← Back to Ledger

Privacy Policy

Last updated: June 2026

1. The short version

Ledger stores the email and password you sign up with, the trades and theses you log, who you follow, and the comments and likes you make. We don't sell your data, we don't serve you ads, and we don't share your private trades with anyone. Public trades are visible to other signed-in users by design.

2. What we collect

Account info: email address, hashed password, username, display name, bio.
Trades: ticker, entry price, target, stop, horizon, thesis, exit reasoning, and the resolution outcome.
Social: who you follow, who follows you, likes and comments you make on public trades.
Usage: standard server logs (IP address, browser type, timestamps) for debugging and security. We don't use third-party analytics or ad tracking.

3. What we don't collect

We don't access your brokerage accounts, your bank accounts, or your real trading positions unless and until you explicitly connect them. We have no plans to sell your data or share it with advertisers.

4. How we use it

To run the service: show you your trades, calculate your stats, surface other users you follow, deliver notifications. To improve the service: debug issues, monitor performance. That's it.

5. Who sees what

Private trades (the default): only you. Database row-level security enforces this — even our admin tooling can't casually browse private content.
Public trades: any signed-in Ledger user can see them. Comments and likes on public trades are also public.
Profile info (username, display name, bio, follower counts): visible to any signed-in user.
Email + password: only you. Never displayed anywhere on the site.

6. Third parties

We use Supabase to host the database and handle authentication, Vercel to host the app, and Yahoo Finance to fetch price data for tickers you've logged. Each has their own privacy policy. We do not send your data to ad networks or analytics services.

7. Your rights

You can edit your profile at any time on the Settings page, delete trades from the trade detail page, and delete your account entirely by emailing us at the address below. We'll wipe your data within 30 days of an account-delete request.

8. Security

Passwords are hashed, traffic is HTTPS, and database access is scoped by row-level security policies. We're a small project without a dedicated security team yet, though — don't put anything in your thesis you wouldn't want a determined attacker to see.

9. Children

Ledger is not directed at anyone under 18. If you believe a child has created an account, please contact us and we'll remove it.

10. Changes

We may update this policy. Material changes will be announced in-app. Continuing to use Ledger after a change means you accept the updated policy.

11. Contact

Privacy questions? Email getledger.app@gmail.com.