Privacy statement
Last updated 11 August 2026
Ledger holds bank statements, which are among the most sensitive personal data there is. This page says exactly what is stored, where it lives, who else sees it, and how to have it removed. It is written to be read rather than to be defensible.
Who we are
Ledger is run by Andrew Bannister, a sole trader based in Ireland, trading as slvnt Ledger. The data controller for your personal data — the person legally answerable for it — is therefore an individual rather than a company.
For anything about your data, including access and deletion requests, write to slvnt.ledger@outlook.com.
What this covers
This statement applies to three places:
- slvnt.cloud — this site.
- app.slvnt.cloud — the Ledger application.
- auth.slvnt.cloud — sign-in, registration and account recovery.
What we collect
This site
This page sets no cookies and uses no browser storage. It loads nothing from any third party — every script, style and font comes from our own servers. See the cookie policy.
We measure how the site is used with analytics we run ourselves (Umami), on the same infrastructure as everything else. For each page view it records the page, the referring site, your browser and device class, your country, and a visitor identifier that is a salted hash of your IP address and browser — the salt changes every day, so the identifier cannot be reversed and cannot connect one day's visit to the next. Your raw IP address is not stored, nothing is placed in your browser, and none of it is shared with anyone.
If you join the waitlist we store the email address you give us and the date you gave it. It is used to tell you when accounts open, and for nothing else.
Your account
- Email address, and whether it has been confirmed.
- Display name, if you set one.
- A password hash — never the password itself. Hashing is Argon2id or bcrypt, and the original is not recoverable by us or by anyone else.
- Sign-in security records: failed attempt counts and lockout state, so an account cannot be guessed into.
- If you use Sign in with Google, a link to that Google account and the email address it carried when you linked it. We never receive your Google password.
- Your subscription tier and its period.
Your financial data
- Accounts you create: a name, the institution, the type, the currency and an opening balance.
- Transactions: dates, amounts, direction, the description exactly as your bank wrote it, a cleaned-up version of it, the category, and a reference back to the statement line it came from.
- The statement files you upload, kept in full so a parsing fix can be re-applied and so you can check any figure against the original.
- Details read out of a transaction description, which can include a counterparty's name, a direct debit mandate reference, or the last four digits of a card used to top up an account. We name this specifically because it can contain another person's details and a fragment of a card number.
- Your budgets, recurring bills, savings goals, projections and credit card repayment settings.
Technical records
Our web server keeps short-lived request logs — IP address, timestamp, the path requested, the response code and the browser's user agent — to keep the service running and to investigate abuse. The self-hosted analytics described above keeps its aggregate page-view statistics alongside them, on the same servers. Application logs deliberately contain none of your financial detail; see below.
Where it is held
On servers run by OVH Hosting Limited, in France. Your data is not transferred outside the EEA except as set out in the processors table below.
Your personal details live in exactly one database. Every other part of the platform knows you only by an opaque identifier, and stores no name, no email address and no profile information at all. This is deliberate, and it is what makes a deletion request something that can be carried out completely rather than approximately.
How it is protected
- Uploaded statements are encrypted at rest with AES-256-GCM, with a separate initialisation vector for every file.
- All traffic is over TLS. There is no unencrypted route into the service.
- Statement content is never written to a log. Transaction descriptions, amounts, account numbers, IBANs and cardholder names are prohibited from every log line and every error message in the platform. Logs record identifiers, counts and statuses.
- Every access to an original statement file is recorded. We should be straight about the current limit: this is written to the application log rather than to a separate tamper-resistant audit store, and those logs rotate.
- Database backups are taken regularly and kept for a limited period, on the same basis as the live data.
Why we are allowed to hold it
| Data | Lawful basis (GDPR Article 6) |
|---|---|
| Your account and financial data | Performance of a contract — it is the service you asked for |
| Waitlist email address | Consent, which you can withdraw at any time by asking us to delete it |
| Sign-in security and abuse records | Legitimate interests — keeping accounts from being broken into |
| Server request logs | Legitimate interests — running and defending the service |
| Self-hosted analytics (aggregate page-view statistics) | Legitimate interests — understanding how the site and application are used. No profile is built, no data leaves our servers, and nothing identifies you across days |
Who else sees it
We do not sell your data, we do not share it for advertising, and we do not use it to train anything that leaves our servers. The full list of third parties involved:
| Who | What they get | Why |
|---|---|---|
| OVH Hosting Limited | Everything, as the operator of the servers | Hosting, France |
| Mailgun (Sinch) | Your email address and the message text | Sending confirmation and password reset emails |
| Only if you choose Sign in with Google: the fact that you signed in, plus your address and name from them | Federated sign-in | |
| Let's Encrypt | No personal data — certificate requests only | TLS certificates |
There is no third-party analytics provider, no advertising network, no error-reporting service and no third-party script anywhere in the platform. The only analytics is Umami, open-source software we run ourselves on the servers already listed above — it appears nowhere in this table because no data goes to anyone by way of it.
Automatic categorisation
Ledger suggests a category for a transaction using a small statistical model. That model is trained and runs on the same servers that hold your data. Nothing is sent to an external AI provider, no large language model is involved, and your transactions are not used to train a model shared with anyone else. Suggestions are suggestions — a category is not applied until you accept it.
Payments
Billing is not live. When it is, checkout will be hosted entirely by the payment provider, and we will never receive or store a card number or anything derived from one.
How long we keep it
- Your account data, for as long as you have an account. If your subscription lapses, nothing is deleted and nothing is hidden — everything stays readable. We do not reclaim data from inactive accounts.
- Uploaded statement files, until you delete them. Deleting a document removes the file and reverses the transactions it created.
- Waitlist addresses, until accounts open or you ask us to remove yours.
- Server request logs, for a short period, then discarded on rotation.
- Backups age out on their own retention schedule, so deleted data can persist in a backup for a short window after it is gone from the live service.
Your rights
Under the GDPR you can ask us to:
- Give you a copy of what we hold about you.
- Correct anything that is wrong.
- Delete your account and everything in it. This is built in rather than manual: deletion removes your statements, transactions, budgets, projections and your account record. We should be clear that today this is done by contacting us rather than by a button in the application.
- Export your data in a machine-readable form.
- Object to or restrict a particular use.
Write to slvnt.ledger@outlook.com. We will respond within one month.
If you are not satisfied you can complain to your national data protection authority. In Ireland that is the Data Protection Commission, dataprotection.ie.
Children
Ledger is not intended for anyone under 16, and we do not knowingly hold data about anyone under 16.
Changes
If this statement changes in a way that affects you, we will tell account holders by email before it takes effect. The date at the top always reflects the current version.