Privacy Policy
Last Updated: October 4, 2026
1. Introduction
Atlas Ledger ("the Service") is a personal finance app operated by ATP Technology LLC, a Colorado limited liability company ("we," "our," "us"), and offered on the web at
atlasledger.studio and as a mobile app for iOS and Android. This policy explains what personal
information we collect, how we use it, who we share it with, how long we keep it, and the choices you have.
Short version: we use your financial data to run the app for you. We do not sell it, and
we do not use it for advertising. You can delete your account at any time.
2. Information We Collect
2.1 Information You Give Us
- Account information: name, email address, time zone, and password (stored only as a bcrypt hash, never in readable form). If you turn on two-factor authentication, we store an authenticator secret (encrypted) and recovery codes.
- Information you enter: such as budgets, savings goals, transaction rules, categories, notes, manually entered transactions and assets, credit scores you record, paycheck settings, and files you import.
- Crypto wallets: public wallet addresses you add, and, for crypto exchange connections, the API keys, secrets, or sign-in tokens you provide. Exchange secrets and tokens are encrypted.
- Receipt images you choose to scan, and AI assistant messages you send (see Section 5).
- Feedback and bug reports you submit in the app (see Section 4.3).
- Household invitations: the email address of anyone you invite to your household.
2.2 Financial Data (with Your Permission)
When you link a bank, card, loan, or investment account, you connect through a third-party provider:
Plaid Inc., or for some institutions Teller. You give your bank login to the
provider, never to us. We never receive or store your banking username or password. The
provider gives us an access token, which we store encrypted. Through it we receive:
- Account details: institution name, account name and type, the last few digits of the account number, and balances
- Transactions: date, amount, merchant or description, category, and pending status
- Investment holdings (if you consent): securities, quantities, and values
See Plaid's End User Privacy Policy.
2.3 Information from Sign-In Providers
If you sign in with Google or Apple, or use sign-in handled by
Google Firebase Authentication, we receive your name, email address, and an account
identifier from that provider. We do not access your contacts, calendar, photos, or other data held by
that provider.
2.4 Payment Information
- Web subscriptions are processed by Stripe, Inc. on Stripe's checkout page. Stripe collects your card details; we do not receive or store your card number. We share your name and email with Stripe, and receive back a customer ID, your plan, billing dates, and subscription and payment status. See Stripe's Privacy Policy.
- In-app purchases on iOS and Android are processed by Apple or Google. We learn the status of those purchases through RevenueCat, which identifies you by your numeric Atlas Ledger user ID.
2.5 Information Collected Automatically
- Device and log data: IP address, browser type, operating system, pages or screens viewed, and timestamps
- Security and audit logs: certain security events and administrative actions (for example, account data exports) are logged with the email address involved, IP address, and time
- Analytics and error reports: see Section 6
- Push notification token: if you allow notifications in the mobile app, we store a push token for your device. It is removed when you sign out of the app.
3. How We Use Your Information
- Provide the Service: sync accounts and transactions, and calculate budgets, goals, net worth, forecasts, and other analytics
- Run features you ask for, such as the AI assistant, receipt scanning, household sharing, and alerts
- Send account emails (such as verification, password reset, payment problems, and household invitations) and alerts and push notifications you have turned on
- Process subscriptions and payments, and apply the one-free-trial-per-person rule
- Secure the Service: authentication, two-factor authentication, rate limiting, fraud and abuse prevention, and audit logging
- Understand how the product is used and fix bugs
- Respond to your support requests and feedback, and comply with the law
We do not sell your personal information. We do not use it for targeted or cross-context
advertising, and our apps do not include advertising SDKs.
