Privacy Policy
Last updated 21 July 2026
Ledger is a private, invite-only app for keeping track of informal debts between people who already know each other. It is operated as a sole proprietorship in Ohio, United States ("Ledger", "we", "us"). This policy explains what we collect, why, and what we will never do with it.
We have tried to keep this short and specific rather than long and vague. If anything here is unclear, email developer@l3dger.xyz.
Information we collect
Information you give us
- Mobile phone number. Used to create your account, to send you a one-time verification code, and to sign you in.
- Your name. Shown to other people in your group so they can identify you.
- Password. Stored only as a salted PBKDF2 hash. We never store, and cannot recover, your actual password.
- Profile photo. Optional. If you add one it is resized on your device and stored on our server.
- Ledger entries. The debts and payments you record: the amount, the other person, an optional note, and the time.
Information we generate
- A short user ID so people can find you unambiguously.
- Invite records linking the code you used to the person who issued it.
- Session tokens so you stay signed in.
Ledger does not collect location data, contacts, advertising identifiers, or browsing activity. There is no analytics or tracking SDK in the app.
How we use it
- To create and secure your account, and to verify that a phone number belongs to the person registering it.
- To show you and your counterparties an accurate record of what is owed.
- To let people in your group find you by name or user ID.
- To prevent abuse — for example, enforcing that invite codes are used only once.
We do not use your information for advertising, profiling, or automated decision-making, and we do not sell it.
SMS and mobile information
We send SMS messages only to deliver one-time verification codes when you create an account or sign in. These are transactional messages. We do not send marketing or promotional text messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as our SMS delivery provider, is permitted solely to deliver the messages you request. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Message and data rates may apply. Message frequency varies and depends on how often you sign in. Reply STOP to opt out of messages or HELP for help. See our Terms & Conditions for full messaging terms.
Who your information is shared with
We share information in only three situations:
- With people in your group. Your name, user ID and optional photo are visible to other members. A ledger entry is visible to the two people it is between. Because the app cancels out circular debts across the group, the resulting balance can be affected by entries between other members — but the details of those entries are never shown to you.
- With service providers who operate the app on our behalf: Cloudflare (hosting and database) and our SMS provider (delivering verification codes). They may process your information only to provide that service.
- When legally required, such as a valid court order.
We do not sell, rent, or trade personal information to anyone.
How long we keep it
Account information is kept while your account exists. Ledger entries are kept as long as the account exists, because balances are recalculated from the full history and deleting an entry would silently change what someone else is owed. Verification codes are discarded once used or after ten minutes, whichever comes first.
If you ask us to delete your account, we remove your name, phone number, password and photo. Entries between you and other people are retained in an anonymised form, because they form part of another person's financial record.
Security
Traffic between the app and our servers is encrypted with HTTPS. Passwords are stored only as salted PBKDF2 hashes. Verification codes are stored hashed, expire after ten minutes, and lock after repeated wrong attempts. Access to the production database is restricted to the operator.
No system is perfectly secure. Please use a password you do not use elsewhere.
Your choices
- Access or correct your information — email us.
- Delete your account — see how to delete your account, which sets out exactly what is removed and what is kept.
- Stop SMS — reply STOP to any message. Note that verification codes are how you sign in, so opting out may prevent you from accessing your account.
- Remove your photo — at any time, in the app.
Children
Ledger is not intended for anyone under 13, and we do not knowingly collect information from children under 13. If you believe a child has created an account, contact us and we will remove it.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how we handle your information, notify you in the app.