Privacy policy
Summary
- Sapient Atoms Ledger is a private ledger for one household. Its only users are people in that household: today only the owner, and later perhaps another member of the household. It has no public sign-up.
- People in the household may sign in with Google. Beyond sign-in, it connects only to the owner's own Google account, for encrypted backups in Google Drive, a Finance calendar, a Ledger task list and a Gmail add-on.
- It never sells Google data, never uses it for advertising or for credit or lending decisions, and never uses it to train AI models.
- Access can be removed at any time at myaccount.google.com/permissions.
The ledger is being built. Every Google feature below is marked "planned": as of the date above, none is running yet. This policy describes how each will work, and it will be updated before any feature handles Google data differently from what it says here.
Who this policy covers
This policy covers Sapient Atoms Ledger, the web application at ledger.sapientatoms.com, its background jobs, its Gmail add-on and the setup tests described below. One person runs it for their own household; it is not a company. Google data comes only from the Google account of a person in that household who connects it. If another member of the household is given access and signs in with Google, the sign-in terms below apply to that person's account too.
What Google data the ledger accesses, and why
Sign in with Google (planned)
- Permissions
openid,emailandprofile: the basic sign-in permissions.- What it reads
- The name, email address, profile picture and Google account ID.
- Why
- To recognize a member of the household when they sign in.
- What it keeps
- The email address, the Google account ID and the name, in the ledger's user record. The profile picture is not kept.
Google Drive: encrypted backups (planned)
- Permission
https://www.googleapis.com/auth/drive.file: access only to files the ledger creates, or files the owner opens with it.- What it does
- Each night it saves a copy of the ledger's database to the owner's Drive as a new, dated file, encrypted before it leaves the server. Before anything is permanently deleted from the ledger, a backup copy of it goes to the same folder, encrypted the same way. Old backups are removed on a schedule.
- What it reads
- Its own backup files' names, dates, sizes and checksums, to check each upload and to remove old ones; and the Drive's storage totals (space used and the limit), to warn the owner before the Drive fills up. Restoring a backup is done by hand: the owner downloads the file and decrypts it.
- What it cannot see
- Any other file in the owner's Drive.
Google Calendar: the Finance calendar (planned)
- Permission
https://www.googleapis.com/auth/calendar.app.created: access only to calendars the ledger creates.- What it does
- Creates one calendar named Finance and keeps events on it for bill due dates, statement closing dates, promotion deadlines, estimated tax dates, tax election deadlines, subscription renewals, bank reconnection dates, filing deadlines, and dates when the cash forecast falls short. An event's title may include a payee and an amount from the ledger. Each event carries a ledger reference number in its private properties, and up to five reminders.
- What it reads
- Only the events on the Finance calendar, to keep them in step with the ledger.
- What it cannot see
- The owner's other calendars and their events.
Google Tasks: the Ledger task list (planned)
- Permission
https://www.googleapis.com/auth/tasks. Google offers no Tasks permission limited to one list, so this one covers every task list in the account.- What it does
- Creates a task list named Ledger with tasks only the owner can do: reconnect a bank, upload a statement, resolve items waiting for review, or approve a month-end close. Due dates are dates only. It checks those tasks for completion, and closes a task itself when it sees the work done, for example when the expected payment posts.
- What it reads
- Only the Ledger list and its tasks. It remembers the list it created, so it never looks through the others, and it does not read, change or delete any other list.
Gmail add-on (planned)
- Permissions
- Gmail's add-on permissions, which let an add-on read only the message open on screen while the owner is using the add-on, plus the owner's email address to identify the owner to the ledger. The exact permissions will be listed here before the add-on is installed.
- What it does
- When the owner opens a message and opens the add-on, it shows matching ledger transactions and records. With one click the owner can link the email to a transaction, a business or another ledger record. To suggest matches, it compares the message's sender, subject and text with rules the owner has set.
- What it reads
- The open message's sender, subject, date and content, only while the owner uses the add-on on that message.
- What it never does
- Scan the mailbox, read other messages in the background, send email, or delete email.
- What it keeps
- For a message the owner links: its Gmail message ID, sender, subject and date and, when the owner chooses, the message text or an attachment kept as a receipt. For a message the owner does not link, those details are used only to find matches while the add-on is open, and are not kept.
Setup tests (temporary, planned)
Before the ledger's server holds any Google connection, a small test program on the owner's own computer proves that a connection to this app keeps working past its eighth day. It runs outside the ledger for about two weeks, and each of its authorizations is revoked when the test ends.
- Permissions
- The main test authorization has the same three permissions as the features above:
drive.file,calendar.app.createdandtasks. A second one, from the ledger's development version (Sapient Atoms Ledger Dev), has the same three and serves as a control. An optional third one has onlyhttps://www.googleapis.com/auth/gmail.labels, which covers Gmail's labels and never the messages themselves. - What it reads
- With the first two: only the Drive's storage totals. With the optional Gmail one: the list of Gmail labels, only to confirm that the authorization works. Label names are neither kept nor shown; only how many there are.
- What it changes
- Nothing. It creates no files, calendars, tasks or labels.
