CourtLedger
Features Security Compare How it works Pricing FAQ
Company
About usWho builds this, and why SecurityWhat we keep, and for how long Contact usSupport, sales and demos
Launch app
Features Security Compare How it works Pricing FAQ About us Security Contact us Launch app
Legal

Privacy Policy

Court Ledger is built around a simple principle: your client documents are yours. This policy explains exactly what we collect, what we don't, and how your documents are processed.

By default, Court Ledger retains nothing about your clients. Input documents are deleted from our servers as soon as processing finishes. Extracted data and output files are deleted within an hour of your first download unless you have enabled data retention. Extraction runs on Amazon Bedrock, which under AWS's terms does not store your document content after a request completes or use it to train models; we also keep Bedrock's optional request logging switched off (see Section 7). We do not sell your data and it is never used to train AI models.

1. About this policy

This Privacy Policy explains how Court Ledger, a sole proprietorship owned and operated by Anden Beers ("Court Ledger," "we," "us," or "our"), handles information in connection with the Court Ledger application and the court-ledger.com website (together, the "Service"). It describes the personal information we collect from account holders and how your documents are handled during processing.

2. Information we collect

  • Account information: your name and email address.
  • Billing information: processed by our payment processor, Stripe. We do not receive or store full payment card numbers.
  • Subscription information: your license key, plan, page-usage counts, and subscription status.
  • Run records (labels only, not client data): for each run we keep the matter or trust name and the account labels you type into the application, together with page counts, timing, and status. That is all. We do not keep the statements, the transactions read from them, the payees, the amounts, the balances, or the account numbers. A run record is a line in your history that says "Larson Family Trust, Schwab account, 42 pages, completed" and nothing more. These labels persist regardless of your data retention setting, and you choose what goes in them - a matter reference works as well as a client name.
  • Diagnostics: anonymous crash reports and usage metrics that do not include the content of your documents or any extracted data.

3. What we do not store by default

Unless you have enabled data retention in your account settings, we do not store or retain on our servers:

  • the PDFs, check images, or other documents you submit for processing;
  • transaction data or other financial information extracted from them;
  • client, conservatee, beneficiary, or account-holder details contained in those documents; or
  • the output files (such as Excel or CSV) generated from your documents.

Input documents are deleted from our servers as soon as processing completes, regardless of your data retention setting and whether the run succeeded or failed. Extracted data and output files are deleted within an hour of your first download unless data retention is enabled. With retention off, no run log is written at any point, so no record of the payees, amounts, or account names in your documents is created.

Two exceptions we would rather state than let you discover.

  • The matter name and account labels you type when setting up a run stay in your run history and are not covered by the retention setting. Those are labels you wrote, not data taken from your documents; no transaction, payee, amount, or account number is stored with them (see Section 2).
  • Your output workbook is held in our database from the moment it is produced until you download it, because that is how it reaches you. With retention off it is erased within an hour of your first download. The delay is deliberate: deleting it during the download itself meant that a dropped connection, or wanting the CSV as well as the workbook, destroyed a finished accounting that could not be recovered without producing it again. A workbook you never download has no deletion timer set and remains in the database until you ask us to remove it - email [email protected]. Until then it exists in the database (see Section 8).

We also do not use your documents or extracted data to train AI models, and our AI provider does not retain them (see Section 7).

4. How your documents are processed

When you submit a document for processing:

  • the document is transmitted to our processing server over an encrypted (TLS 1.2 or higher) connection;
  • it is written to a temporary, per-run working area on the processing server so its pages can be rendered and read;
  • each page is classified to determine whether it contains transaction data (classification is free, and pages with no relevant data are not sent for extraction);
  • pages containing data are sent to our AI provider for extraction, and the extracted transactions are assembled into your output workbook; and
  • the entire per-run working area, including every document you uploaded and the generated workbook, is permanently deleted from the processing server as soon as the run finishes, whether it succeeded or failed. This happens regardless of your data retention setting.

We describe the temporary working area explicitly rather than claiming documents are never written anywhere, because reading a scanned PDF requires rendering its pages. What we commit to is that this storage is transient and per-run, and that it is deleted when the run ends.

Document content is never used to train any AI model, by us or by our AI provider.

5. Data retention setting

By default, extracted data and output files are deleted within an hour of your first download. If you enable data retention in your account settings, we will store your extracted transaction data and output files on our servers so you can access prior accountings within the application. Retained runs are kept until you delete them or close your account, and we do not impose an expiry - if you would prefer an automatic one, tell us and we will set it for your account. You can disable data retention at any time, which will stop future storage; you may also request deletion of any previously retained data by emailing [email protected]. Input documents are never retained regardless of this setting.

6. How we use information

We use the limited information we collect to provide and maintain the Service, process payments and manage subscriptions, provide support, secure the Service and prevent abuse, and comply with legal obligations.

