LedgeRR← Back

Privacy Policy

Last updated 11 August 2026

LedgeRR holds your trading records, which are personal and financial. This page says exactly what is collected, where it is kept, and who else can see any part of it. It describes what the software actually does — not what would be convenient to claim.

Who is responsible

LedgeRR is operated from India by the individual who runs this service. Under the Digital Personal Data Protection Act, 2023, they are the Data Fiduciary for the personal data described below. Questions and grievances go to contact@ledgerr.app.

What is collected

Your account

Your email address. If you sign in with Google, Google also gives us the name and profile picture on your Google account. We never see or store your Google password. If you set a password with us, it is stored only as a one-way hash by our authentication provider — nobody at LedgeRR, or anywhere else, can read it back.

What you put in the journal

Everything you enter: trades, entry and exit prices, quantities, stop losses, dates, brokerage and charge settings, your account size and risk preferences, diary entries, the emotions you tag them with, capital added or withdrawn, and any chart images or chart links you attach.

Technical records

Our hosting and database providers keep server logs that include your IP address, browser type and the pages requested, for security and diagnostics. If page analytics are enabled, they record anonymous page views, plus a small number of named events — that a sign-up form was opened, that someone signed in, that setup was finished — so we can tell how many people who arrive end up with a working journal. These carry a count and nothing else: no email address, no name, and nothing you typed into a form. They do not use cookies, do not fingerprint your device, and cannot identify you.

If the app crashes while you are signed in, we record the error message, the page it happened on and the technical stack trace, so it can be fixed. That record is tied to your account and is kept in our own database. It never includes what you had typed or any part of your journal.

Your sign-in session is stored in your own browser’s local storage. It is not a tracking cookie and is not sent to anyone else.

Why it is collected

  • To give you an account and keep you signed in.
  • To store and show your journal — this is the service itself.
  • To compute your statistics. This happens in your browser or on our server, never by sending your data elsewhere.
  • To keep the service working and secure, and to count how many people use it.

Your trading data is never sold, rented, shared with advertisers, used to train any model, or used to build a profile of you.

Who else can see any of it

We use a small number of service providers. Each one is listed here with what it actually receives.

  • Supabase — the database, authentication and file storage. It holds all of your account and journal data.
  • Vercel — hosting. It sees the requests your browser makes, including your IP address.
  • Yahoo Finance — where current market prices come from. Only the stock symbols are sent, and they are requested by our server, not your browser, so your IP address is not disclosed to them.
  • TradingView — if you attach a TradingView chart snapshot, the image is loaded by your browser directly from TradingView’s servers. TradingView can therefore see your IP address and which chart you are viewing. Nothing else about your journal is sent to them. If you would rather not have this, do not attach chart links.
  • Google — only if you choose to sign in with Google, and only to authenticate you.
  • Our analytics provider, if enabled — anonymous page view counts, with no cookies and no personal data.

We will also disclose data if we are legally required to. Nothing else.

Where it is stored, and for how long

Data is held on our providers’ infrastructure. It stays for as long as your account exists. If you delete your account, your journal data is deleted with it. Provider backups and server logs may retain copies for a short period afterwards, in line with those providers’ own retention schedules.

How it is protected

  • All traffic uses HTTPS.
  • Every table enforces row-level security, so a signed-in user’s queries can only ever return their own rows. This is enforced by the database, not by the app.
  • Uploaded chart images live in a private bucket and are served through short-lived signed links.
  • Passwords are stored only as hashes.

No system is perfectly secure, and we do not claim otherwise. If we ever become aware of a breach affecting your data, we will tell you and the Data Protection Board of India as the law requires.

Your rights

Under the Digital Personal Data Protection Act, 2023, you may:

  • ask what personal data we hold about you and how it is processed;
  • have inaccurate data corrected — most of it you can edit yourself, at any time;
  • have your data erased, by deleting your account;
  • nominate someone to exercise these rights if you die or become incapacitated;
  • raise a grievance with us, and afterwards with the Data Protection Board of India.

You can export your journal at any time. We would rather you were able to leave with your data than feel stuck with us.

Raising a grievance

If something here has not been honoured — an export that never arrived, data you asked to have deleted and can still see, a question about processing that went unanswered — say so and it will be dealt with.

Grievances are handled by Bavya J R, at contact@ledgerr.app. You will get a reply within 30 days. Please say which email address your account uses, so it can be found.

If you are not satisfied with the answer, or do not get one, you can complain to the Data Protection Board of India. You do not need our permission to do that, and nothing here asks you to come to us first.

Children

This service is not intended for anyone under 18, and we do not knowingly create accounts for children. If you believe a child has an account here, write to contact@ledgerr.app and it will be removed.

Changes

If this policy changes in a way that affects you, the date at the top changes and we will say so in the app. Continuing to use LedgeRR after that means you accept the revised policy.