Privacy Policy

Last updated: September 21, 2026

Nth Ledger is built to help you track your expenses, not to track you. This policy explains what data we collect, why we collect it, and how we protect it. We keep it plain and honest.

Information We Collect

  • Email address: collected when you sign in with Apple or via a magic link. An account is required to use Nth Ledger.
  • Receipt images: photos you take or select. If you turn on AI scanning, they are sent to our AI providers (the Gemini API from Google, and the OpenAI API) so the details can be read; see AI Scanning below. Images are stored in your Nth Ledger account (Cloudflare R2) on every plan.
  • Expense data: merchant or income source name, amount, currency, date, category, notes, the card used (brand, issuer, and last four digits), and the store's location (area, city, region, and country), whether you enter them or AI reads them from a receipt.
  • Other records you keep in the app: accounts and cards (name, type, credit limit and statement day), loans (name, lender and balances), budgets, categories, and mileage trips (date, distance, rate, purpose, odometer readings and vehicle details).
  • Name: your name and, on the Business plan, your business name, if you add them in Settings. They are printed on the reports you create.
  • Forwarded receipts: if you forward a receipt to your Nth Ledger email address, we read that email to add the receipt. Until the receipt is added, we keep its attachments and subject line so the app can show what is waiting, and we delete them after 30 days if it never is. We also keep the email's message ID for 7 days so the same receipt isn't added twice.
  • Device push token: registered when you sign in, so we can tell your other devices to sync and let you know when a forwarded receipt has been added or couldn't be read.
  • Profile photo: if you choose to upload one from Settings.
  • Diagnostic data: when the app or our backend hits a crash or an error, a diagnostic report is sent to our error-monitoring provider (Sentry) so we can find and fix it. These reports carry the error itself plus technical context such as your device model, OS version, and app version. They are tagged with your account's internal ID only: no email address, no receipt images, no expense data, and no screenshots.

How We Use Your Information

  • To provide and operate the Nth Ledger service: scanning receipts, organising expenses, and syncing data across your devices.
  • If you turn on AI scanning, to send receipt images and forwarded receipts to our AI providers (the Gemini API from Google, and the OpenAI API) so the details can be read. They are sent solely for this purpose.
  • To sync your data securely across your devices.
  • To send transactional emails (e.g. sign-in magic links). We do not send marketing emails.
  • To diagnose crashes and errors so we can keep the app working. We use diagnostic reports only to fix problems, never to build a profile of you or to track your behaviour.
  • We do not sell, rent, or share your personal data with third parties for advertising.

AI Scanning

  • AI scanning is off until you turn it on. We ask during setup, and you can turn it on or off at any time in Settings > AI Scanning. While it is off, nothing is sent to an AI provider: you add expenses by hand, and receipts you forward by email are not read.
  • When it is on, a receipt you scan, or one you forward by email, is sent to the Gemini API (from Google) or the OpenAI API so the details can be read. We use their paid services, under which your receipts are not used to train or improve their models.
  • These providers may keep a copy for a limited time to detect abuse and keep their services secure: Google for a limited period, and OpenAI for up to 30 days. They may process it in countries other than your own. Their handling of your data is governed by their own terms, linked under Third-Party Services.
  • Turning AI scanning off takes effect immediately and stops anything further being sent. Receipts already read stay in your account until you delete them or your account.

Third-Party Services

  • Google (Gemini API): if AI scanning is on, receipt images and text are sent to the Gemini API, a paid service, so the details can be read. Google's privacy policy applies: policies.google.com/privacy
  • OpenAI (OpenAI API): if AI scanning is on, receipt images and text are sent to the OpenAI API, a paid service, so the details can be read. OpenAI's privacy policy applies: openai.com/privacy
  • RevenueCat: handles subscription management and purchase verification. RevenueCat's privacy policy applies: revenuecat.com/privacy
  • Cloudflare: our infrastructure provider for compute, database, and file storage. Cloudflare's privacy policy applies: cloudflare.com/privacypolicy
  • Resend: used to deliver magic-link sign-in emails. Resend's privacy policy applies: resend.com/legal/privacy-policy
  • Sentry: receives crash and error reports from the app and our backend, tagged with your internal account ID only, as described above. Sentry's privacy policy applies: sentry.io/privacy
  • We share personal data only with the providers above, only as much as each needs to provide its service to us, and only with providers that give your data the same or equal protection described in this policy.

Data Storage and Security

Your expense data and receipt images are stored in Cloudflare's global infrastructure with encryption in transit (TLS) and at rest. Access tokens are short-lived and refresh tokens are stored as hashed values. We follow industry-standard security practices, but no transmission over the internet is 100% secure.

Data Retention

We retain your data as long as your account is active. You can permanently delete your account and all associated data at any time from Settings in the app; deletion is immediate, with any residual copies purged within 30 days. After deletion we keep a minimal record only as long as needed to meet legal, tax, and billing or dispute-resolution obligations: a one-way hash of your email plus your subscription identifiers, and no receipts, images, or other content. We also retain anonymized, aggregate scan-usage statistics that are no longer linked to you. Any diagnostic reports already sent to Sentry age out on their own retention schedule rather than being erased by account deletion, though because they carry only your internal account ID, deleting your account removes the record that maps that ID back to you; email us at hi@nthledger.com if you want them removed sooner. Data stored locally on your device is removed when you uninstall the app.

Children's Privacy

Nth Ledger is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

Your Rights

  • Access: you can request a copy of your personal data at any time.
  • Deletion: you can request deletion of your account and all associated data.
  • Correction: you can update your email or profile information through the app.
  • Withdrawing consent to AI scanning: turn it off at any time in Settings > AI Scanning. It takes effect immediately.
  • Portability: Settings > Export Data downloads a machine-readable archive of everything in your account, receipt images included, over any date range you choose. It is available on every plan, including the free one. Formatted PDF and CSV reports are a paid feature, but your right to a copy of your own data is not.
  • To exercise any of these rights, email us at hi@nthledger.com.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the 'Last updated' date above. Continued use of the app after changes constitutes acceptance of the revised policy.

Questions? Email us at hi@nthledger.com