Privacy Policy
SmartLedger ("we", "us", or "our") is an AI-powered expense tracking service. This Privacy Policy explains what data we collect, how we use it — including when you connect Gmail or Outlook — and the choices you have.
1. Information we collect
We collect the following categories of information:
Account information
- Email address and authentication identifiers when you sign in (for example via magic link, Google, or Microsoft through our auth provider)
- Profile details such as your display name and a private inbound email address used to receive forwarded receipts
- Subscription and billing status if you use a paid plan
Financial and receipt data you provide
- Receipt images and PDFs you upload, plus extracted fields (vendor, amount, date, category, and similar metadata)
- Transactions, ledger entries, and review-queue items
- Usage data such as parsing credits consumed
Mailbox connection data (optional)
If you choose to connect Gmail, Outlook, or Yahoo in Settings, we store:
- Which provider is connected and the mailbox email address
- OAuth access and refresh tokens, encrypted at rest, so we can perform actions you authorize on your behalf
- Connection status and timestamps
Technical and usage data
- Device/browser type, IP address, and request logs for security
- Error and performance diagnostics (for example via Sentry, if enabled)
2. How we use Gmail data
Gmail access is optional and only activated when you click Connect Gmail and complete Google's OAuth consent screen. We request these permissions:
gmail.settings.basic— to add a forwarding address and create a mail filter so receipt- and invoice-related messages can be forwarded to your private SmartLedger inbound addressgmail.readonly— to scan recent messages when you use Fetch receipts, limited to metadata needed to detect finance-related emails (subject, date, and a short preview snippet)openidanduserinfo.email— to identify which Gmail account you connected
We use Gmail data only to:
- Configure forwarding and filters you asked us to set up
- Find candidate receipt or invoice emails and extract transaction details for your ledger
- Maintain your connection until you disconnect or delete your account
We do not use Gmail data for advertising, sell your inbox contents, or enable global "forward all mail" without a filter. We do not send email on your behalf.
3. How we use Outlook / Microsoft mailbox data
If you connect Outlook, we use Microsoft Graph with your consent to:
- Create an inbox rule that forwards receipt- and invoice-related messages to your SmartLedger inbound address
- Read recent messages when you use Fetch receipts (subject, date, and body preview)
- Read your profile email address to confirm the connected mailbox
The same limitations apply: no ads, no resale of mailbox content, and no sending email from your account.
4. How we use Yahoo Mail data
Yahoo Mail access is optional and only activated when you click Connect Yahoo Mail and complete Yahoo's OAuth consent screen.
We use Yahoo Mail data to:
- Identify which Yahoo mailbox you connected
- Scan recent messages when you use Fetch receipts, if Yahoo Mail API access is enabled for your account (subject, date, and preview metadata)
- Maintain your connection until you disconnect or delete your account
Yahoo does not offer a public API to create inbox filters automatically. After connecting, you may need to set up forwarding to your private SmartLedger inbound address manually in Yahoo Mail settings.
The same limitations apply: no ads, no resale of mailbox content, and no sending email from your account.
5. Do we store your emails?
We do not store a full copy of your Gmail, Outlook, or Yahoo mailbox.
- Mailbox scan: When you run Fetch receipts, we read recent messages over the API, process finance-related items in memory, and retain only extracted transaction fields and minimal identifiers (such as message ID, subject, and date) needed for deduplication and your ledger — not full message bodies.
- Forwarded receipts: When a receipt email is forwarded to your private inbound address, we process the message to extract receipt data. Attachments may be stored in our secure file storage as part of your receipt records, linked to your account.
- Uploaded files: Receipt images and PDFs you upload directly are stored in private storage associated with your account.
- OAuth tokens: Encrypted mailbox tokens are stored so you do not have to reconnect on every visit. Disconnecting a provider removes our ability to access your mailbox going forward.
6. Do we share data with third parties?
We do not sell your personal information. We share data only with service providers that help us operate SmartLedger, under contracts that require them to protect your data and use it only for our instructions:
- Supabase — authentication, database, and private file storage
- OpenAI / Anthropic — receipt parsing and insights (we send receipt content or relevant excerpts for processing; API providers do not use API submissions to train their models by default)
- Stripe — payment processing for subscriptions
- Google / Microsoft / Yahoo — only when you initiate OAuth; we exchange authorization codes and call their APIs on your behalf
- Email infrastructure — inbound receipt routing (for example Cloudflare Email Workers) that delivers forwarded messages to our processing endpoint
- Sentry (if enabled) — error monitoring with redacted diagnostics
We may also disclose information if required by law, to protect our rights, or in connection with a merger or acquisition with notice where legally permitted.
7. How to delete your data
You can remove your data in several ways:
Disconnect a mailbox
In Settings, use Disconnect next to Gmail, Outlook, or Yahoo. This revokes our stored OAuth tokens for that provider and stops further API access. Filters or forwarding rules already created in your mailbox may remain until you remove them in Gmail or Outlook.
Delete individual transactions or uploads
You can edit or remove ledger entries and receipt records from within the app where those features are available.
Delete your entire account
In Settings, scroll to Delete account, type DELETE, and confirm. This permanently deletes:
- Your profile and authentication account
- Transactions, jobs, and related database records
- Uploaded receipt files in our storage
- Email connection records and encrypted mailbox tokens
Account deletion cannot be undone. Billing subscriptions should be canceled separately if applicable.
8. Data retention and security
We retain your data while your account is active and as needed to provide the service, comply with law, or resolve disputes. Mailbox tokens are encrypted at rest. Access to production systems is restricted. No method of transmission or storage is 100% secure; we work to protect your data using industry-standard practices.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data. Account deletion in Settings fulfills most deletion requests. Contact us if you need additional assistance.
10. Children
SmartLedger is not directed at children under 16, and we do not knowingly collect their personal information.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Continued use after changes means you accept the updated policy.
12. Contact
Questions about this Privacy Policy or your data? Visit our Contact page or email gordenfl1@gmail.com.