ShadowLedger
How it worksPlatformFor firmsPricing
Sign inStart free scan
← Back to ShadowLedger

Privacy Policy

Effective August 14, 2026

This Privacy Policy explains how ShadowLedger (“ShadowLedger,” “we,” “us,” or “our”) collects, uses, and protects information when you use our website and application (the “Service”). ShadowLedger helps organizations discover software subscriptions and optimize spend from their accounting data.

Who is responsible for your data

ShadowLedger is operated by John Dorn, a sole proprietor based in California, United States. For questions or requests, write to support@getshadowledger.com.

Which role we play depends on whose data it is, and the distinction matters if you are a firm using this for your clients:

  • Your own account information (your name, email, billing details, how you use the product) is data we decide the purposes for. In UK and EU terms we are the controller of it.
  • The accounting data you connect or upload, including your clients' ledgers if you are a firm, is data we process only on your instructions and only to run the Service. In UK and EU terms you are the controller and we are the processor. Our Data Processing Agreement sets out that relationship, and applies automatically to Firm accounts.

Information we collect

We collect the following categories of information:

  • Account information. When you sign up, our authentication provider (Clerk) collects your email address, name, and authentication credentials. We do not store your password.
  • Financial and accounting data. When you upload an accounting export or connect QuickBooks Online, we process transaction records (dates, amounts, descriptions, and vendor names) to detect subscriptions and estimate spend. We do not access bank login credentials.
  • Connection tokens. If you connect QuickBooks Online, we store OAuth access and refresh tokens so we can sync on your behalf. These tokens are encrypted at rest.
  • Billing information. Payments are processed by Stripe. We store your Stripe customer and subscription identifiers and plan status; we do not store your full card number.
  • Usage data. We collect basic technical information such as scan history and log data needed to operate and secure the Service, plus the first-party page-view records described under Usage analytics below.

How we use information

  • To provide the Service: running scans, generating reports, and syncing data you connect.
  • To manage your account, subscription, and billing.
  • To secure the Service, prevent abuse, and debug problems.
  • To communicate with you about your account or the Service.

We do not sell your personal information, and we do not use your financial or accounting data for advertising.

How we share information

We share information only with service providers that help us operate the Service, and only as needed to perform their function. Each entry below says what that provider can actually see. This list is generated from the application code, and a test fails our build if an outbound integration is added without being disclosed here.

  • Vercel: Application hosting, and storage for firm logos on client reports. All request traffic, server logs, and uploaded firm logo images.
  • Prisma Postgres: The primary database that stores your scans and account data. Everything the Service stores: transactions, findings, vendor records, connection tokens (encrypted), preferences, and billing identifiers.
  • Clerk: Authentication and account management. Your email address, name, and authentication credentials.
  • Stripe: Payments and subscription billing. Your email address, billing address, card details you enter on Stripe's own form, and subscription state. Card numbers never reach our servers.
  • Anthropic: The AI analysis behind vendor matching, the Ask your ledger chat, and contract term extraction. Transaction descriptions and vendor names sent for matching; the text of questions you ask in chat, together with the vendor names and amounts needed to answer them; and the full text of any contract document you upload for extraction. Under Anthropic's commercial terms, API inputs are not used to train their models.
  • Resend: Transactional and notification email. Your email address and the full contents of every message we send you, which for alerts and digests includes vendor names and amounts.
  • Inngest: Background jobs, including scheduled re-scans and renewal alerts. Job payloads, which carry account and connection identifiers. The financial data itself stays in our database.
  • Expo: Push notifications to the mobile app, if you use it. Renewal alerts name the vendors that are renewing, so those names appear in the notification text. Your device push token and the text of each notification. Renewal alerts name the vendors renewing, so those names pass through Expo and the Apple or Google push network in readable form.

All of the providers above process data in the United States, which means that if you are outside the United States your data is transferred there to run the Service.

Accounting systems you connect

These are platforms you already use and choose to connect. Data moves from them to us on your instruction, which is a different relationship from the providers above.

  • Intuit / QuickBooks Online: When you choose to connect it, to read your accounting transactions. We only ever issue read and query calls, and never write to your books.
  • Xero: The same read-only transaction access as QuickBooks Online, for firms on Xero.
  • Google Workspace (built, but not open to customers yet): Reads the admin reports that show which paid applications a workspace is actually using.

We may also disclose information if required by law, or to protect the rights, safety, and security of ShadowLedger and its users. If we are involved in a merger or acquisition, information may be transferred as part of that transaction.

Google user data

The Google Workspace connection reads something different from the accounting connectors, so it gets its own description. Everything in this section also applies while the connection is marked above as built but not open to customers: until Google's verification review clears, only our own staff can authorize it.

What we access. Two read-only Google Admin SDK permissions, and nothing else: the audit report of third-party application activity (admin.reports.audit.readonly) and the user directory (admin.directory.user.readonly). Together they show which applications people in the workspace use and how many licensed users the workspace has. The connection cannot read email, files, calendars, or messages, and it cannot change anything in the Google account.

