Privacy
Your writing stays yours. Here is exactly what that means.
This page covers the Ledgable apps (iPhone, iPad, Apple Watch, Android) and this website. The short version: the apps send nothing to us, and the site keeps only what a support ticket or a comment needs.
The apps
We run no server for your data. Your day pages, notes, ink, contacts, mail, books and feed subscriptions live on your device. If you turn on sync, they go to a place you choose and control — your own WebDAV server or your own Google Drive — as plain files. We never see them.
Accounts you add are yours. A mail account talks to your mail provider directly from the app. A feed account talks to your feed server. A WordPress site talks to your site. Credentials are stored on the device in the system keychain and are sent only to the service they belong to.
Ask my Ledger uses a key you supply. When you ask the assistant a question, the text it needs is sent to the AI provider whose key you entered, under that provider’s terms. Nothing is sent until you ask, and nothing is sent to us.
Permissions, and what each is for. Calendar: to show your events on the day’s schedule. Reminders: to turn handwritten tasks into Reminders. Contacts: to fill your rolodex from your address book, only when you choose to import. Photos: to place a picture on a page, and to save a page image you export. Microphone: to record voice captures. Notifications: new-article alerts, asked for only once a feed server is set up. Each can be refused and the app keeps working without it.
No analytics, no advertising, no tracking. The apps contain no analytics library and no advertising library, and make no request to any server other than the ones you configured.
Crash reports. If you opted in to sharing crash data with Apple or Google, they may pass an anonymous crash log to us. That is the only telemetry we ever receive, and only through the store.
This website
Reading it stores nothing about you beyond ordinary server logs (address, browser, page, time), kept by our host for security and deleted on their schedule.
A support ticket stores the name and email you give, the ticket text, and any screenshot you attach, so we can answer you. We keep it while the conversation is open and for a reasonable time afterwards to recognise a repeat problem. Ask and we delete it.
An account on this site (made to open a ticket) stores a username, an email address and a hashed password. If you log in, WordPress sets cookies to keep you logged in; they carry no personal data and expire on their own.
Comments, if enabled, store what you typed, your name and email, and your address and browser string for spam detection.
We do not sell, share or rent any of this to anyone. No third-party analytics runs on this site.
Your rights, and who to ask
You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted, at any time. Open a ticket on the Support page or write to the address on the Support page. We answer within a few days.
Ledgable is made by Michael Joel Hall. This page was last revised on 3 September 2026.
Ledgable — cozy and transgressive