Security

What Ledgerline does to keep your financial records private, and, just as plainly, what it does not do.

Encryption at rest, one key per workspace

  • Every record you keep (entries, accounts, categories, budgets, goals, loans, notes, the advisor's readings) is encrypted with AES-256-GCM before it is written to the database. The database only ever holds ciphertext.
  • Each workspace has its own random 256-bit data key. That key is stored only in wrapped (encrypted) form, under a key-encryption key derived from a master key that lives in the server's configuration, never in the database. A copy of the database alone opens nothing.
  • Every record is bound to its workspace, its kind and its id. A record copied into another workspace, or moved to another place, fails to decrypt instead of showing up somewhere it does not belong.
  • The few lookups the server has to make without decrypting (recognising a duplicate import, keeping account names unique) use keyed fingerprints, made with a separate key for each workspace.

What this is not

This is not end-to-end encryption. The server holds the keys and decrypts your records to show them to you, to build your reports and downloads, and to answer the advisor when you have turned it on. Someone who took over the running server could read the workspaces it serves. We chose this so that password reset, Google sign-in and the advisor work; a design where only your password could unlock your data would lose all three, and a forgotten password would lose your data.

Signing in

  • Email and password (at least 10 characters, stored only as a slow, salted hash), with your email address confirmed first, or Google. A Google account is only joined to an existing account when Google has confirmed the same address.
  • A six-digit PIN on every sign-in, on every device. Nothing in the app opens until it is entered. Five wrong PINs end that session; ten in an hour lock PIN entry everywhere and email you.
  • Sign-ins, failed sign-ins, PIN and password changes, downloads and billing changes are recorded in your account's security activity. A sign-in from a browser your account has not used before emails you.
  • You can see every device that is signed in, and sign out any of them, or all of them, from your account page.
  • Sign-in, PIN entry, and every change you make are rate-limited per person and per address.

Deleting your account

You can delete your account from the account page, after typing your email address and your PIN. Nothing is removed for 7 days, in case it was not you or you change your mind. Then your workspace's key is destroyed first, which makes every record unreadable at once, and the records and your account are deleted. Encrypted backups age out within [N] days and cannot be read without the destroyed key.

You can download everything you have stored, as JSON or as spreadsheets, at any time and on every plan.

The AI advisor

  • It is off until you turn it on, and the screen that asks says what it sends and to whom.
  • When you ask a question, it sends what the answer needs: the question, recent turns of the conversation, an outline of your account and category names and this month's totals, and the entries it looks up. It never sends your email address, password, PIN or notes.
  • It goes through OpenRouter to Claude Haiku 4.5, then GPT-5.6 Luna, and only to endpoints that keep nothing and do not train on it (zero data retention). If no such endpoint is available, the question fails rather than going elsewhere.
  • Each plan has a monthly allowance (20 messages on Free, 500 on Pro), and you can turn the advisor off at any time.

Everything else

  • Imported files are read in memory to build the preview and never stored.
  • Payments go to Paddle, our merchant of record. Your card details never reach us; we keep only which plan you are on and Paddle's reference for your subscription.
  • No analytics, advertising or tracking scripts. The only third-party script anywhere in the app is Paddle's checkout, on the account page, when you choose to pay.
  • Logs never contain decrypted financial data, passwords, PINs or keys. Addresses in the security log are kept as a keyed fingerprint, not in full.
  • Strict security headers on every page: a content security policy, no framing, HTTPS only.

Reporting a problem

If you find a security issue, please write to [SUPPORT EMAIL] before telling anyone else, and we will answer quickly. See also our privacy policy.