4. How We Share Information
4.1 Service Providers
We share personal information only with the providers below, and only as needed to run the Service:
- Plaid Inc. and Teller — connecting your financial accounts (Teller may be used for some institutions)
- Stripe, Inc. — web subscription billing
- RevenueCat, Apple, and Google — mobile in-app purchases
- Google Firebase Authentication, Google Sign-In, and Sign in with Apple — signing in
- Anthropic — AI assistant and receipt scanning (see Section 5)
- PostHog, Google Analytics, and Sentry — product analytics and error reports (see Section 6)
- Cloudflare — network delivery, HTTPS, and security for all traffic to the Service; it processes IP addresses and request data
- Google (Gmail) — sending our emails; it receives your email address and the message
- Expo — delivering mobile push notifications; it receives your push token and the notification text
- AbstractAPI — checking at signup that an email address is valid; it receives that email address
- GitHub — tracking feedback and bug reports (see Section 4.3)
- Hetzner — hosting our standby database server (see Section 10)
- Public blockchain and market-data services (such as CoinGecko, Coinbase, Etherscan, Polygonscan, Blockchain.com, a Solana network endpoint, and Yahoo Finance) — crypto balances and prices, and stock prices. They receive the public wallet addresses you add and coin or stock symbols, not your name or email.
- Crypto exchanges you connect — they receive the credentials or tokens you authorize, to sync your balances
4.2 Household Members
If you create or join a household, the other members can see your name, email address, and role, and a
combined view showing your total assets, total liabilities, net worth, and number of linked accounts.
You can leave a household at any time.
4.3 Feedback and Bug Reports
When you submit feedback or report an issue in the app, we create an issue in our issue tracker on
GitHub containing your name, email address, the page you were on, your browser's user
agent, and your message. We may also email the report to ourselves. Please do not include sensitive
financial information in feedback.
4.4 Legal Requirements and Business Transfers
We may disclose information if we believe in good faith that the law requires it, or to protect the
rights, property, or safety of our users, the public, or us. If Atlas Ledger is involved in a merger,
acquisition, or sale of assets, your information may be transferred as part of that transaction and will
remain subject to this policy.
5. AI Assistant and Receipt Scanning
AI assistant (Pro plan). When you send a message, we send the following to
Anthropic's Claude API to generate a reply: your message; up to the 20 most recent messages
of the current conversation; and a financial snapshot of your net worth, total assets, total liabilities,
this month's income, expenses and net savings, savings rate, and top spending categories over the last
3 months (category names and amounts). We do not send your name, email address, account
numbers, or individual transactions. We do not store the text of your AI conversations on our servers. We
do keep usage records (date, model, token counts, and estimated cost) to enforce usage limits.
Receipt scanning (Plus and Pro). The receipt image you upload is sent to Anthropic's Claude
API to extract the merchant, date, amount, and category. We do not store the receipt image. Only the
details you choose to save become part of your transactions.
Anthropic processes this data under its terms for API customers. See
Anthropic's Privacy Policy.
6. Cookies, Analytics, and Error Reporting
- Necessary cookies: sign-in cookies (a short-lived access token and a refresh token, both HttpOnly) and a CSRF-protection token. The Service does not work without them.
- PostHog (web and mobile) records which pages or screens you view and which buttons you click. On the web it also records session replays and page-load speed measurements (timings only, such as how long the page took to appear). All text, form inputs, and page element attributes are masked, so replays show layout and clicks but not your balances, transactions, or what you type. We identify you to PostHog only by your numeric user ID and plan, never by name, email, or dollar amounts, and we remove most query strings from recorded web addresses.
- Google Analytics measures website traffic and may set cookies. It only runs after you choose "Accept" on our cookie banner, and we remove query strings other than campaign tags from the page addresses it receives, so one-time links (such as password-reset links) never reach it. Choosing "Decline" keeps Google Analytics off and also turns off PostHog on the website in that browser.
- Cloudflare may set cookies for security and performance and may collect aggregate traffic statistics.
- Sentry (server and mobile app) receives technical error reports. It is configured not to send default personal data, and we remove query strings from web addresses in server error reports.
You can block or delete cookies in your browser, but you may not be able to sign in if you block the necessary ones.
7. Data Security
- Encryption in transit: all traffic to the Service uses HTTPS (TLS)
- Encryption at rest: bank-connection access tokens, crypto-exchange secrets and tokens, and two-factor authentication secrets are encrypted in our database using AES-256-GCM. Other data, such as balances and transactions, is not separately encrypted by the application.
