Privacy Policy

Last updated: May 30, 2026

1. Introduction

LedgNity is a product of FindNity LLC, a Limited Liability Company registered in the State of Colorado, United States. ("we", "our", "us"). LedgNity is an AI-powered accounting platform designed for accounting firms. We are committed to protecting your privacy and the confidentiality of your financial data. This Privacy Policy explains how we collect, use, store, and protect your personal and financial information when you use our platform.

2. Data We Collect

We collect the following types of data:

Account Information:

  • Name, nickname, email address, phone number
  • Company name, role, date of birth, gender
  • Profile photo (stored in Firebase Cloud Storage, max 2MB)
  • Password (hashed with bcrypt, never stored in plain text)

Financial Data:

  • Invoices (incoming and outgoing), expenses, receipts
  • Bank account details (IBAN, SWIFT, balances) and transactions
  • Payroll records (employee salaries, tax deductions, insurance)
  • Tax records (VAT, sales tax, income tax filings)
  • Contracts, assets, and contact information (clients and vendors)
  • Chart of accounts, journal entries, and general ledger data
  • Audit trail logs (who changed what and when)
  • Financial reports (P&L, Balance Sheet, Cash Flow, Trial Balance, Aging)

Usage Data:

  • Login timestamps, device information (browser, OS)
  • Features used, pages visited
  • AI chat conversations and generated reports
  • Notification preferences and settings

3. How We Use Your Data

  • To provide core accounting services (invoicing, expenses, payroll, taxes, reports, chart of accounts, journal entries, audit trail)
  • To process financial documents using AI (categorization, OCR, anomaly detection)
  • To power the AI assistant (chat, smart recommendations, report generation)
  • To connect your bank accounts via Plaid (US/Canada) and TrueLayer (EU/UK)
  • To process payments and manage subscriptions via Stripe
  • To send notifications about deadlines, security alerts, and system updates
  • To authenticate your identity and secure your account (including 2FA)
  • To sync your email for invoice/receipt detection (Google Workspace, Microsoft 365)
  • To provide customer support
  • To improve the platform based on anonymous usage patterns

4. Data Storage

Hybrid storage model: We use a split approach to maximize security and minimize our data footprint.

  • We store: Metadata, extracted text, and structured data in Firebase Firestore. All data is encrypted at rest using AES-256 encryption.
  • You store: Original documents (PDFs, images, spreadsheets) remain in your own cloud storage — Google Drive, Dropbox, or OneDrive. We never store your original files on our servers.
  • Avatars and logos: Stored in Firebase Cloud Storage with size limits (avatars 2MB, logos 2MB, documents 20MB).

Data isolation is enforced at the database level — each user can only access their own data. Team members can access shared company data based on their assigned role (Owner, Senior, Accountant, Junior).

5. Third-Party Services

We share data only with trusted third-party services necessary to operate the platform:

  • Firebase (Google): Authentication, database, cloud storage, cloud functions
  • Stripe: Payment processing and subscription management. We do not store your credit card information — Stripe handles all payment data.
  • Plaid: Bank account connections for users in the US and Canada. Plaid accesses your bank data directly with your authorization.
  • TrueLayer: Bank account connections for users in Europe and the UK.
  • Google Workspace: Gmail scanning for invoices/receipts, Google Drive for document storage, Google Calendar for deadlines (only when you connect your account)
  • Microsoft 365: Outlook email and OneDrive integration (only when you connect your account)
  • Dropbox: Document storage backup (only when you connect your account)
  • Google AI (Gemini): AI-powered document processing, chat assistant, and report generation. Financial data sent to AI is processed in real-time and not stored by Google for training purposes.

We do not sell your data to any third party. We do not share your data with advertisers.

6. Cookies

We use cookies in four categories:

  • Essential: Authentication, session security, 2FA verification. Always active.
  • Functional: Theme preferences, language, dashboard layout, timezone, currency format.
  • AI & Smart Features: AI assistant context, transaction categorization preferences.
  • Analytics: Anonymous usage statistics to improve platform performance.

Cookie consent is stored in your browser (localStorage + cookie, 365 days) and synced to your account when logged in. You can manage your preferences at any time through the cookie settings. For full details, see our Cookie Policy.

7. GDPR Compliance

If you are located in the European Union or the United Kingdom, you have the following rights:

  • Right of access: Request a copy of all data we hold about you
  • Right to rectification: Correct any inaccurate data
  • Right to erasure: Request deletion of your account and all associated data
  • Right to data portability: Export your data in standard formats (PDF, CSV, Excel)
  • Right to object: Opt out of non-essential data processing
  • Right to restrict processing: Limit how we use your data

To exercise any of these rights, contact us at support@ledgnity.com. We will respond within 30 days.

8. Data Retention

  • Active account: Data is retained for as long as your account is active.
  • Deleted items: Moved to Trash and permanently deleted after 30 days.
  • Account deletion: All data is permanently deleted within 30 days of account deletion, unless required by law.
  • AI chat history: Stored per session and can be deleted by the user at any time.
  • Cookie consent: Stored for 365 days.

9. Team Access

If you invite team members to your account, they will have access to shared company data based on their role:

  • Owner: Full access to all data and settings
  • Senior: Access to all company data and team management
  • Accountant: Access to financial data within assigned companies
  • Junior: Limited access to assigned tasks

You are responsible for managing team member access and ensuring they comply with your organization's data policies.

10. Security

  • HTTPS with TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Firebase Authentication with email/password and Google OAuth
  • Two-Factor Authentication (2FA) via authenticator apps with backup codes
  • Login alerts with device tracking (browser and OS)
  • Database-level data isolation (Firestore security rules)
  • File upload size limits and type validation
  • OAuth token encryption for third-party integrations

11. Children's Privacy

LedgNity is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. The "Last updated" date at the top of this page indicates when the policy was last revised.

13. Contact

If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:

FindNity LLC

7761 Salt Fork Dr, Colorado Springs, CO 80908, United States

Email: support@ledgnity.com

Terms of ServiceCookie PolicyHelp & Support