Privacy policy

Sapient Atoms Ledger. Effective October 3, 2026. Last updated October 3, 2026.

Summary

The ledger is being built. Every Google feature below is marked "planned": as of the date above, none is running yet. This policy describes how each will work, and it will be updated before any feature handles Google data differently from what it says here.

Who this policy covers

This policy covers Sapient Atoms Ledger, the web application at ledger.sapientatoms.com, its background jobs, its Gmail add-on and the setup tests described below. One person runs it for their own household; it is not a company. Google data comes only from the Google account of a person in that household who connects it. If another member of the household is given access and signs in with Google, the sign-in terms below apply to that person's account too.

What Google data the ledger accesses, and why

Sign in with Google (planned)

Permissions
openid, email and profile: the basic sign-in permissions.
What it reads
The name, email address, profile picture and Google account ID.
Why
To recognize a member of the household when they sign in.
What it keeps
The email address, the Google account ID and the name, in the ledger's user record. The profile picture is not kept.

Google Drive: encrypted backups (planned)

Permission
https://www.googleapis.com/auth/drive.file: access only to files the ledger creates, or files the owner opens with it.
What it does
Each night it saves a copy of the ledger's database to the owner's Drive as a new, dated file, encrypted before it leaves the server. Before anything is permanently deleted from the ledger, a backup copy of it goes to the same folder, encrypted the same way. Old backups are removed on a schedule.
What it reads
Its own backup files' names, dates, sizes and checksums, to check each upload and to remove old ones; and the Drive's storage totals (space used and the limit), to warn the owner before the Drive fills up. Restoring a backup is done by hand: the owner downloads the file and decrypts it.
What it cannot see
Any other file in the owner's Drive.

Google Calendar: the Finance calendar (planned)

Permission
https://www.googleapis.com/auth/calendar.app.created: access only to calendars the ledger creates.
What it does
Creates one calendar named Finance and keeps events on it for bill due dates, statement closing dates, promotion deadlines, estimated tax dates, tax election deadlines, subscription renewals, bank reconnection dates, filing deadlines, and dates when the cash forecast falls short. An event's title may include a payee and an amount from the ledger. Each event carries a ledger reference number in its private properties, and up to five reminders.
What it reads
Only the events on the Finance calendar, to keep them in step with the ledger.
What it cannot see
The owner's other calendars and their events.

Google Tasks: the Ledger task list (planned)

Permission
https://www.googleapis.com/auth/tasks. Google offers no Tasks permission limited to one list, so this one covers every task list in the account.
What it does
Creates a task list named Ledger with tasks only the owner can do: reconnect a bank, upload a statement, resolve items waiting for review, or approve a month-end close. Due dates are dates only. It checks those tasks for completion, and closes a task itself when it sees the work done, for example when the expected payment posts.
What it reads
Only the Ledger list and its tasks. It remembers the list it created, so it never looks through the others, and it does not read, change or delete any other list.

Gmail add-on (planned)

Permissions
Gmail's add-on permissions, which let an add-on read only the message open on screen while the owner is using the add-on, plus the owner's email address to identify the owner to the ledger. The exact permissions will be listed here before the add-on is installed.
What it does
When the owner opens a message and opens the add-on, it shows matching ledger transactions and records. With one click the owner can link the email to a transaction, a business or another ledger record. To suggest matches, it compares the message's sender, subject and text with rules the owner has set.
What it reads
The open message's sender, subject, date and content, only while the owner uses the add-on on that message.
What it never does
Scan the mailbox, read other messages in the background, send email, or delete email.
What it keeps
For a message the owner links: its Gmail message ID, sender, subject and date and, when the owner chooses, the message text or an attachment kept as a receipt. For a message the owner does not link, those details are used only to find matches while the add-on is open, and are not kept.

Setup tests (temporary, planned)

Before the ledger's server holds any Google connection, a small test program on the owner's own computer proves that a connection to this app keeps working past its eighth day. It runs outside the ledger for about two weeks, and each of its authorizations is revoked when the test ends.

Permissions
The main test authorization has the same three permissions as the features above: drive.file, calendar.app.created and tasks. A second one, from the ledger's development version (Sapient Atoms Ledger Dev), has the same three and serves as a control. An optional third one has only https://www.googleapis.com/auth/gmail.labels, which covers Gmail's labels and never the messages themselves.
What it reads
With the first two: only the Drive's storage totals. With the optional Gmail one: the list of Gmail labels, only to confirm that the authorization works. Label names are neither kept nor shown; only how many there are.
What it changes
Nothing. It creates no files, calendars, tasks or labels.
What it keeps
The authorizations and the date and result of each check, in a folder on the owner's computer that only the owner's user account can open. Revoking an authorization deletes its stored copy; the dates and results stay as the test's record.

How Google data is used

Google data is used only to provide the features above to the household that uses them. It is never:

No person outside the household reads Google data held by the ledger, except with the agreement of the person the data belongs to, for security, or where the law requires it.

AI: the ledger's automatic transaction classifier works from bank and card records, not from Google data. When the owner asks an AI assistant connected to the ledger a question whose answer needs Google-derived data, such as which email was linked to a charge, the ledger returns only what that request needs, labeled as untrusted text. Google-derived data goes only to AI services set not to use it for model training: today that is Anthropic's Claude, with its model-training setting off on every account connected to the ledger.

Limited Use disclosure

Sapient Atoms Ledger's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Where it is stored, and how it is protected

Who it is shared with

Google data is not sold, and is not shared with advertisers or data brokers. It reaches only:

How long it is kept

Your choices: removing access and deleting data

Other data

The ledger also holds the household's financial records, which come from banks (through bank connections) and from statements. This policy is about Google user data, as Google requires; those records are private to the household and protected the same way.

Children

The ledger is not directed to children and does not knowingly collect data from anyone under 13.

Changes to this policy

Changes are published on this page with a new date. Before Google data is used in any new way, the change is published here, and the people in the household who use the ledger are told and asked to agree.

Contact

Questions or requests about this policy: privacy@sapientatoms.com