What we keep. The raw report rows name individual users. We do not store them. Each sync reduces those rows, in memory, to one count per application: how many distinct people used it and when it was last used. Only those counts are saved, together with the workspace's licensed user total. Which named person uses which application is never written to our database and never shown in the product.

How we use it. Solely to compare the seats a workspace pays for against the seats it actually uses, in the reports you run. We do not use Google user data for advertising, and we do not sell it.

AI and machine learning. Google user data is not used to develop, improve, or train any AI or machine-learning model, and it is not sent to Anthropic or any other model provider. Application names reported by Google are matched to vendors by deterministic code, not by a model, and none of the AI features described under Automated analysis below receive Google user data.

Who else sees it. No one. The stored counts sit in our database like everything else we hold and are not transferred to any third party beyond the storage and hosting providers listed above, which process them only on our behalf.

How it is protected. The OAuth tokens for the connection are encrypted at rest, and all traffic between us and Google uses encrypted transport (HTTPS).

Retention and deletion. Disconnecting Google Workspace revokes our access at Google, deletes the stored tokens, and deletes the stored seat counts. Closing your account does the same as part of the erasure described under Data retention below. You can also revoke our access yourself at any time from your Google account's security settings.

ShadowLedger's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Automated analysis

Three parts of the Service use a large language model, all of them running on Anthropic's API: matching a transaction description to a known vendor, answering questions in the Ask your ledger chat, and extracting terms from a contract document you upload. Anthropic is our only model provider for anything that touches your books, and we do not send this data to a second provider. Where you connect your own AI assistant, that is your choice rather than ours; see below.

What is sent: for vendor matching, the transaction description; for chat, your question along with the vendor names and amounts needed to answer it; for contract extraction, the contents of the document you uploaded. An uploaded contract is passed straight through and is never written to storage on our side. Under Anthropic's commercial terms, API inputs are not used to train their models.

We do not make automated decisions that produce legal or similarly significant effects. Findings are suggestions for a human to accept or reject, and every figure in a report is computed from your transactions rather than generated by a model.

Connecting your own AI assistant

On the Pro and Firm plans you can create an API token in Settings and give it to an AI assistant you run, so it can work with your audit data without opening the app. A token reads only, unless you mark it as writable when you create it. A writable one additionally lets an assistant snooze and dismiss findings and edit vendor notes and contract dates. Anything an assistant changes is recorded as having come from an assistant, so you can always tell those apart from your own decisions.

Four things no token permits, whatever you tick: recording a savings amount against a finding, adding or removing a client, running an audit, and sharing a report. Those change what you are billed or change a figure your own client sees, so they stay with you.

This is worth understanding before you turn it on. When you connect an assistant, your audit data goes to whoever provides that assistant, on their terms, not ours. We have no control over what they do with it and no visibility into it, and the assurances above about Anthropic apply only to the AI features we operate. Whether a given assistant is an appropriate place for your clients' financial data is a decision only you can make, and if you act as a processor for your own clients it may be one your engagement terms speak to.

A token is a credential: anyone holding it can read everything the app shows you, until you revoke it. Revoke one in Settings the moment it is no longer in use. We record which tool an assistant called and when, so we can answer what a token reached, and that record holds no vendor names or amounts.

Usage analytics

We measure traffic ourselves rather than handing it to an analytics vendor. There is no third-party analytics script on this site, no advertising pixel, and no cross-site tracking. Each page view is recorded on our own servers with the page's route, the referring site's domain, a two-letter country code from our host's edge network, whether the device is a phone, and a session identifier from a first-party cookie that expires after 30 minutes of inactivity.

We do not store your IP address with these records, we do not build a device fingerprint, and page addresses are reduced to their route before being saved, so identifiers in a URL (a scan id, a report link) are never kept. Raw page-view records are deleted after 30 days; what remains after that is daily totals that describe no individual visit.

If your browser sends a Do Not Track or Global Privacy Control signal, we record nothing at all for that visit.

Visitors in the UK and the European Economic Area get no analytics cookie at all. The visit is counted using an identifier that lasts only for that one request, so nothing is stored on the device and there is nothing to ask consent for, which is why this site has no cookie banner. Every cookie we set is listed in the Cookie Notice.

Data retention

You may delete stored scans at any time, and you may disconnect QuickBooks Online to revoke our access and remove stored tokens. Beyond that, a nightly job applies these limits:

WhatKept for
Scans, including the transactions and findings behind them400 days, except the most recent scan in each workspace, which is kept while the account is open
Record of which emails we sent you400 days
Mobile push registrations180 days after a device last checked in
Raw page-view records30 days, then only daily totals that describe no individual visit
Security audit trail: who reached what, including views of a report you shared by link400 days
Everything else in your accountWhile the account is open

Each workspace always keeps its most recent scan, however old, so a client you audit once a year does not come back to an empty history.

