Privacy Policy
LedgerSmith AI LLC · Effective 26 July 2026 · Last updated 26 July 2026
The short version. We never ask for your online banking credentials — we work from statements you upload, never from a live bank connection. We do not sell your information. We do not use your financial data to train AI models. Your books and deliverables belong to you.
1. Who we are and what this covers
LedgerSmith AI LLC (“LedgerSmith,” “we,” “us”) provides bookkeeping services. We reconstruct and reconcile business books from bank statements and issue a numbered Tie-Out Certificate when the books tie exactly to the financial institution’s own printed record.
This policy explains what we collect, how we use it, who we share it with, how long we keep it, and the choices available to you. It applies to our website, our client and firm portals, and our bookkeeping services.
We do not provide tax advice, tax preparation, audit, attest, or accounting services. Those remain with your own tax professional.
2. Information we collect
From businesses and their representatives
- Financial documents you upload — bank and credit-card statements (PDF, scan, photo, or CSV), including closed accounts and historical periods.
- Transaction data extracted from those documents — dates, amounts, descriptions, balances, and the categorizations applied to them.
- Business information — legal and trade names, entity type, fiscal periods, chart-of-accounts preferences.
- Contact information — name, business name, email address, phone number, mailing address.
- Your answers to our questions — where a transaction is ambiguous we ask, and your replies are recorded verbatim as part of the work papers, because they are the evidence supporting how the item was treated.
- Account and portal data — login identifiers, agreement acceptances (including version, timestamp, and a cryptographic hash of the version accepted), and activity logs.
From partner firms
The above, submitted on behalf of the firm’s own end clients, plus firm account and billing details.
Automatically
Standard server and security logs (IP address, timestamps, user agent), used for security, abuse prevention, and diagnostics.
Payments
Processed by Stripe. We never receive, hold, or store your full payment card number.
3. What we do not collect
- We never ask for, collect, or hold your online banking credentials. We work from statements — the printed record — not from live bank connections. If we ever introduce an optional bank connection, this policy will be updated before that feature exists.
- We do not sell personal information.
- We do not use client financial data to train artificial-intelligence models, and our agreements with providers prohibit them from doing so.
4. How we use information
- To perform the bookkeeping services you engaged us for — extraction, categorization, reconciliation, work papers, financial statements, and certificate issuance.
- To ask clarifying questions and record your answers as part of the engagement record.
- To operate the client and firm portals, including access control and agreement gating.
- To bill and collect payment, and to maintain commission records for the representative who introduced you.
- To secure our systems, detect and prevent fraud or abuse, and maintain audit logs.
- To meet legal, tax, and recordkeeping obligations.
- De-identified, aggregated analytics only — data stripped of identifiers may be used in aggregate for product improvement and benchmarking. This never involves selling or disclosing your information, and never identifies you or your business.
5. Automated processing and human review
We use software — including third-party artificial-intelligence services — to read documents and propose transaction categorizations. Two safeguards apply:
- Identifier scrubbing before transmission — account numbers, government identification patterns, and long digit sequences are removed before any transaction text is sent to an external processing service.
- A mechanical accuracy gate — no deliverable is issued unless beginning balance plus activity equals ending balance exactly, per account and per period. Items that cannot be resolved become questions routed to you, never assumptions.
No decision producing legal or similarly significant effects about an individual is made by automated processing alone.
6. Who we share information with
We share information only with service providers who are bound by contract to protect it:
| Provider | Function | Data touched |
|---|---|---|
| Anthropic | Document extraction and transaction categorization | Identifier-scrubbed transaction text; not used for model training |
| Base44 | Client, firm, and representative portal platform | Account records, engagement metadata, uploaded documents |
| Cloudflare | Website hosting, DNS, encrypted deliverable storage | Uploaded documents and deliverables at rest; site traffic |
| Stripe | Payment processing | Billing contact and payment data (card data held by Stripe, not by us) |
| Google Workspace | Business email | Correspondence |
| Resend | Transactional email delivery | Email address and message contents |
| Telegram (optional, where elected) | Clarifying questions only | Masked transaction descriptions; never account numbers, balances, or attachments |
We also share with professional advisors under confidentiality, with a successor in a merger or asset transfer (subject to this policy), and with government or legal authorities where required by law or to protect rights and safety.
Where a partner firm engages us on behalf of its own client, we act as that firm’s service provider and handle the data under the firm’s instructions and agreement.
7. Public certificate verification
Each engagement ends in a certificate bearing a serial number and a separate verification code. Anyone holding both can confirm validity on our public verification page.
The verification page is anonymous by design. It returns validity, issue date, period covered, current status, and a cryptographic fingerprint of the sealed file. It never displays your name, your business name, or any financial figure. A serial number alone returns nothing.
8. How we protect information
We maintain a written information security program designed to the FTC Safeguards Rule (16 CFR Part 314), including encryption of client data in transit and at rest, multi-factor authentication on systems that can access client information, least-privilege access controls, audit logging, secure disposal, vendor oversight, security training, and a written incident response plan.
Documents move through our secure portal upload — never by email. Sales representatives have no access to client documents or client financial data at any time.
9. How long we keep information
| Data | Retention |
|---|---|
| Work papers, general ledger, certificates, tie-out records | 7 years from deliverable date |
| Source statements you provided | Duration of engagement plus 7 years, unless you request earlier return or deletion where law permits |
| Your recorded answers | With the work-paper file to which they belong |
| Prospect and contact records | 3 years from last contact |
| Certificate registry (serial, scope, hashes — no financial content) | Retained permanently; it is what allows certificates to stay verifiable |
Disposal is by return, certified destruction, or cryptographic erasure.
10. Your rights and choices
Depending on where you live, you may have the right to request access to the personal information we hold about you, request correction, request deletion, request a portable copy, and be free from discrimination for exercising these rights. California residents have specific rights under the CCPA/CPRA, including the right to know what categories are collected and disclosed. We do not sell or share personal information for cross-context behavioral advertising.
Two limits, stated plainly: records we must retain to meet legal, tax, or professional recordkeeping obligations cannot always be deleted on request; and where a partner firm engaged us on behalf of its client, requests should be directed to that firm, whose instructions govern.
To exercise a right, contact billing@ledgersmith.ai. We will verify your identity before acting.
11. Children
Our services are for businesses. We do not knowingly collect personal information from children under 13, or the applicable age in your jurisdiction.
12. Where information is processed
Our services are directed to businesses in the United States and its territories, and information is processed in the United States.
13. Changes to this policy
We will post any changes here with a revised “last updated” date, and will provide additional notice where required by law.
14. Contact
LedgerSmith AI LLC
1654 Calle Tulipán, Suite 100
San Juan, PR 00921
Privacy questions: billing@ledgersmith.ai
Security matters: security@ledgersmith.ai
LedgerSmith AI LLC provides bookkeeping services only. We do not provide tax preparation, audit, review, compilation, or attest services. Your relationship with your own tax professional is unaffected.