Privacy Policy

Effective date: August 28, 2026 · Last updated: August 28, 2026

Ledger is a budgeting app. To budget, it needs to see your transactions, so it does, and so does the server it syncs to.

The rest of this page is the detail behind those statements.

Who we are

Ledger is made by TJ Taurisano, doing business as CanoSoftware. You can reach us at support@canosoftware.net.

What we collect, and why

Account and sign-in

Ledger uses Sign in with Apple. We receive an Apple-provided user identifier and, if you choose to share it, your name and email address. If you use Apple's Hide My Email, we only ever see the relay address. We use this solely to identify your account and to contact you about the service. We never receive your Apple ID password.

Your budget

Everything you create in Ledger: accounts, categories, budget assignments, transactions, payees, notes and memos, and, if you use them, shared household members. This is the product. It is stored on our servers so that it syncs between your iPhone, iPad, and Mac, and so that automatic transaction import can run when none of your devices are awake.

Bank and financial account data

Ledger can bring in transactions and balances three ways. You choose which, per account.

  1. Manual entry. You type it. Nothing leaves your devices except your own sync.
  2. Your own aggregator key (SimpleFIN). You create an account with SimpleFIN Bridge, pay them directly, and connect your banks on their site. You then give Ledger a token that lets it read the data you have chosen to share. Ledger never sees your bank username, password, or multi-factor codes; those go to the aggregator, not to us. See "Third parties" below, because this matters.
  3. Apple Wallet accounts (FinanceKit), on iPhone. If you grant permission, Ledger reads balance and transaction information for the Apple Card, Apple Cash, and Apple Savings accounts you specifically choose, for the time range you choose. Apple lets you change or revoke this at any time in Settings. Ledger then uploads that data to our servers so it appears on your other devices. See the FinanceKit section below for the commitments that apply to it.

In each case what we store is: the account name and balance, and for each transaction its date, amount, description, merchant name, merchant category code where provided, and whatever category and notes you or Ledger's categorization assign to it.

Diagnostics

Ledger does not collect crash reports, analytics, or usage telemetry. If that changes (for example, if we add Apple's own crash reporting), this section and the App Store privacy label will both be updated before the change ships.

What we do with it

That is the complete list. We do not use your financial data to market to you, to profile you, to train models that serve other users, or to build any product other than your own budget.

What we do not do

Please read this part: Ledger is not end-to-end encrypted

We want to be straightforward about this, because some privacy policies are written to obscure it.

Your data is encrypted in transit and encrypted at rest on our servers. But it is not encrypted in a way that prevents us from reading it. Our server categorizes your transactions automatically, and it cannot do that on data it cannot read.

What this means concretely:

If you need a budgeting tool where the provider genuinely cannot read your data, Ledger is not that tool, and we would rather tell you now.

Third parties, and what each one gets

We keep this list short on purpose. These are all of them.

WhoWhat they getWhy
AppleYour sign-in identity. On iPhone, FinanceKit data stays on your device until Ledger uploads it to us.Sign in with Apple; App Store distribution
SupabaseEverything in your budget. They host our database and authentication.This is where your data lives
SimpleFIN Bridge (only if you use it)Your bank credentials go to them, not us. They pass us the transaction and balance data you have authorized.Bank connections
MX (via SimpleFIN)SimpleFIN Bridge uses MX as its underlying bank-connection provider, so your bank data passes through MX's systems.Bank connections
CloudflareEncrypted database backups.Disaster recovery

About the aggregator chain, honestly. When you use a bring-your-own-key bank connection, your data passes through companies we do not control and whose security is not ours to guarantee. SimpleFIN Bridge publicly disclosed that on 28 May 2026, a defect at its upstream provider MX exposed some users' data to other users for approximately four hours, affecting up to 39 users. We mention this not because we think SimpleFIN handled it badly (publishing an incident of that size is better practice than most of the industry), but because you are entitled to know that a chain exists and that it has a history. Your contract for that service is with SimpleFIN, and their privacy policy and terms govern what they do with your data.

We do not use any advertising network, analytics provider, attribution SDK, or customer-data platform.

Apple Wallet data (FinanceKit)

If you choose to share Apple Card, Apple Cash, or Apple Savings data with Ledger, additional commitments apply to that data specifically, and they are commitments we make to you and to Apple:

Ledger reads this data on your iPhone with your explicit per-account consent and for the time range you approve. You can revoke that access at any time in iOS Settings. Revoking it stops future imports; transactions already imported remain in your budget until you delete them.

Household sharing

If you share a household with someone, they can see everything in that household's budget: accounts, balances, transactions, and categories, including ones you added. That is the point of a shared budget, but it is worth stating plainly before you invite someone. Removing a member stops their access going forward.

How long we keep it

We keep your data while your account exists. When you delete your account we delete your budget data from our live systems promptly, and it ages out of our encrypted backups within 12 months, after which it is gone.

Deleting your account

You can delete your account and all of its data from inside the app, without emailing anyone. Deletion removes your budget data and any stored aggregator token.

Two things deletion cannot do, so you know:

Before you delete, you can export your entire budget. We think you should own your data and be able to leave.

Security

No system is perfectly secure, and we are a small operation. We have said above what we cannot promise.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Ledger is built so that you can do the main ones yourself, at any time, without asking us: your data is visible in the app, editable in the app, exportable in full, and deletable in the app. For anything else, contact us at support@canosoftware.net and we will respond within the period required by applicable law.

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, so there is nothing to opt out of.

Children

Ledger is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

If we change how Ledger handles your data, we will update this page and change the "last updated" date. For changes that materially affect your privacy, we will tell you in the app before they take effect rather than relying on you to re-read this page.

Contact

support@canosoftware.net