Privacy Policy
Last updated: 2026-08-29
Contents
1. Who we are 2. Information we collect 3. Data collected through Google sign-in 4. Local processing of your financial data 5. Support uploads and on-device redaction 6. How we use information 7. We do not sell or share your data 8. Data storage & retention 9. Security 10. Your rights 11. Children's privacy 12. Changes to this policy 13. Contact us1. Who we are
LedgerPanda is a local-first Chrome extension for people who keep their own books. It parses bank statement PDFs inside your browser, normalises merchant names using an on-device model, reconciles the parsed rows against the totals your bank printed, and exports CSV. Parsing, cleaning, reconciliation, categorisation and storage all run on your device. The operator is LedgerPanda (a trade name of the individual developer behind this Extension), and our website / domain is https://ledgerpanda.com.
2. Information we collect
We collect the minimum information necessary to provide the service. In practice, that is one category:
- Account information: identity details obtained through Google sign-in (see Section 3).
3. Data collected through Google sign-in
The Extension uses Google OAuth 2.0 for authentication. When you choose "Sign in with Google", we obtain only the following basic profile information, used to identify you and keep you signed in:
| Data | Purpose | Uploaded? |
|---|---|---|
| Email address | Unique account identifier & session | Yes (email only) |
| Name | Display & greeting | Yes |
| Profile picture | Display | Yes |
| Google user ID (sub) | Stable account key | Yes |
We do not use Google sign-in to read your Gmail, contacts, Drive, or any other Google
service. The scopes we request are limited to openid, email, and profile.
4. Local processing of your financial data
Statement parsing, reconciliation, categorisation, merchant-name cleaning and ledger storage run as a Rust / WASM engine inside your browser. Your transactions are stored in a local SQLite database (wa-sqlite) persisted to your browser’s own storage area (OPFS), inside a dedicated worker. Unless you explicitly trigger an export, or a support upload you approve yourself (Section 5), this data never leaves your device.
- We do not host your ledger — your transactions stay in the local SQLite database — and we never ask for your online-banking credentials. The only statement file we ever store is the redacted copy you send us for support (Section 5).
- Reconciliation — the rows parsed from your statement are checked against the balances and totals your bank printed on it (opening balance, closing balance, income and expense). Every amount is computed in integer cents. This comparison runs entirely on your device; no totals are transmitted to us.
- Merchant-name cleaning and categorisation use the language model built into your own browser (Chrome’s on-device AI, Chrome 138+). Cleaning runs only when you choose to run it — via the AI Simplify action, or by turning automatic classification on in Settings; it never runs on its own in the background. Your descriptions are never sent to a third-party model provider, and there is no API key or inference endpoint involved.
- On-device logic runs entirely on your machine.
5. Support uploads and on-device redaction
If the Extension cannot read a statement layout, you can send us the file so we can adapt to it. This is entirely optional and only ever happens when you choose to submit it. Before a PDF leaves your browser, it is rebuilt and redacted on your device:
- The file is rebuilt from scratch on your device: a new PDF is written fragment by fragment. Sensitive spans — account and card numbers, account holder and customer names, customer IDs, SSN / social security number, tax ID, IBAN, phone numbers, date of birth, and addresses — are not written into it at all; a black block labelled REDACTED occupies their position instead;
- Everything that is not sensitive — transaction dates, descriptions, amounts, balances — is rewritten at its original page position and font size, so the file keeps a text layer. This is deliberate: it lets us run our parser against the file you actually sent, which is how we reproduce and fix your layout;
- Redaction is enabled by default, and you can preview the redacted file before it is uploaded;
- Images are not redacted. Rebuilding works on PDFs. If you attach a screenshot or other image instead, it is uploaded exactly as it is — there is no text layer to rebuild, so nothing is removed. Review the preview before sending it.
The redacted file is stored in our object storage so that we can reproduce the layout problem. It is used only to build and test a parser configuration for that bank. It is not sold, not shared with third parties, and not used to train any model. To have an upload deleted, email us with the filename and the approximate date you sent it.
6. How we use information
We use the information we collect only for the following purposes:
- Creating and maintaining your account and session;
- Providing, maintaining, and improving the Extension (e.g. validating perk / subscription eligibility);
- Troubleshooting, securing the service, and preventing abuse;
- Communicating with you about material changes or legal matters when necessary.
7. We do not sell or share your data
We will not sell your personal information, and we will not use it for targeted advertising. Except for the limited cases below, we do not share your data with third parties:
- Service providers: infrastructure vendors (e.g. our website host, authentication provider and object storage, the providers serving ledgerpanda.com, such as Cloudflare Pages / Supabase) that process data only on our instructions. A redacted support file you send (Section 5) is stored with such a provider solely so we can reproduce the layout problem;
- Legal requirements: where required by applicable law or a valid subpoena / court order;
- With your consent: for example, a cloud backup you explicitly enable.
8. Data storage & retention
Your Google sign-in identity is retained until you delete your account or revoke authorization. You can revoke the Extension's access at any time via Google's third-party app permissions. After revocation we stop using and delete the associated identity data.
Locally stored financial data is under your control — uninstalling the Extension or clearing site data removes it.
A redacted support file you upload (Section 5) is retained only as long as we need it to reproduce and fix the layout problem, after which it is deleted. You can request deletion at any time by emailing us with the filename and the approximate date you sent it.
9. Security
We apply reasonable technical and organizational measures to protect your information, including transport encryption (HTTPS / TLS), minimal-scope OAuth, and keeping sensitive financial processing on your device. No transmission over the internet is absolutely secure, and we cannot guarantee 100% security.
10. Your rights
Depending on your jurisdiction, you may have the following rights:
- Access, correct, or delete the personal information we hold about you;
- Revoke authorization for Google data access;
- Data portability (where technically and legally feasible);
- Complain to the relevant supervisory authority.
To exercise these rights, contact us using the details below.
11. Children's privacy
The Extension is not directed to children under 13 (or the equivalent age in your jurisdiction), and we do not knowingly collect their personal information. If you believe we have inadvertently done so, contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Please review it periodically before continued use.
13. Contact us
If you have any questions about this Privacy Policy or our data practices, contact us at:
- Email: ledgerpanda@gmail.com
- Operator: LedgerPanda
- Website: https://ledgerpanda.com