Privacy Policy
PocketLedger helps you record, organize, search, and review expenses through ChatGPT and the PocketLedger web app. This policy explains what data is handled, why it is used, and how you stay in control.
Last updated: June 12, 2026
Information PocketLedger collects
When you use PocketLedger, the service may collect and store account information needed to operate your account, including your email address, password hash if you sign in with email, profile name if provided, locale, timezone, default currency, and account preferences.
PocketLedger also stores the financial records you create, including transaction amounts, currencies, merchants, categories, dates, notes, parsed expense text, action history, and related metadata needed to search, edit, undo, restore, and report your spending.
OAuth and connected app data
When you connect PocketLedger to ChatGPT or another MCP-compatible assistant, PocketLedger may store OAuth and integration records such as connected client names, granted scopes, consent records, access tokens, refresh tokens, token rotation events, and token revocations.
Connected assistants can only use the tools and scopes you approve. Available scopes may include account access, transaction reading, transaction writing, and report reading.
Google Sign-In
If you choose Continue with Google, PocketLedger uses Google OAuth only to verify your identity and receive basic profile information such as your email address, name, and Google account subject ID. Your Google password is never shared with PocketLedger.
PocketLedger does not sell Google user data or use Google user data for advertising. Google user data is used only to authenticate your PocketLedger account and provide account access.
Cookies and analytics
PocketLedger may use essential cookies for authentication and security. If analytics or error monitoring tools are used, they are used to understand reliability, errors, and service performance, not to sell personal finance data.
Operational and security logs
PocketLedger may keep operational logs required for security, idempotency, audit trails, debugging, abuse prevention, fraud prevention, and service reliability. These logs help prevent duplicate write actions, investigate errors, and protect user accounts.
How PocketLedger uses data
- To provide expense logging, categorization, search, reports, summaries, undo, restore, and account features.
- To authenticate users, secure accounts, honor OAuth scopes, and manage connected AI assistant access.
- To prevent duplicate or accidental write actions through idempotency and audit-friendly workflows.
- To respond to export, deletion, privacy, and support requests.
- To improve reliability, detect abuse, debug issues, and maintain service integrity.
AI assistant integrations
When you connect PocketLedger to ChatGPT, ChatGPT can call only the PocketLedger tools allowed by your approved OAuth scopes. Read-only scopes may allow account, category, transaction, or report access. Write scopes may allow creating, updating, deleting, restoring, or undoing transactions.
You can disconnect an AI client by revoking OAuth access, signing out from the connected flow, or contacting support.
Data sharing
PocketLedger does not sell personal finance data. Data may be processed by infrastructure providers required to host, secure, monitor, email, log, and deliver the service. PocketLedger may also disclose information when required by law or when necessary to protect users, prevent abuse, or defend the service.
Security controls
- OAuth authorization code flow with PKCE for ChatGPT and MCP authorization.
- Scoped permissions so connected apps request only the access they need.
- Refresh token rotation and token revocation support.
- HTTPS-focused production settings and secure cookie configuration in production.
- Idempotency checks for sensitive write actions.
- Undo, restore, and audit-friendly workflows for finance changes.
- Operational logs for sensitive transaction actions and abuse prevention.
Your controls
- Request a data export from Export your data while signed in, or from Profile → Settings.
- Request account deletion from Delete your account while signed in, or from Profile → Settings.
- Update account preferences from Profile → Account.
- Disconnect AI clients by revoking OAuth access in Settings → AI connections or contacting support.
- Contact PocketLedger about privacy questions at [email protected].
Retention and deletion
Account deletion requests are scheduled with a safety window before hard deletion. PocketLedger currently schedules hard deletion after 30 days. Some security, audit, and transaction integrity records may be retained where required to prevent abuse, resolve disputes, meet legal duties, or preserve an accurate audit trail.
Children
PocketLedger is not intended for children under 13 or for anyone below the minimum age required in their jurisdiction.
Changes to this policy
PocketLedger may update this policy as the product changes. Material changes will be reflected on this page and, when appropriate, communicated through the app or email.
Contact
For privacy, account, export, deletion, or security questions, contact [email protected].