LedgerMCP: Data Retention and Disposal Policy

LedgerMCP, LLC

Effective date: July 7, 2026

Last reviewed: July 7, 2026

Review cadence: Reviewed at least annually and upon any material change to systems, data handling, or applicable law.


1. Purpose

This Data Retention and Disposal Policy defines how LedgerMCP, LLC ("the Company")

retains, and securely disposes of, the information it processes, including

end-user financial account data obtained through Plaid, authentication data, and

the double-entry bookkeeping records the platform maintains. Its purpose is to

ensure that data is kept only as long as there is a legitimate business or legal

need, that it is disposed of securely when that need ends, and that these

practices comply with applicable data-protection laws.

2. Scope

This policy applies to all Company systems and to all data the Company stores or

processes on behalf of its users, whether held in the production database, file

storage, backups, or application logs, and whether processed directly by the

Company or by a subprocessor acting on its behalf.

3. Guiding Principles

provide the Service, to meet a legal or regulatory obligation, or to resolve

disputes and enforce agreements.

to operate the Service. It does not store end-user bank login credentials.

deletion of their account and associated data.

deletion request is fulfilled, it is disposed of using methods appropriate to

its sensitivity so that it is not practically recoverable.

applicable privacy laws and are reviewed periodically.

4. Retention Schedule

The Company retains data according to the following schedule. "Life of account"

means for as long as the user's account remains active.

Data categoryExamplesRetention periodDisposal method
Account & authentication dataEmail address, session recordsLife of account; removed within 30 days of a verified deletion requestLogical deletion from the primary database
Bookkeeping & ledger recordsChart of accounts, journal entries, categorized transactions, tags, notesLife of account; purged on account deletion (subject to legal holds)Logical deletion; postings are immutable during account life and corrected by reversing entries, not edited in place
Plaid-derived financial dataTransactions, balances, account/routing identifiersLife of account; import stops immediately on bank disconnectLogical deletion; imported records remain in the user's books unless the user deletes them
Plaid access tokensEncrypted item access tokensInvalidated immediately on bank disconnect; destroyed on account deletionPlaid item-removal API call + deletion; crypto-erasure of the encrypted value
Uploaded filesReceipts and attachmentsLife of account; removed on account deletionDeletion from managed object storage
Audit logActor, action, and affected records for data-mutating actionsLife of account (integrity/security control)Purged on account deletion
Application logsRequest method, path, timestamp, statusRolling window of up to 90 daysAutomatic rotation and expiry
Database backupsPoint-in-time recovery snapshotsRolling provider-managed window; expire automaticallyAutomatic expiry of the backup window

5. Financial Data and Plaid

If a user connects a financial account through Plaid and later disconnects it, the

Company calls Plaid's item-removal API to invalidate the associated access token,

and the encrypted token is destroyed. Transactions already imported into the

user's books are retained as part of those books unless the user deletes them,

because they form part of the user's financial record. Plaid access tokens are

encrypted at the application layer (AES-256-GCM) at all times while stored.

6. Deletion and Disposal Procedures

deletes the user's account and associated bookkeeping data, files, and audit

records from the primary database within 30 days, except data the Company is

required to retain for legal, tax, accounting, or security purposes.

are disposed of by deleting the encrypted value; because these values are

unusable without the separately-held encryption key, key rotation/destruction

additionally renders any residual copies cryptographically unrecoverable

(crypto-erasure).

backup window expires; backups are not retained indefinitely.

(e.g., object storage, and Plaid via item removal) so that copies held on the

Company's behalf are also removed.

7. User Rights

Service and can export all of their data at any time.

by contacting the Company at the address below; the Company responds to verified

requests as required by applicable law.

invalidates the associated Plaid access token.

8. Legal Holds and Exceptions

The Company may retain specific records beyond the periods above where required to

comply with legal, tax, accounting, or regulatory obligations, to resolve

disputes, to enforce its agreements, or to preserve information subject to a legal

hold. Such records are retained only for as long as the obligation or hold

requires and are then disposed of in accordance with this policy.

9. Roles and Enforcement

The owner/operator of LedgerMCP, LLC is accountable for enforcing this policy,

including configuring retention settings, fulfilling deletion requests, and

overseeing secure disposal. Retention and disposal are enforced through

application logic (immutability and audit controls), managed-platform settings

(backup windows, storage lifecycle), and documented operational procedures.

10. Policy Review

This policy is reviewed at least annually and after any material change to the

Company's systems, data handling, or applicable law. Revisions are

version-controlled with the review date recorded above.


Contact: LedgerMCP, LLC (support@ledgermcp.com, https://ledgermcp.com)