Veracity Ledger

Privacy Policy

Effective date: September 8, 2026

Veracity Ledger is operated by Veracity Holdings ("we," "us," or "our"). This policy explains how we handle personal information when you visit veracityledger.com, create an account, use our financial management features, connect a service, or contact us.

Veracity Ledger helps individuals and business owners organize financial records, track income and expenses, manage budgets and debt, and support bookkeeping and tax planning. The information we process depends on the features you use and the information you provide.

Privacy questions and requests: veracityholdings2022@gmail.com

1. Information we collect

Account and business information

We collect information you provide when registering or maintaining your account, such as your email address, account identifiers, authentication information, business name, entity type, business location, tax year, profile information, and workspace role. If you choose Google sign in, we receive the identity information made available through that sign in process, such as your email address and basic profile details. Google sign in does not give Veracity Ledger access to your Gmail messages or Google Drive files.

Financial and planning information

We process records you enter, upload, or authorize a connected service to provide. These can include account information and balances; transaction dates, amounts, merchants, descriptions, categories, and status; income and expenses; tax profile facts and recorded tax payments; budgets; debts and interest rates; savings goals; investment holdings and activity; mileage, trip purposes, and vehicle information; and the classifications, notes, reports, and estimates created from these records.

Documents and communications

We process receipts, invoices, statements, and other files you upload, including their contents, file names, and related metadata. We also process support messages, questions submitted to the assistant, professional review requests, reviewer contact details, and comments or responses associated with those requests.

Connection and technical information

When you connect a financial institution or another service, we process connection identifiers, authorization tokens or API credentials you supply, synchronization status, and the records authorized for import. Our service providers and application systems may also process IP addresses, browser and device information, request times, error details, security events, and usage information needed to operate and troubleshoot the service.

Financial records and uploaded documents can contain sensitive information. Provide information you are authorized to use, and remove bank passwords, security codes, and unnecessary full Social Security or payment card numbers from documents, notes, support messages, and AI questions.

2. How we use information

We use personal information to create and authenticate accounts; operate workspaces; import and organize financial records; categorize transactions; prepare calculations, reports, budgets, and planning tools; and provide the features you request.

We also use information to process subscriptions, maintain billing records, respond to support and privacy requests, communicate about your account, diagnose errors, improve service reliability, detect misuse, protect accounts, maintain audit records, comply with applicable legal obligations, and establish or defend legal claims.

Connecting a financial account for analysis does not authorize payments or transfers from that account. Our financial management features do not make lending or credit eligibility decisions about you.

3. Bank connections through Plaid

If you choose to connect an account, Plaid facilitates the connection to your financial institution and provides the financial information you authorize. We receive connection identifiers, tokens, institution information, and transaction data for the financial management features you use. The information available depends on the institution, your authorization, and the enabled integration.

You enter bank authentication information through Plaid or your financial institution. Veracity Ledger does not receive your bank password through this integration. Connection tokens allow the service to retrieve authorized information while the connection remains active. Our Plaid integration is used to read financial data and does not initiate transfers or payments.

Plaid handles information under its End User Privacy Policy. You can manage eligible connections through Plaid Portal or your financial institution's available controls. You can also contact us to request disconnection. Stopping a connection does not automatically delete records already imported into Veracity Ledger; request deletion separately as described below.

4. Subscription payments through Stripe

Stripe processes payments for Veracity Ledger subscriptions. We share account identifiers, email addresses, and subscription information needed for checkout and billing. Stripe collects the payment and billing details you provide in its checkout and billing interfaces.

We receive information such as customer and subscription identifiers, plan and subscription status, payment results, invoice details, and limited billing information. Our Stripe checkout integration does not send us your full payment card number or card security code. Stripe may process information for payment services, fraud prevention, compliance, and other purposes described in the Stripe Privacy Policy.

Subscription payments are separate from the financial account information you connect for bookkeeping. Canceling a subscription and requesting deletion of personal information are separate actions.

