job ID, they still cannot download the file without your authentication credentials. All download endpoints verify both identity and file ownership before serving any content.

How long we keep your data

Data Type Retention Notes
Original uploaded file Deleted immediately Deleted from disk after parsing. Never stored permanently.
Processed output file (XLSX) 30 days Auto-purged after 30 days. Delete manually anytime from File History.
Annotated original (color-coded) 30 days Same retention as standardized output.
Job metadata (filename, row count, anomalies) Account lifetime Lightweight record used to populate your File History. No financial data, no file contents.
Account credentials Until account deletion Email + bcrypt-hashed password only. Plain passwords never stored.

To delete your processed files, go to File History in the app and click the delete button next to any job. To delete your account entirely, email support@ledgerready.app.

Who else sees your data

Your financial data is not sold, shared, or provided to any third party for their own purposes. Here's the complete list of external systems that touch your data:

No marketing, analytics, or ad platforms receive your data. We don't use Google Analytics, Facebook Pixel, or any behavior tracking on the app pages. Your file processing activity is not profiled or monetized.

Where your data is processed and stored

Component Provider Compliance
Web server / file processing Render (US) SOC 2 Type II, GDPR
Database (job metadata) Neon PostgreSQL (US) SOC 2 Type II, GDPR
Transit encryption TLS 1.2 / 1.3 HTTPS enforced
Password storage bcrypt (cost factor 10) One-way hash, never plaintext
Session tokens JWT (HS256, 30-day expiry) Stored client-side only

Talk to us about security

If you have a specific compliance question before uploading client data — HIPAA, SOC 2, firm security policy, anything — reach out directly. We'll answer plainly.

Email: support@ledgerready.app

Ready to try it on a real file?

One free file included — no credit card required.

Try It Free →