LedgerMCP: Data Retention and Disposal Policy
LedgerMCP, LLC
Effective date: July 7, 2026
Last reviewed: July 7, 2026
Review cadence: Reviewed at least annually and upon any material change to systems, data handling, or applicable law.
1. Purpose
This Data Retention and Disposal Policy defines how LedgerMCP, LLC ("the Company")
retains, and securely disposes of, the information it processes, including
end-user financial account data obtained through Plaid, authentication data, and
the double-entry bookkeeping records the platform maintains. Its purpose is to
ensure that data is kept only as long as there is a legitimate business or legal
need, that it is disposed of securely when that need ends, and that these
practices comply with applicable data-protection laws.
2. Scope
This policy applies to all Company systems and to all data the Company stores or
processes on behalf of its users, whether held in the production database, file
storage, backups, or application logs, and whether processed directly by the
Company or by a subprocessor acting on its behalf.
3. Guiding Principles
- Retain only as needed. Data is retained only for as long as required to
provide the Service, to meet a legal or regulatory obligation, or to resolve
disputes and enforce agreements.
- Data minimization. The Company collects and keeps the minimum data needed
to operate the Service. It does not store end-user bank login credentials.
- User control. Users can export their data at any time and can request
deletion of their account and associated data.
- Secure disposal. When data reaches the end of its retention period or a
deletion request is fulfilled, it is disposed of using methods appropriate to
its sensitivity so that it is not practically recoverable.
- Compliance. Retention and disposal practices are designed to comply with
applicable privacy laws and are reviewed periodically.
4. Retention Schedule
The Company retains data according to the following schedule. "Life of account"
means for as long as the user's account remains active.
| Data category | Examples | Retention period | Disposal method |
|---|---|---|---|
| Account & authentication data | Email address, session records | Life of account; removed within 30 days of a verified deletion request | Logical deletion from the primary database |
| Bookkeeping & ledger records | Chart of accounts, journal entries, categorized transactions, tags, notes | Life of account; purged on account deletion (subject to legal holds) | Logical deletion; postings are immutable during account life and corrected by reversing entries, not edited in place |
| Plaid-derived financial data | Transactions, balances, account/routing identifiers | Life of account; import stops immediately on bank disconnect | Logical deletion; imported records remain in the user's books unless the user deletes them |
| Plaid access tokens | Encrypted item access tokens | Invalidated immediately on bank disconnect; destroyed on account deletion | Plaid item-removal API call + deletion; crypto-erasure of the encrypted value |
| Uploaded files | Receipts and attachments | Life of account; removed on account deletion | Deletion from managed object storage |
| Audit log | Actor, action, and affected records for data-mutating actions | Life of account (integrity/security control) | Purged on account deletion |
| Application logs | Request method, path, timestamp, status | Rolling window of up to 90 days | Automatic rotation and expiry |
| Database backups | Point-in-time recovery snapshots | Rolling provider-managed window; expire automatically | Automatic expiry of the backup window |
5. Financial Data and Plaid
If a user connects a financial account through Plaid and later disconnects it, the
Company calls Plaid's item-removal API to invalidate the associated access token,
and the encrypted token is destroyed. Transactions already imported into the
user's books are retained as part of those books unless the user deletes them,
because they form part of the user's financial record. Plaid access tokens are
encrypted at the application layer (AES-256-GCM) at all times while stored.
6. Deletion and Disposal Procedures
- Account deletion. On a verified account-deletion request, the Company
deletes the user's account and associated bookkeeping data, files, and audit
records from the primary database within 30 days, except data the Company is
required to retain for legal, tax, accounting, or security purposes.
- Secure disposal of secrets. Encrypted secrets (such as Plaid access tokens)
are disposed of by deleting the encrypted value; because these values are
unusable without the separately-held encryption key, key rotation/destruction
additionally renders any residual copies cryptographically unrecoverable
(crypto-erasure).
- Backups. Deleted data ages out of point-in-time backups as the rolling
backup window expires; backups are not retained indefinitely.
- Subprocessors. Deletion requests are propagated to relevant subprocessors
(e.g., object storage, and Plaid via item removal) so that copies held on the
Company's behalf are also removed.
7. User Rights
- Access and portability. Users can view and edit most data directly in the
Service and can export all of their data at any time.
- Deletion. Users may request deletion of their account and associated data
by contacting the Company at the address below; the Company responds to verified
requests as required by applicable law.
- Disconnection. Users may disconnect a financial account at any time, which
invalidates the associated Plaid access token.
8. Legal Holds and Exceptions
The Company may retain specific records beyond the periods above where required to
comply with legal, tax, accounting, or regulatory obligations, to resolve
disputes, to enforce its agreements, or to preserve information subject to a legal
hold. Such records are retained only for as long as the obligation or hold
requires and are then disposed of in accordance with this policy.
9. Roles and Enforcement
The owner/operator of LedgerMCP, LLC is accountable for enforcing this policy,
including configuring retention settings, fulfilling deletion requests, and
overseeing secure disposal. Retention and disposal are enforced through
application logic (immutability and audit controls), managed-platform settings
(backup windows, storage lifecycle), and documented operational procedures.
10. Policy Review
This policy is reviewed at least annually and after any material change to the
Company's systems, data handling, or applicable law. Revisions are
version-controlled with the review date recorded above.
Contact: LedgerMCP, LLC (support@ledgermcp.com, https://ledgermcp.com)