family-ledger

Private household accounting

Privacy policy

Policy version: October 2, 2026

This policy describes the current local Gmail intake configuration of family-ledger, a private household accounting tool.

Information accessed and stored

The application accesses the authorized mailbox address, selected email metadata and message contents, and attached statement PDFs. It retains source messages, original and decrypted statement files, extracted transaction details, accounting entries and audit records on operator-controlled storage.

Google authorization

The application requests the Gmail read-only permission, gmail.readonly. This permission covers the mailbox, not just statements. Configured message queries and sender rules limit what the application retrieves. It does not send, delete, archive or mark messages as read.

Purpose and access

Data is used to prepare household accounting records, trace entries back to statements, identify duplicates and support corrections. Access is intended for the operator and authorized household members. The operator manages access to the computer, storage and backups.

Sharing and processing

Statement data is not published on this website, sold, used for advertising or used to train general-purpose AI models. The current configuration has no external AI model enabled. Corrections may be retained as local categorization rules. Any future external processing requires updated disclosures and authorization before it is enabled.

family-ledger's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and retention

OAuth credentials are stored outside the source repository in private local files. PDF passwords are stored in a local encrypted vault. This does not mean all statement data or backups are encrypted. There is currently no automatic deletion schedule: data remains until the operator deletes it, including relevant backups.

Revoking access and deleting data

You can revoke the application's Google access through Google Account connections. Revocation stops future authorized access but does not delete data already stored locally. Contact the operator to request removal of locally retained records and backups.

Website visitors

The informational pages include no application analytics, advertising, forms or third-party scripts. The hosting provider processes requests needed to serve the pages under its own privacy practices. The website is separate from the private accounting data store.

Contact and changes

Questions and deletion requests: wli.agent.tw@gmail.com. This policy must be updated before changes to data use or sharing take effect.