Legal

Privacy Policy

Last updated: 2026-08-29

This Privacy Policy explains how LedgerPanda (the "Extension", "we", or "us") collects, uses, and protects your information. We follow a privacy-first principle: your bank statements and financial data are processed locally and, by default, are never uploaded to any server.

1. Who we are

LedgerPanda is a local-first Chrome extension for people who keep their own books. It parses bank statement PDFs inside your browser, normalises merchant names using an on-device model, reconciles the parsed rows against the totals your bank printed, and exports CSV. Parsing, cleaning, reconciliation, categorisation and storage all run on your device. The operator is LedgerPanda (a trade name of the individual developer behind this Extension), and our website / domain is https://ledgerpanda.com.

2. Information we collect

We collect the minimum information necessary to provide the service. In practice, that is one category:

No analytics, no telemetry: the Extension ships no usage-analytics, telemetry or crash-reporting SDK, and it does not report your activity to us. We do not collect usage metrics, feature events, screen views, or device identifiers. The only things that ever leave your device are the sign-in identity described in Section 3 and a support file you choose to send yourself, which is redacted on your device first (see Section 5).
Key promise: The bank statements, transactions, and classification results you upload or paste are, by default, processed and stored locally in your browser (wa-sqlite + OPFS) and are not uploaded to our servers.

3. Data collected through Google sign-in

The Extension uses Google OAuth 2.0 for authentication. When you choose "Sign in with Google", we obtain only the following basic profile information, used to identify you and keep you signed in:

DataPurposeUploaded?
Email addressUnique account identifier & sessionYes (email only)
NameDisplay & greetingYes
Profile pictureDisplayYes
Google user ID (sub)Stable account keyYes

We do not use Google sign-in to read your Gmail, contacts, Drive, or any other Google service. The scopes we request are limited to openid, email, and profile.

Limited Use: User data we access is used only for the purposes described in this Privacy Policy — providing and improving the Extension's functionality — in compliance with the Google API Services User Data Policy and Chrome Web Store requirements. We do not use Google user data for advertising.

4. Local processing of your financial data

Statement parsing, reconciliation, categorisation, merchant-name cleaning and ledger storage run as a Rust / WASM engine inside your browser. Your transactions are stored in a local SQLite database (wa-sqlite) persisted to your browser’s own storage area (OPFS), inside a dedicated worker. Unless you explicitly trigger an export, or a support upload you approve yourself (Section 5), this data never leaves your device.

5. Support uploads and on-device redaction

If the Extension cannot read a statement layout, you can send us the file so we can adapt to it. This is entirely optional and only ever happens when you choose to submit it. Before a PDF leaves your browser, it is rebuilt and redacted on your device:

Why this distinction matters: drawing a black bar over live text is not redaction — the text underneath is still present and any extractor can recover it. Our block has nothing underneath it: sensitive fragments are identified first and then simply not written into the new file, so those characters are gone, not hidden. In the rare case where the rebuilt file cannot be verified, the Extension falls back to rendering the pages as images instead — still redacted, but without a text layer. Please still review the preview before sending, and switch redaction off only if you are certain the file contains nothing you wish to withhold.

The redacted file is stored in our object storage so that we can reproduce the layout problem. It is used only to build and test a parser configuration for that bank. It is not sold, not shared with third parties, and not used to train any model. To have an upload deleted, email us with the filename and the approximate date you sent it.

6. How we use information

We use the information we collect only for the following purposes:

7. We do not sell or share your data

We will not sell your personal information, and we will not use it for targeted advertising. Except for the limited cases below, we do not share your data with third parties:

8. Data storage & retention

Your Google sign-in identity is retained until you delete your account or revoke authorization. You can revoke the Extension's access at any time via Google's third-party app permissions. After revocation we stop using and delete the associated identity data.

Locally stored financial data is under your control — uninstalling the Extension or clearing site data removes it.

A redacted support file you upload (Section 5) is retained only as long as we need it to reproduce and fix the layout problem, after which it is deleted. You can request deletion at any time by emailing us with the filename and the approximate date you sent it.

9. Security

We apply reasonable technical and organizational measures to protect your information, including transport encryption (HTTPS / TLS), minimal-scope OAuth, and keeping sensitive financial processing on your device. No transmission over the internet is absolutely secure, and we cannot guarantee 100% security.

10. Your rights

Depending on your jurisdiction, you may have the following rights:

To exercise these rights, contact us using the details below.

11. Children's privacy

The Extension is not directed to children under 13 (or the equivalent age in your jurisdiction), and we do not knowingly collect their personal information. If you believe we have inadvertently done so, contact us so we can delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Please review it periodically before continued use.

13. Contact us

If you have any questions about this Privacy Policy or our data practices, contact us at: