Privacy Notice

Last updated 11 September 2026

What we collect, where it lives, who else touches it, and what you can ask us to do about it. Written to be specific about this product rather than generic about software.

This notice describes what the software actually does, checked against the code rather than assembled from a template. It has not been reviewed by a lawyer in your jurisdiction. Questions, corrections and requests: privacy@mahiledger.com.

Two kinds of information, and our different roles

This distinction runs through everything below, so it comes first.

  • Information about you, as our user. Your account and how you use MahiLedger. We decide what to collect and why, and this notice is our account of that.
  • Information inside your books, about other people. Your customers, your suppliers, names on imported bank lines, colleagues you invite. You decide what goes in and why; we hold it and act on your instructions. We don't mine it, analyze it, or use it for anything except running the product for you. If one of those people asks us about their data, we'll point them to you.

What we collect about you

  • Account. Your email address, and your display name and profile picture if you sign in with Google. A unique account id. Whether your email is confirmed.
  • Passwords — actually, no. If you use a password it is held by Firebase Authentication. It never reaches this application in any form, and we cannot read it, recover it, or tell you what it is.
  • Workspaces. Which companies you belong to, your role in each, who invited you, and any accounting-firm engagements.
  • Billing. Your plan, your subscription's status and renewal date, and Stripe's identifiers for your customer and subscription. Not your card.
  • Activity. An audit trail of material actions — who posted, reversed, paid, reconciled or locked, and when.
  • Technical logs. Standard server logs kept by our hosting: IP address, timestamps, and error diagnostics. Used to keep the service running and to investigate faults and abuse.
  • What you send us. Anything in an email to support or privacy.
  • Provider waitlist. If you join it, your provider type, organization, name, work email, optional message, consent time and submission time. Joining the waitlist does not create a MahiLedger account or a marketplace listing.

What's in your books

Whatever you put there. In practice that usually includes customer and supplier names and email addresses, invoice and bill detail, payments, imported bank transaction descriptions (which routinely name whoever you paid), your company's address, and any files you attach to a document.

Why we hold it

  • To run the product — the reason nearly everything above exists.
  • To take payment for paid plans.
  • To send you what the product needs to send — invitations, email sign-in links, address confirmation, and notices about your account. These aren't marketing and you can't unsubscribe from them while you hold an account, because they are the product working.
  • To keep it secure and investigate abuse.
  • To run the provider waitlist — understand which services are interested, shape the provider programme and contact people who explicitly joined it.
  • To meet our own legal obligations, such as keeping billing records.

We do not sell your information, and we do not share it for advertising. There is no advertising in MahiLedger.

Tracking, or the lack of it

There is no analytics in MahiLedger. No Google Analytics, no product analytics, no session recording, no advertising or social pixels, and no cookie banner because there are no tracking cookies to consent to. Signing in stores what's needed to keep you signed in, and that's the extent of it.

The emails we send carry no tracking pixels and no images — we don't know whether you opened one.

Where it's stored, and who else touches it

MahiLedger runs on Google Cloud in the United States. Specifically: your books are in the us-central1 region (Iowa), files you upload are in us-east1 (South Carolina), and the servers that run the application are in us-east4 (Virginia). If you're using MahiLedger from elsewhere, your data is being transferred to and stored in the US.

We have no EU, UK or Asia-Pacific region today. If you need data residency outside the US, we can't offer it yet, and it's better you know that before you start than after.

These are everyone who receives any of it:

WhoWhat reaches themWhere
Google Cloud / Firebase Everything — accounts, your books, uploaded files, and the servers that run the product. United States — Iowa, South Carolina and Virginia
Stripe Your email address, your workspace's id, and the plan you chose. Nothing from your books. Card details go straight to Stripe and never reach us. United States
Resend Everything the product emails on your behalf: invitations, and the invoices, credit notes, statements and payment reminders you send to your customers — which carry that customer's name and email address, the document's line items and the balance outstanding. Also the notices we send you about your own account. United States

That's the complete list. We'll update it here before adding anyone.

