Legal

Ledger privacy policy

Effective date: 2 August 2026

Controller: Neuronetix, operating Ledger. This notice applies to Ledger only. Established in Belgium. Neuronetix is the data controller for the personal data described below.

Contact: miguel@neuronetix.be

1. What Ledger is

Ledger is a Slack app that turns a Slack message into a tracked decision or commitment. This policy covers the data Ledger itself collects when a workspace installs it, and the data collected by this website.

2. What we collect

  • Slack workspace and account identifiers: your team ID, channel IDs, and the Slack user IDs of the person who records an entry and the person assigned as its owner.
  • The Slack OAuth access token issued when your workspace installs Ledger, scoped to: commands, chat:write, chat:write.public, im:write, users:read.
  • The content you explicitly record: the text of a Slack message logged as a decision or commitment, plus any category, due date, rationale, alternatives, blocker, dependency, or scope you add when recording it.
  • A permalink to the original Slack message an entry was recorded from.
  • If you subscribe to a paid plan: your workspace identifier, a subscription ID and customer ID issued by our payment provider, plan, and billing period dates. Payment card details are collected and processed entirely by Paddle.com Market Ltd, our payment provider and merchant of record — Ledger never receives or stores your card number.
  • Display names, resolved at the moment a briefing is generated using Slack's own API. These are used only to render that briefing and are cached in memory, not stored in our database.
  • Standard server logs generated by normal operation: timestamps, error messages, and workspace or event identifiers.

3. What we do not collect

We do not read or store Slack messages that have not been explicitly recorded with a Ledger shortcut. We do not collect data for advertising, and we do not sell personal data. This website does not use tracking cookies or third-party analytics.

4. Why we process this data

  • To operate the service: recording decisions and commitments, sending reminders, and running the command surface and briefing.
  • To bill you for a paid plan.
  • To keep the service secure and to diagnose problems.

Our legal bases are: performance of our contract with you (operating the service and billing paid plans), our legitimate interest in keeping the service secure and diagnosing faults, and compliance with legal obligations such as tax record-keeping.

Ledger has no special handling for sensitive personal data (health, biometric, or similar categories). Please don't record this kind of information as decision or commitment text.

5. Where data is stored

  • Application data: PostgreSQL, hosted on a Hostinger virtual private server located in the European Union.
  • Billing and payment data: Paddle.com Market Ltd. See Paddle's own privacy policy at paddle.com/legal/privacy for how they handle this.
  • Anything outside what Ledger explicitly records remains governed by Slack's own privacy policy.

Data is held within the European Union. Where a processor transfers data outside the EU/EEA, that transfer relies on an adequacy decision or Standard Contractual Clauses.

6. Who we share data with

  • Slack Technologies, LLC — the platform Ledger operates within.
  • Paddle.com Market Ltd — merchant of record for the sale of paid plans: payment processing, subscription management, tax compliance and invoicing, for paying workspaces only.
  • Hostinger International Ltd — infrastructure hosting, with no independent access to your data.
  • Professional advisers (legal, accounting) and public authorities, where required by law.

We do not share data with any other third party, and we do not sell personal data.

7. Retention

Recorded decisions and commitments, and your workspace's OAuth token, are kept for as long as Ledger remains installed. Uninstalling Ledger revokes and deletes the stored OAuth token immediately. Previously recorded decisions and commitments are not deleted automatically on uninstall, so that a reinstalled workspace keeps its history; they are deleted on request. You can request deletion of your workspace's data at any time by emailing miguel@neuronetix.be, and we will action it within 30 days. Billing records are retained by Paddle for as long as tax and accounting law requires.

8. Security

We apply appropriate technical and organisational measures to protect this data: traffic is encrypted in transit over TLS, Slack OAuth tokens are stored server-side and never exposed to the browser, access to production systems is restricted to the operator, and Slack request signatures and payment webhook signatures are verified before any payload is processed.

9. Your rights

If you are in the EU/EEA or the UK, you have the right to access, rectify, erase, restrict or port your personal data, to object to processing carried out on the basis of our legitimate interests, and to withdraw consent where processing relies on it. You may also lodge a complaint with your supervisory authority — in Belgium, the Data Protection Authority (gegevensbeschermingsautoriteit.be). To exercise any of these rights, email miguel@neuronetix.be; we respond within one month.

10. Cookies

This website sets no analytics or marketing cookies. Paddle's checkout sets cookies strictly necessary to process your payment.

11. Children

Ledger is a workplace tool. We do not knowingly collect data from children, and it is not directed at them.

12. Changes to this policy

We'll update the effective date above when this policy changes and, for material changes, do our best to notify installed workspaces directly.

13. Contact

Questions about this policy or your data: miguel@neuronetix.be.