LedgerPDF disclosures

Privacy & Data Practices

Effective August 13, 2026

LedgerPDF has no Ledger Labs account, hosted binder service, product analytics, advertising, telemetry, or automatic update check. Opening and editing a binder does not send it to Ledger Labs LLC.

Files on your device

LedgerPDF reads source files you select and creates binders and exports at paths you choose. Hidden working, recovery, and lock files may exist beside an open binder and can contain client information. The app’s per-user data directory stores preferences and a recent-binder list, which can contain complete filesystem paths including client or engagement names.

LedgerPDF does not encrypt binder, export, working, or recovery files. Use device encryption, folder permissions, retention, backup, and secure-disposal controls approved by your firm. Uninstalling does not delete your binders and may leave preferences or recents until you remove the app-data directory.

Optional agent access

Agent access is not required. Live access to the open binder is off at each launch and, when enabled, uses a local Unix socket or Windows named pipe—not a network port—with a fresh random 256-bit token. Separately, folders approved under Agent access grant persistent standalone read/write access inside those folders. That approval remains in effect when live access is off and when the app is closed, until you withdraw it.

Within approved folders, an MCP client can receive paths, filenames, page text, OCR, spreadsheet cell values, mark and tape metadata, and other binder content, including tax identifiers. LedgerPDF does not directly send that data across a network, but a hosted AI provider may receive whatever your separate MCP client sends it. That provider’s privacy, retention, training, security, and contract terms apply. Removing a folder affects later requests; it cannot recall information already received.

Website and downloads

ledgerpdf.com is a static site hosted by Vercel. Ledger Labs LLC has not added accounts, forms, advertising, product analytics, tracking pixels, or third-party web fonts. Vercel may process ordinary request information needed to serve the site under its privacy policy.

GitHub hosts the source repository, issue tracker, and release downloads. GitHub’s privacy statement applies when you use those services.

Messages, reports, and deletion

Ledger Labs LLC receives information you choose to send in a message or report. Never send real client files, screenshots, filenames, tax identifiers, credentials, or extracted page text; use synthetic examples. You control deletion of local sources, binders, exports, recovery files, and backups. Ledger Labs does not operate a cloud copy it can delete for you. Information sent to an MCP client, AI provider, GitHub, Vercel, email provider, or another third party is governed by that party and your arrangement with it.

Read the repository’s full privacy and data-practices document and detailed data flow. LedgerPDF is intended for professional use and is not directed to children. Questions may be sent to info@ledgerlabs.co.