- Password hashing: passwords are hashed with bcrypt
- Authentication: short-lived (15-minute) access tokens with HttpOnly refresh cookies, and optional authenticator-app two-factor authentication
- Other protections: CSRF protection, rate limiting, security audit logging, and access controls so users can reach only their own data (and household summaries they have joined)
No system is perfectly secure, and we cannot guarantee absolute security. If we learn of a breach
affecting your personal information, we will notify you as the law requires.
8. Data Retention
- Account data (profile, linked accounts, transactions, budgets, goals, and other content) is kept while your account is open, and deleted when you delete your account (Section 9).
- AI usage records: 180 days.
- Security and audit logs (which may include your email address and IP address): up to 365 days. These are kept even after you delete your account, for security and fraud prevention.
- Processed payment webhook records: 30 days.
- Free-trial record: to allow only one free trial per person, we keep a one-way SHA-256 hash of your normalized email address and the date your trial started. This hash is kept after you delete your account, so a new account with the same email does not get a second trial. It does not contain your email address in readable form or any other account data.
- Backups: we back up our database daily. Backups are deleted automatically on a rotating schedule, and on our current schedule the oldest copies are kept for up to about 90 days. After you delete your account, your data may remain in backups until they rotate out.
- Service providers keep data under their own retention policies, including analytics events, error reports, feedback issues, and payment records that Stripe, Apple, or Google must keep.
We may keep information longer where the law requires it or to resolve disputes.
9. Deleting Your Account
You can delete your account from Settings → Delete Account. For security, we ask you to re-confirm your identity:
your password (if you have one) and, if two-factor authentication is on, an authenticator code. You can also email
us to request deletion. Deleting your account:
- Removes your profile, linked accounts, transactions, budgets, goals, rules, household memberships, crypto wallets, AI usage records, feedback, and other content from our live database
- Asks Plaid or Teller to revoke our access to your linked banks
- Cancels any active Stripe subscription and deletes your Stripe customer record
- Deletes your sign-in identity at Firebase
The provider steps run right after deletion on a best-effort basis. Deletion does not
remove: security and audit logs, backups, and the free-trial hash (Section 8); your purchase record at
RevenueCat, Apple, or Google; or data already held by our analytics, error-reporting, and issue-tracking
providers. Deleting your account does not cancel an App Store or Google Play subscription.
Cancel those in your Apple or Google account settings.
10. Where Your Data Is Stored
The Service is intended for users in the United States and supports U.S. financial institutions only. Our
primary servers are located in the United States. For disaster recovery, we keep a continuously updated
copy of our database on a standby server hosted by Hetzner in Finland
(European Union). If our primary servers are unavailable, requests to the Service may be handled by that
standby server. Some service providers may also process data outside the United States.
11. Your Rights and Choices
- Access and export: view your data in the app, or use Download my data in Settings (any plan) to get a ZIP copy of the personal data we hold about you. Passwords, two-factor secrets, and bank or exchange connection tokens are left out of the download for your security. Plus and Pro subscribers can also export transactions as CSV or PDF from the Transactions page.
- Correction: update your profile, transactions, categories, budgets, and goals in the app
- Deletion: delete your account from Settings (Section 9)
- Withdraw consent: disconnect linked accounts, turn off alerts and notifications, or delete your account
Wherever you live, you can also ask us to access, correct, delete, or export a copy of your personal
information by emailing [email protected]. We will
verify your identity, usually by confirming you control your account email, before we act on a request.
Depending on where you live, you may have additional rights under applicable privacy laws.
12. Children's Privacy
The Service is not intended for anyone under 18. We do not knowingly collect personal information from
anyone under 18. If we learn that someone under 18 has given us personal information, we will delete it.
13. Changes to This Policy
We may update this privacy policy from time to time. We will post the updated policy on this page and
update the "Last Updated" date, and for significant changes we may also notify you by email or in the app.
14. Contact Us
If you have questions about this privacy policy or our data practices, or want to make a request, please
contact us at [email protected].
← Back to Home