Two things that are deliberately visible to others

  • A published directory listing. If you list your firm or your business in the marketplace, the details on that listing — name, location, specialties, description, website and contact email — become visible to other MahiLedger users. Nothing from your books is ever part of a listing, and listing is off until you turn it on.
  • A listing's logo. So that it displays to people who aren't in your workspace, a logo is served from a link that works without signing in. Anyone who has that link can view the image for as long as the file exists. Delete the logo to revoke it. Don't use an image you wouldn't want public.

Tools you connect

MahiLedger can be driven by other software, including AI assistants, using your credentials. Anything you authorize can read and write your books exactly as you can, and whatever it does with what it reads is governed by that tool's privacy policy, not this one. Connect only what you trust.

How long we keep things

  • Your books: for as long as your workspace exists. We don't delete them on a timer.
  • The audit trail: kept for at least as long as the law where your business is registered requires business records to be kept. Your plan can extend that window; it cannot shorten it. Where we don't know your country, we apply the longest period we know of rather than the shortest.
  • What the sweep actually removes: change history for contacts, budgets and imported bank lines, and nothing else. Attribution for anything posted to the ledger — who raised an invoice, who posted an entry, who reconciled an account — is never deleted, because the audit trail is the only place we record it.
  • Demo workspaces: deleted seven days after they're created, including the temporary account created with them.
  • Your account: until you ask us to delete it.
  • Provider waitlist submissions: until the provider programme opens, for no longer than 24 months, or until you ask us to remove yours.
  • Billing records: as long as tax and accounting law requires us to keep them.

Your choices, and how to use them

Whoever and wherever you are, you can ask us to give you a copy of what we hold about you, correct it, or delete it. Email privacy@mahiledger.com from your account address and we'll respond within 30 days.

What you can do right now, without asking:

  • Export your general ledger, trial balance, receivables and payables agings, and audit log as CSV, from inside the app.
  • Change your display name and email through your sign-in provider.
  • Remove a team member, or end an engagement with a firm, which ends their access.

What still needs an email, honestly:

  • Deleting your account or a workspace. There's no button for this yet. We do it by hand when you ask, within 30 days, and we'll confirm when it's done.
  • A single archive of everything. Still by email — there's no button for it yet — but it is now one operation rather than an assembly job: we produce a complete machine-readable copy of every record in your workspace, and it tells us plainly whether any part of it could not be read.

One limit worth stating plainly: if you're a member of a company's workspace, its books belong to that company, not to you. We can remove you, but we can't delete a company's accounting records at the request of one of its team members.

If you're in California

In the past 12 months we've collected the categories described above: identifiers (name, email, account id, IP address), commercial information (your plan and subscription), and internet activity (server logs). We collect them from you and from your use of the product, for the purposes listed under "Why we hold it".

We have not sold or shared personal information, and we do not process it for cross-context behavioral advertising. We don't knowingly collect sensitive personal information beyond what's listed. You have the right to know, delete, correct, and to not be discriminated against for exercising any of them — exercise them at the address above. An authorized agent may act for you with written permission. Whether the CCPA formally applies to us depends on thresholds we may not meet; we'll honor these requests either way.

Security

Specifically, rather than reassuringly:

  • Traffic is encrypted in transit, and data is encrypted at rest by Google Cloud.
  • Every workspace is separately scoped, and that scope is checked on the server on every read and every write — not by filtering a shared pile in the browser.
  • Uploaded files are readable only by members of the workspace they belong to, enforced by the storage layer itself, and capped at 10 MB each.
  • Passwords are held by Firebase Authentication and never by this application.
  • Access to a workspace comes only from a membership or an accepted engagement, and revoking either revokes the access.

No system is perfectly secure. If something goes wrong that affects your data, we'll tell you and tell you what we know. If you think you've found a vulnerability, email security@mahiledger.com — we'd rather hear it from you.

Children

MahiLedger is a business tool and isn't for anyone under 18. We don't knowingly collect information from children. If you believe a child has given us information, email us and we'll delete it.

Changes to this notice

When we change it, the date at the top changes. If a change materially affects how we handle your information, we'll email the address on your account before it takes effect.

Contact

Privacy requests and questions: privacy@mahiledger.com
Security: security@mahiledger.com
Anything else: support@mahiledger.com