braatzledger

The website being hacked must be a bad day. Not a disclosure letter.

That sentence is a design requirement in this product's architecture, and the design below is what it bought. All of it is live today.

Security disclosures reach us fastest through the address on your welcome mail; honest reports get honest answers.

Your data at Braatz Ledger: pausing, cancelling, deleting

Plain English, deliberately. Where we have not built something yet, we say "planned" rather than promise it.

The promise, in one paragraph

If you ask us to delete your books, your data is gone within 60 days of your request, unless the law says otherwise, and here is how we know: a deletion request opens a 30-day window in which you can change your mind and cancel it; at the end of that window the only keys that can decrypt your books are destroyed, and a drill then tries to read the data back with each of them and records that it could not. You cancel your subscription yourself, from Settings, and the books stay exportable while you do. The proof is not our word for it: the drills that measure each of these write dated receipts into docs/security/receipts/ in the repository that builds this site, and the audit that checks this page against the running system refuses to publish a sentence whose receipt is missing or stale.

What we hold, and how it is protected

Braatz Ledger keeps a copy of the bank and card transactions you connect, the categories and notes you add, and the reports built from them — your books. Each customer's books live in their own separate database; no query can read across customers. The credentials that let us read your bank feed are encrypted (XChaCha20-Poly1305) under keys that never leave our server. Our backups are encrypted with a key that is held offline by the owner, not on the server that makes them. Everything between your browser and us travels over TLS.

Two other companies hold records about you that we do not control: Shopify, which processes your subscription payment and keeps the billing record (we never see your card number), and Plaid, which connects your bank and keeps its own record of that consent. Your subscription is charged against a first-party Shopify subscription contract; the card stays with Shopify and never reaches us.

Pausing or cancelling

Cancelling is not the same as deleting. Cancelling stops the subscription and closes your access. Deleting removes your books. You can do either, or both, in that order or separately.

Pausing is a button in Settings: press it and the next sync does not run, you are not metered while paused, and a receipt of the pause is filed to you. Press resume and it picks up where it left off — nothing was disconnected and nothing was deleted. Cancelling is the same shape: one form in Settings closes the account, writes the closing record in the same database transaction, and sends you a goodbye note with your export still available.

If you would rather a person did it, write to jason@braatzledger.com and it is handled within 24 hours; the Settings card names the same address. Anything billed while a pause request is waiting is refunded. You can export your books at any time, before or after cancelling.

After you cancel, we keep your books. We keep them indefinitely, within technical reason, so that you can come back, so that your records exist if you ever need them, and because records that a customer has not asked us to delete may be required by lawful process — a court order or a subpoena — and we comply with lawful process. If we disagree with a law we say so through the democratic channels, not by destroying records.

Deleting your books

We delete your books only when you ask us to — cancelling alone never deletes anything. Today that request is made by e-mail to the address above, and a person carries it out. The request opens a 30-day window you can cancel; after it closes, your books are removed from our live systems. Encrypted backups that still contain them expire within 14 days after that, which is how the 60-day outer bound above is met. You can disconnect a bank at any time from Settings; a deletion request disconnects every bank you had connected. What Shopify and Plaid keep after that is governed by their own policies, linked above.

If we are under a legal obligation to preserve records when a deletion request arrives, the obligation wins and the deletion waits until it is lifted — the deletion tool refuses to run against a held account rather than asking us to remember. We will tell you if we lawfully can.

Who to ask

jason@braatzledger.com. A person answers.

Last changed: 2026-09-22. This page is checked against the running system by an automated audit; the date above moves only when the words do.