5. AI assistance and receipt reading

Tim is our AI support assistant. General support questions send your question, up to four previous questions, and a recognized page name to the AI provider. This mode does not automatically attach financial records or uploaded files. Built in help topics do not call the AI provider. Choosing Tim's Financial records mode uses the supporting workspace information described below.

Tim's chat is temporary in the current view. Reports submitted through the report form are saved separately with your account identifier, category, description, recognized page name, timestamps, and status history. Reports and owner updates are accessible to the submitter and app administrators. Recognized application failures may generate limited diagnostic reports containing a fixed error category and timestamps; a signed in page failure can also include your account identifier and a recognized page name. Raw error text, stack traces, query strings, chat transcripts, and financial documents are not automatically attached to these Tim reports. Basic automated masking may miss sensitive information, so review a report before submitting it. Support records follow the retention and deletion practices below.

When enabled, the assistant and receipt reading features use OpenAI GPT models through the configured direct OpenAI or Lovable gateway connection. When you submit a question to the assistant, your question and a limited selection of supporting workspace information are sent for processing. That information can include entity type, state and tax year, merchant names, transaction dates and amounts, classifications, document counts, mileage dates and distances, and recorded tax payments. The assistant does not include bank connection tokens, full business profile notes, document names, or account credentials in its supporting context. Avoid including unnecessary sensitive information in your question.

When you select the receipt reading feature, the complete selected receipt image is sent for extraction. The resulting extracted information may be stored with the document and used to suggest transaction matches. Uploading a document and selecting receipt reading are separate actions.

You can use the other recordkeeping features without submitting an assistant question or selecting receipt reading. We disable Lovable's AI app context feature for this project and request that OpenAI not store responses for later retrieval. These settings do not guarantee zero retention: providers can retain information for security, abuse monitoring, legal obligations, and service operation under their applicable terms. See Lovable's Privacy Policy and OpenAI's Privacy Policy. Contact us before using these features if you need information about the applicable processing arrangements. AI outputs may contain errors and should be checked against your original records.

6. When we disclose information

Service providers

We disclose information needed by providers that support hosting, authentication, databases, file storage, payment processing, account connectivity, AI processing, email delivery, technical support, and security. These include Lovable and Supabase for application infrastructure, Plaid for bank connections, Stripe for billing, and the AI providers described above. Providers may use their own service providers to deliver these functions. See the Supabase Privacy Policy for information about Supabase.

People and services you authorize

Information may be available to authorized members of your business workspace and to accountants, advisers, or other recipients when you create and share a report, export, or review link. Anyone who obtains a valid review link may be able to view the information covered by that link until it expires or is revoked. Revoking access does not recall copies a recipient already downloaded or received.

Optional integrations exchange information within the permissions you authorize. Their availability and the records involved depend on the connection. A provider listed in the application is not automatically connected to your account.

Legal requirements and business changes

We may disclose information when reasonably necessary to comply with applicable law or valid legal process, investigate fraud or security incidents, protect rights and safety, or establish or defend legal claims. Information may also be disclosed as part of evaluating or completing a merger, acquisition, financing, or transfer of business assets, subject to applicable confidentiality and legal requirements.

Sale and advertising

We do not sell personal information or share it for advertising that follows you across different businesses' websites or services. We do not use your financial records for targeted advertising. The operational disclosures described in this policy, including to payment, bank connectivity, infrastructure, and AI providers, are separate from selling information or sharing it for that advertising purpose.

7. Cookies, browser storage, and tracking

The application and integrated services use browser technologies for sign in, session continuity, preferences, security, and feature operation. Some imported records and classification changes may remain in your browser's local storage as a fallback. Clearing browser data can remove these local copies and preferences, and may sign you out. It does not delete records stored in your online workspace.

Some application pages request fonts from Google Fonts. Your browser sends technical request information, such as your IP address, when contacting that service. Embedded payment, account connection, and authentication services may also collect information directly and use their own cookies or similar technologies. Their notices explain their collection, including any activity information they process across services.