7. Sharing and service providers (subprocessors)

We do not sell or rent personal information. We share limited information only with the service providers below, each of which is necessary to operate the Service:

  • Amazon Bedrock (AI extraction) - performs the document extraction. Page images from your statements are sent to Amazon Bedrock to be read. Extraction runs on Amazon Bedrock. Under AWS's terms for Bedrock, your document content is not stored after a request completes and is not used to train any model. We additionally keep Bedrock's optional model invocation logging switched off, and our software verifies this at startup and refuses to run if logging is enabled or if it cannot confirm that it is off. Invocation logging is an optional AWS feature that would write the full text of every request to storage in our own AWS account; it is off, and the check that it is off runs in both our web and processing services every time they start.
  • Stripe - payment processing. Stripe is PCI DSS Level 1 certified. Full payment card numbers never reach our servers and we never store them.
  • Railway (cloud infrastructure) - hosts our application, processing server, and database. Uploaded documents are written to a transient per-run working area on this infrastructure and deleted when the run ends (see Section 4). Account records and, if you have enabled retention, your saved output files reside in the database hosted here.
  • stockanalysis.com - used to resolve security names. When a statement lists a holding, the security's name or ticker (for example "iShares Gold Trust" or "IAU") may be sent to this service to obtain its canonical name for your schedules. No client, account holder, beneficiary, or account-number information is included in these lookups, and no document is transmitted. Resolved names are cached so the same security is looked up only once, and the cache is keyed by ticker or security name only. This is a public financial-data website queried over HTTPS; we have no contract with it and it has made us no commitments about its own logging or retention, which is why we limit what is sent to a security name and never include anything identifying a client, matter, or account. Its privacy policy is available at stockanalysis.com/privacy-policy.

We do not use advertising networks, analytics providers that profile individuals, or data brokers. We may also disclose information where required by law or to protect our legal rights, and in connection with a merger, acquisition, or sale of assets (with notice to affected users).

8. Data retention

We retain account, billing, and subscription information for as long as your account is active. After you close your account we delete account records within 30 days, except for billing and transaction records, which we keep for seven years because tax and accounting rules require it. Input documents are never retained. Extracted data and output files are retained only if you have enabled data retention in your account settings, with one exception we would rather state than have you discover: an output workbook that is never downloaded has no deletion timer set on it, so it stays in the database until you ask us to remove it.

Backups. Your uploaded documents are never written to our database. Figures extracted from them are – as your finished workbook, and while a run is in progress or paused, as the extraction itself – and those are covered by the retention terms above. The documents themselves are not. They exist only in a temporary working area on the processing container, and container storage is not backed up by our infrastructure provider, so your client documents cannot appear in any backup at any point. When that working area is deleted at the end of a run, the documents are gone.

Our database is separate, and it is backed up automatically for disaster recovery. What the database holds is your account record, your run history (matter and account labels only, as described in Section 2), any output file waiting to be downloaded, and output files you have chosen to retain. Those can persist in a backup for a period after you delete them from the live system. We do not edit backups in response to a deletion request, because doing that reliably is not possible; backups age out on a rolling schedule and no one restores one except to recover from an infrastructure failure. When we say something is deleted, we mean it is removed from the live system and ages out of backups thereafter.

You may request deletion of your account information at any time (see Section 10).

9. Security

Because the Service handles confidential client material, we describe our safeguards specifically rather than in generalities.

  • Encryption in transit. All traffic between your browser, our servers, and our providers travels over TLS 1.2 or higher. Uploads, downloads, and API calls are encrypted in transit.
  • Encryption at rest. Our database and its backups are encrypted at rest by our infrastructure provider using AES-256. This covers account records, run history, and any output files you have chosen to retain. The transient per-run working area holding uploaded documents sits on encrypted provider storage for the duration of the run.
  • Minimised retention. Uploaded documents are deleted as soon as a run ends. With data retention off (the default), run logs are never written and your output workbook is deleted within an hour of your first download. The less we hold, the less there is to expose.
  • Retention is opt-in and deliberate. Turning retention on requires an explicit in-app confirmation. It cannot be enabled by accident, and each run records the setting in force when it was created, so changing the setting later never retroactively alters an earlier run.
  • No retention by our AI provider, checked at startup. See Section 7. Document content is not retained by Amazon Bedrock after processing and is never used for model training, and our software will not start if Bedrock request logging is enabled, or if it cannot verify that logging is disabled.
  • Account isolation, enforced server-side. Every request for a run, a log, or an output file is checked against the account that created it on the server. Access is never inferred from the browser, so one firm's matters are not reachable from another account.
  • Credential handling. Passwords are stored only as bcrypt hashes and are never recoverable in readable form, by us or anyone else. Sessions use signed, expiring tokens.
  • Brute-force protection. Repeated failed sign-in attempts trigger an escalating lockout keyed to both the account and the originating network. Account creation is rate-limited per network.
  • Upload controls. Uploads are size-limited and streamed to disk rather than buffered in memory, so a single oversized or malformed request cannot degrade the Service for others. Only document and image file types are accepted.
  • No sensitive detail in errors or logs. Error messages shown in the application contain a plain description only. Operational logs record what the software was doing - which run, which stage, how many pages, how long, and any error type - and we do not write document content, extracted transactions, payee names, or account numbers into them. Operational logs are retained for 30 days and then discarded. Per-run processing logs, which do contain extracted values, are written only when you have enabled data retention, and never otherwise.
  • Payment isolation. Card data is handled entirely by Stripe and never transits or rests on our servers.

