Skip to content
LEDGERMACHINE
Legal Back to app

Privacy

Privacy Policy

This policy explains how personal data is processed when you visit the Ledgermachine website or use its browser-based visual consistency auditor.

1. Controller

Sandro Vogel
Klingsorstr. 66
12167 Berlin
Germany

Email: sandrovogel@pm.me

2. Local project processing

Ledgermachine reads project folders, ZIP archives, source files, and Ledgermachine archives locally in your browser. It analyzes imported source as text. Project source, scan inputs, findings, and exports are not uploaded to us or evaluated on our servers.

Full source files are kept only for the active browser session and are not persisted by Ledgermachine after that session. Results-only project ledgers may include scan summaries, detected values, findings, decisions, settings, file paths, and small evidence snippets needed to explain a finding.

Exports are generated locally. They leave your device only if you choose to copy, save, publish, or share them.

3. Browser storage and offline use

Ledgermachine uses IndexedDB to save results-only project ledgers in your browser. It uses localStorage to remember your selected appearance theme. This data remains on the same device and browser, and we cannot access it.

A service worker may store Ledgermachine's own application files in browser Cache Storage so the interface can remain available offline. Project source and project ledgers are not placed in that application cache.

You can delete a project ledger inside Ledgermachine. You can remove all locally stored data by clearing the website's storage in your browser.

4. Local command-line and agent integrations

If you install or run Ledgermachine's command-line tool, Claude Code skill, or local MCP server, those components read files on your machine only when you invoke them. They do not send project content to the Ledgermachine website or to us. Data handling by an AI tool or editor you connect to Ledgermachine is governed by that provider and your configuration of it.

5. Technical access data

When you visit the website, technically necessary access data may be processed to deliver the site and maintain security and stability. This can include your IP address, approximate location derived from it, date and time of access, requested URL, referrer information, browser and device information, status codes, diagnostics, and error data.

6. Purposes and legal bases

The website is provided on the basis of Article 6(1)(f) GDPR. Our legitimate interest is to provide a secure, stable, and functional website.

Browser storage is used to provide the local persistence, appearance, and offline features requested by the user. Where Section 25 TDDDG applies, storage and access are based on Section 25(2) No. 2 TDDDG because they are necessary to provide those requested functions.

Project data that remains exclusively on your device is not received or processed by us.

7. Hosting and source-code platforms

The website is hosted on Vercel. Vercel may process access, usage, device, and service-generated information to deliver, operate, and protect the website. Details are available in the Vercel Privacy Notice.

Vercel may process data in the United States and other countries outside the European Economic Area. Where required, such transfers rely on an applicable legal mechanism, such as an adequacy decision or standard contractual clauses.

The Ledgermachine source code and deployment workflow may be hosted on GitHub. GitHub is not involved in browser-based project analysis. If you follow a link to GitHub or interact with a repository there, GitHub processes that visit under its General Privacy Statement.

8. Cookies, analytics, and tracking

Ledgermachine does not use advertising cookies, analytics cookies, tracking pixels, or behavioral profiling. The browser storage described above supports only local application functionality.

9. Recipients and retention

Recipients of technical website-access data may include Vercel as the hosting provider. Project inputs and locally saved ledgers are not transmitted to us and therefore have no recipients unless you choose to share them yourself.

Local Ledgermachine data remains in your browser until you delete it or clear the site's storage. Hosting access data is retained only as long as necessary for delivery, security, troubleshooting, and abuse prevention, unless a longer period is legally required.

10. Your rights

Subject to the statutory requirements, you have rights to access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw that consent with effect for the future.

Because project inputs and local ledgers are not transmitted to us, these rights mainly concern technical data processed when the website is accessed or hosted.

11. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. In Berlin, the competent authority is the Berlin Commissioner for Data Protection and Freedom of Information.

12. Automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.

13. Changes to this policy

We may update this policy if Ledgermachine's functionality, hosting setup, or legal requirements change. The current version is published on this page.

Last updated: July 16, 2026

Ledgermachine ยท Local-first visual system audit
LegalApp