The application does not currently change its behavior in response to browser Do Not Track signals. It does not use advertising trackers to sell or share personal information for advertising across services. A Global Privacy Control signal therefore has no sale or advertising sharing activity in Veracity Ledger to switch off. This does not prevent you from making another applicable privacy request.

8. Retention and deletion

We retain account information and workspace records while needed to provide the service and for the purposes described in this policy. Retention depends on the type and sensitivity of the information, your use of the service, deletion requests, accounting and legal obligations, security needs, and the resolution of disputes. We do not apply one fixed retention period to every category of information.

You can delete individual uploaded documents using available document controls. For account closure or a broader deletion request, contact us using the email below. We review the request, verify the authority to make it, and delete or deidentify information as required by applicable law. We may retain limited information where required or permitted for billing, legal obligations, fraud prevention, security, or legal claims, and explain applicable limits when responding to your request.

Deletion from active systems may not immediately remove copies in backups, security records, or a service provider's systems. Those copies remain subject to applicable retention arrangements and legal obligations. Files you exported, local browser copies, and information retained independently by your bank, payment provider, or a recipient require separate handling. Keep any financial records you need before closing your account.

9. Your choices and privacy requests

You can choose whether to connect a service, upload a document, request AI processing, or share a review link. Use available profile and document controls to review or change information. Contact us for assistance accessing, correcting, exporting, or deleting information, closing an account, or stopping a connection.

Depending on where you live and which laws apply, you may have rights to confirm whether we process your personal information, access or obtain a copy of it, correct inaccuracies, request deletion, withdraw consent, or opt out of specified processing. Additional rights may include limits on certain uses of sensitive information or an appeal of a denied request. These rights have legal conditions and exceptions.

Email veracityholdings2022@gmail.com with the subject "Veracity Ledger privacy request." Describe your request and the email associated with your account. Do not send passwords, full payment card numbers, bank login details, or government identification documents in your initial email. We may ask for information reasonably needed to verify your identity or an authorized agent's authority before disclosing or deleting account information.

We respond within the period required by applicable law and explain any applicable extension or denial. If an appeal right applies, reply with the subject "Privacy request appeal." We will explain the outcome and any further complaint options required by law. We do not penalize you for exercising applicable privacy rights, although a feature may no longer work when information necessary for it is deleted or permission is withdrawn.

If a business manages your workspace, some requests may need to be handled with that business because the workspace contains records it controls. We will explain this when relevant.

10. Security

The application uses authentication, workspace access controls, private document storage, and server processing for integration credentials. We use these measures to help protect information from unauthorized access, disclosure, alteration, or loss. No internet service or storage system can guarantee absolute security.

Protect your account credentials, use a device you trust, and share exports and review links carefully. Contact us promptly if you suspect unauthorized access. Where a security incident triggers a legal notification obligation, we will provide the required notices.

11. Where information is processed

Veracity Holdings operates in the United States. Service providers may process information in the United States and other countries where they or their authorized providers operate. The location can depend on the service and feature. Applicable contractual and legal requirements govern this processing. Contact us if you need details about data location before connecting accounts or submitting sensitive information.

12. Children and information about others

Veracity Ledger is intended for adults age 18 and older and is not directed to children. If you believe a child has created an account or directly provided personal information, contact us so we can investigate and take appropriate action, including deletion where required.

Adult users may provide household, dependent, employee, customer, or reviewer information as part of financial records or planning. Provide only information you are authorized to use and that is relevant to the feature. This policy covers that information when we process it through the service.

13. Changes to this policy

We may update this policy as the service or applicable requirements change. We will post the revised policy here and update its effective date. For material changes, we will provide additional notice when required, such as an account notice or email. Where a new use requires consent, we will obtain it before that processing begins.

14. Contact us

Veracity Holdings
Veracity Ledger privacy requests
veracityholdings2022@gmail.com

Website: veracityledger.com