We are a small team and do not currently hold SOC 2 or ISO 27001 certification; we would rather state that plainly than imply an audit we have not undergone. No method of transmission or storage is completely secure. If we become aware of a security incident affecting your personal information or document content, we will notify you without undue delay and in any event within 72 hours of confirming it, describing what happened, what data was involved, and what we are doing about it. We commit to that timeline whether or not a particular law requires it, because a firm with its own notification duties cannot meet them on information it does not have.

9a. Confidential and privileged material

Many of our users are attorneys, professional fiduciaries, and CPAs with independent duties of confidentiality, and the documents processed may be subject to attorney-client privilege or similar protections. We want you to be able to assess this accurately rather than rely on marketing language:

  • Producing an accounting requires software to read your documents, so during a run the content necessarily passes through our infrastructure and Amazon Bedrock's. We cannot honestly claim otherwise.
  • That exposure is limited to the duration of the run. Nothing is retained afterward by us - unless you enable retention, or you never download the workbook, which leaves it in the database until you ask us to delete it (see Section 3) - or by Amazon Bedrock.
  • Court Ledger personnel do not read, review, or access the content of your documents in the ordinary course of business, and there is no routine review, sampling, or quality-checking of customer material.
  • There are narrow circumstances in which we could: diagnosing a failure you have reported and asked us to investigate, responding to a valid legal process, or acting on a credible security threat. Because Court Ledger is operated by one person, that person is the only one with production access and is the person who authorises it. In the first case we will ask you first and act only with your agreement. If you have data retention switched off, there is in practice nothing to look at: the documents and the output are already gone.
  • We do not use your documents or extracted data to train models, to build datasets, or for any purpose other than producing your output.

If your firm requires a written description of this data flow, a subprocessor list, or a data processing agreement in order to satisfy its own professional-responsibility obligations, email [email protected] and we will provide one.

10. Your privacy rights (including California)

Depending on where you live, you may have the right to access, correct, or delete personal information we hold about you, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). California residents may also use an authorized agent to make a request and are entitled to non-discrimination for exercising their rights. To make a request, email [email protected] from the address on your account. If we cannot match the request to an account we will ask you to verify it from that address before we act, since acting on an unverified deletion request is itself a way to lose someone's data. We respond within 45 days, extendable once by a further 45 days where the law permits and we tell you why. An authorised agent must provide written permission signed by you.

Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, and Texas) have comparable rights and may use the same address. We honour these requests regardless of where you live rather than checking whether your state obliges us to.

Where your data is handled. Court Ledger is operated from the United States. Your account record, your run history, and any output files you have chosen to retain are stored in the United States.

Document extraction is different, and we would rather be precise than reassuring. Page images from your statements are sent to Amazon Bedrock through a global inference profile, which means AWS may carry out any given request in any of its regions, including regions outside the United States. We use that profile because AWS prices it below the US-only equivalent.

AWS's terms for Bedrock apply in every region: your document content is not stored after the request completes and is not used to train any model, and we keep Bedrock's optional request logging switched off (see Section 7). So what changes with region is where a page is read, not what is kept afterwards, which is nothing. Nothing else about your data leaves the United States - documents are never stored outside the transient per-run working area described in Section 4, and the database holding your account and run history is US-hosted.

If your firm has a data-residency obligation this does not meet, email [email protected] before you upload anything. Processing region is a configuration setting and we can move the service back to US-only regions; we would rather hear from you than have you assume one way or the other.

11. Data processing agreement

If your firm requires a data processing agreement (DPA) for its use of the Service, contact us at [email protected] and we will make our standard DPA available.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, give you notice by email or within the application at least 14 days before they take effect. A change is material if it broadens what we collect, adds a purpose for using your information, adds a subprocessor that receives document content, weakens a retention or deletion commitment, or reduces your rights under this policy. Fixing a typo or clarifying existing wording is not. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

13. Contact

Questions or requests? Email us at [email protected].

Last updated: September 2026 · Court Ledger
CourtLedger
California court accounting software
for trust & conservatorship attorneys.
Product
Features How it works Security Pricing
Legal
About us Security Contact us Privacy policy Terms of use

© 2026 Court Ledger. All rights reserved. Questions? [email protected]