- What it keeps
- The authorizations and the date and result of each check, in a folder on the owner's computer that only the owner's user account can open. Revoking an authorization deletes its stored copy; the dates and results stay as the test's record.
How Google data is used
Google data is used only to provide the features above to the household that uses them. It is never:
- sold or rented;
- used for advertising, including personalized or retargeted ads;
- used to decide on credit or lending;
- used to develop, improve or train AI or machine-learning models;
- used or shared for any purpose unrelated to these features.
No person outside the household reads Google data held by the ledger, except with the agreement of the person the data belongs to, for security, or where the law requires it.
AI: the ledger's automatic transaction classifier works from bank and card records, not from Google data. When the owner asks an AI assistant connected to the ledger a question whose answer needs Google-derived data, such as which email was linked to a charge, the ledger returns only what that request needs, labeled as untrusted text. Google-derived data goes only to AI services set not to use it for model training: today that is Anthropic's Claude, with its model-training setting off on every account connected to the ledger.
Limited Use disclosure
Sapient Atoms Ledger's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Where it is stored, and how it is protected
- The ledger's database is hosted by Neon (managed PostgreSQL) in Amazon Web Services' US East (Ohio) region, us-east-2, in the United States. Neon encrypts stored data.
- The ledger's server (planned) runs on Render in its Ohio region, in the United States.
- Backups are encrypted on the server before they are saved to the owner's Drive. The key that decrypts them is kept offline by the owner, not on the server.
- Google access tokens are stored in the ledger's database, encrypted by the application with a key held only in the server's settings, never in the database. The encrypted backups therefore contain them too, still encrypted.
- The setup test's authorizations stay on the owner's own computer, outside the ledger, in a folder only the owner's user account can open, and are revoked when the test ends.
- In transit, every connection is encrypted with TLS (HTTPS for web traffic).
- Access requires signing in. Every change is recorded with who made it, and AI agents act only with the permissions the owner grants.
Who it is shared with
Google data is not sold, and is not shared with advertisers or data brokers. It reaches only:
- Service providers that run the ledger, which handle it only to run the ledger: Neon (database hosting) and Render (application hosting, planned). Cloudflare provides the domain's name service and hosts these two pages. Sentry (error reports, planned) is set up to leave out financial details and Google content. Better Stack (uptime and job check-ins) and Resend (alert emails to the owner, planned) receive no Google content.
- AI assistants (today Anthropic's Claude), only as described above and only when the owner asks.
- Google itself, since the features run inside the owner's own Google account.
- Authorities, if the law requires it, or to protect against fraud or a security threat.
How long it is kept
- Sign-in details: while the user's ledger account exists.
- Google access tokens: while the connection is in use. They stop working as soon as access is removed in the Google Account, and the ledger's daily check then tells the owner that the connection is broken.
- Setup test authorizations: about two weeks; each is revoked and its stored copy deleted when the test ends.
- Drive backups: the ledger removes its older backups on a schedule. The planned schedule keeps nightly backups for 90 days and one backup a month for 7 years; it is set when backups are built. The copy saved before a deletion is kept for a period not yet set; this policy will state it before deletions are possible. The files are in the owner's Drive, so the owner can delete them at any time.
- Calendar events and tasks: they stay in the owner's Google account. The ledger updates or removes its events, and closes its tasks, as the underlying items change. Deleting the Finance calendar or the Ledger list removes them.
- Linked email details: kept with the ledger record they support, for as long as the household keeps that financial record. The ledger's audit history keeps its own copy permanently (see "Delete data" below).
Your choices: removing access and deleting data
- Remove access: go to myaccount.google.com/permissions and remove Sapient Atoms Ledger (it may be listed as sapientatoms.com). The ledger's connection stops at once.
- Gmail add-on: it has its own entry on the same page, under the add-on's name; remove that too, and uninstall the add-on from Gmail's add-on settings. Uninstalling it alone does not remove its access.
- Delete data: email the contact address below to ask for the Google-derived data the ledger holds to be deleted. The ledger then removes those details from its working records, stops using them, and deletes its Google tokens. Copies remain in two places, both readable only by the household:
- the ledger's permanent audit history, which keeps the original record of each email link as it arrived and a history of every change. Like a business's audit trail, it is never edited or deleted;
- the encrypted backups in the owner's Drive, until each backup reaches the end of its retention: up to 90 days for nightly backups and up to 7 years for monthly ones under the planned schedule. The deletion itself first saves an encrypted copy of what it removes to the same folder, kept for the period described above.
- Files, events and tasks in Google: the backup files, the Finance calendar and the Ledger list stay in the Google account until the owner deletes them. Removing the ledger's access does not delete them.
Other data
The ledger also holds the household's financial records, which come from banks (through bank connections) and from statements. This policy is about Google user data, as Google requires; those records are private to the household and protected the same way.
Children
The ledger is not directed to children and does not knowingly collect data from anyone under 13.
Changes to this policy
Changes are published on this page with a new date. Before Google data is used in any new way, the change is published here, and the people in the household who use the ledger are told and asked to agree.
Contact
Questions or requests about this policy: privacy@sapientatoms.com