If you close your account, the erasure runs automatically. Every accounting grant you hold is first revoked at the provider, then your scans, transactions, connections, clients, custom rules, share links, calendar links, vendor corrections, uploaded report logo, and preferences are deleted, and any active subscription is cancelled. Two things are retained in de-identified form: product analytics events and any feedback you sent us, both stripped of your account id and, for feedback, of the reply address you gave.

The security audit trail is the one thing that is not erased on request. It records who reached what, including views of reports shared by link, and much of it describes actions taken by other people rather than by you. A trail the subject can erase is not much of a trail, and the account most worth investigating is often one that has since been closed. It is bounded rather than kept indefinitely: the same 400 days limit in the table above applies, and the nightly job enforces it. We may also retain records where retention is required by law.

Security

We use industry-standard measures to protect your data, including encryption of connection tokens at rest and encrypted transport (HTTPS). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Why we are allowed to process it

If you are in the UK or the European Economic Area, we rely on these legal bases:

  • Performance of a contract for running your account, scanning what you give us, producing reports, and billing you.
  • Legitimate interests for keeping the Service secure, preventing abuse, understanding which parts of the site are read, and telling you about changes to the product you use. Where we rely on this, we have considered whether it overrides your interests, and you can object (see below).
  • Legal obligation for keeping records we are required to keep, such as tax and payment records.

International transfers

We operate from the United States and every provider listed above processes data there. If you are in the UK, the EEA, Australia, or New Zealand, using the Service means your data is transferred to the United States.

For transfers of UK and EEA personal data, the transfer mechanism and the safeguards that go with it are set out in our Data Processing Agreement, which you can enter into with us before connecting any client ledger. Ask and we will send a countersigned copy.

Your rights

Everyone, wherever they are, can ask us for a copy of their data, ask us to correct it, or close their account and have it erased. Signed-in users can download everything the account holds from Settings, and closing the account runs the erasure described above. Neither costs anything and neither requires a paid plan.

Depending on where you live you may have these additional rights, and we apply them on request rather than asking you to prove where you are:

  • United Kingdom and European Economic Area. Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. You can complain to the UK Information Commissioner's Office or to your national supervisory authority.
  • California. The right to know what we collect and why, to access and delete it, to correct it, and not to be discriminated against for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to offer for either. You may use an authorized agent.
  • Australia. Access and correction under the Australian Privacy Principles, and a complaint route to the Office of the Australian Information Commissioner if we do not resolve it.
  • New Zealand. Access and correction under the Information Privacy Principles, and a complaint route to the Office of the Privacy Commissioner.

To exercise anything not available in the app, email support@getshadowledger.com. We will respond within 30 days, and will tell you if we need longer and why. If a request concerns a client ledger that a firm connected, we will refer it to that firm, because the data is theirs to decide about and not ours.

If something goes wrong

If personal data we hold is breached, we will notify the relevant supervisory authority and affected people where the law requires it, and without undue delay. If the data belongs to a firm's client, we notify the firm so it can meet its own obligations, as set out in the Data Processing Agreement.

Children's privacy

The Service is not directed to individuals under 18, and we do not knowingly collect information from children.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the effective date above. Material changes will be communicated where appropriate.

  • August 18, 2026. A token can now optionally be marked writable, letting a connected assistant snooze and dismiss findings and edit vendor notes. Named the four things no token permits, and recorded that assistant-made changes are marked as such.
  • August 16, 2026. Added the section on connecting your own AI assistant: what a token can read, that access is read-only, that data reaching an assistant you connect travels on that provider's terms rather than ours, and what we log about it.
  • August 14, 2026. Added the Google user data section: what the Google Workspace connection reads, what is kept, that none of it is used for AI or transferred onward, and that disconnecting deletes the seat counts along with the tokens. Added our adherence to the Google API Services User Data Policy, including its Limited Use requirements.
  • August 12, 2026. Named Anthropic as the provider behind the product's AI features and described what is sent there. Added our controller and processor roles, legal bases, international transfers, per-region rights for the UK, EEA, Australia and New Zealand, breach notification, and the cookie position for UK and EEA visitors. Described what account closure actually does.
  • July 15, 2026. First published.

Contact us

Questions about this policy or your data can be sent to support@getshadowledger.com.

This policy is provided for transparency and is not legal advice. We recommend reviewing it with qualified counsel before relying on it.

ShadowLedger
ProductHow it worksPlatformFor firmsPricingLive demoXeroAI assistant
ResourcesCompareGlossaryWritingFAQ
CompanyAboutSecuritySupportSign in
© 2026 ShadowLedger. The software-spend audit for QuickBooks and Xero.
1968 S. Coast Hwy #2257, Laguna Beach, CA 92651
PrivacyTermsDPACookies