Privacy Policy
Last Updated: August 31, 2026
1. Introduction
Welcome to Quaestor Ledger ("we," "our," or "us"), a service operated by SilkTech, LLC d/b/a Quaestor Ledger. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, and share your information when you use our website (quaestorledger.com) and our AI-powered financial tracking services.
2. Information We Collect
We collect information that you voluntarily provide to us when you use the App:
- Account Information: Email address and authentication details.
- Financial & Receipt Data: Images of receipts, invoices, and the data extracted from them (e.g., merchant names, dates, transaction totals).
- Connected Bank Data (Read-Only): If you link your bank accounts, we receive read-only transaction data to categorize your ledger. We do not collect, process, or store your bank login credentials. This is handled through a secure financial-data connection partner.
- AI Chat Prompts & Interactions: When you interact with the Quaestor Intelligence chat agent, we collect the text of your queries and the contextual financial data required to answer your questions. Do not input Sensitive Personally Identifiable Information (PII) such as Social Security Numbers, full unmasked bank account numbers, or passwords into the AI chat interface.
- Payment Information: If you subscribe to a paid plan, your payment details are processed by a third-party payment processor. Unless expressly stated otherwise at checkout, SilkTech, LLC d/b/a Quaestor Ledger is the seller and merchant of record for subscriptions. We do not store your full credit card number or raw payment card data on our servers.
- Operational Usage and Diagnostic Data: Information needed to operate, secure, and troubleshoot the Service, including sanitized page or screen categories, feature usage, device/browser information, request and error logs, approximate location derived from IP address, and interactions with application features. Microsoft Application Insights provides this operational monitoring even when you decline marketing measurement.
- Acquisition and Marketing Measurement Data: While marketing measurement is enabled under the choices described below, we may record first- and last-touch campaign information such as a sanitized public landing-page category, a validated referring website host (never its path or query), validated UTM values, and advertising click identifiers (for example,
gclid,fbclid, ormsclkid). Referring hosts that look like account, receipt, credential, UUID, or private identifiers are rejected. We may also send sanitized public-page categories and a small set of public funnel actions, such as a landing view or trial-button click, to the enabled marketing providers described below.
3. Age Restrictions
The Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13. The Service is intended for users who are at least 18 years old or the age of majority in their jurisdiction. If we learn that we have collected information from a child under 13, we will take reasonable steps to delete it.
4. How We Use Your Information
We use your data to:
- Provide and manage your account.
- AI Processing and Data Controls: We use AI and cloud services to process receipt images, extracted transaction data, categorized transaction strings, and user prompts solely to provide the Service. We do not use your personal financial data, receipt images, or prompts to train AI or intelligence systems. Where available and applicable, we configure those services to restrict training use of customer content. Retention may vary depending on the service, feature, abuse-monitoring requirement, legal obligation, and security configuration.
- Improve our application and user experience.
- Monitor reliability, diagnose failures, protect the Service, and prevent abuse.
- Subject to your marketing choices, understand which campaigns and public pages lead to trial interest and account creation.
- Comply with legal obligations.
5. Data Retention
We retain account, ledger, receipt, linked-account, chat, usage, security, and billing-related records for as long as your account is active or as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, prevent fraud or abuse, enforce our agreements, maintain backups, and support tax/accounting records. If you delete your account, we will delete or de-identify personal data within a commercially reasonable period, except where continued retention is required or permitted for the reasons above.
Our first-party acquisition record in your browser expires after 90 days. The cookie that records your marketing choice and the companion cookie that records when that choice was made each expire after one year. Operational Application Insights workspace data is currently configured for a 30-day retention period. Account-level acquisition fields that were validly collected may remain with the account record until account deletion; changing Cookie choices stops future marketing collection but does not selectively erase existing account or telemetry rows. Provider-controlled records follow the provider terms and retention controls described below.
6. Account Deletion
You may request deletion of your account by contacting support@quaestorledger.com or using any account-deletion feature made available in the Service. Deleting your account may permanently remove access to your ledger, receipts, transaction history, chat history, and account configuration, subject to limited retention for legal, security, billing, backup, and dispute-resolution purposes.
7. Sharing Information with Third Parties
We do not sell your personal data for money. We share personal data only with service providers and integration partners reasonably necessary to operate the Service, process payments, provide AI extraction and chat features, connect financial accounts, host infrastructure, provide security, analyze usage, comply with law, and protect our rights. These providers may process data only as permitted by our agreements and applicable law.
- AI and Intelligence Services: We may transmit receipt images, extracted receipt data, categorized transaction data, user prompts, and relevant account context to AI services solely to provide receipt extraction, categorization, analytics, and conversational features. We do not authorize these services to use customer content to train AI or intelligence systems, except where a user has separately consented or where applicable law permits or requires processing.
- Cloud Hosting: Our infrastructure is hosted by cloud service providers.
- Financial Data Aggregators: We use secure financial-data connection services to connect your external bank accounts. Your use of those services may be subject to their own terms and privacy policies.
- Payment Processors: We use third-party payment processors to process subscription payments securely.
- Operational Monitoring: We use Microsoft Azure Application Insights to monitor reliability, errors, and usage. This processing is operational rather than advertising-based and remains active when marketing measurement is declined. We attach acquisition context to browser-generated Application Insights telemetry only while marketing measurement is enabled. Canonical server milestone telemetry may continue to include bounded attribution that was previously collected while measurement was enabled and retained in your account record until account deletion; changing your browser choice stops new browser capture and advertising-provider delivery but does not rewrite committed operational records.
- Analytics and Advertising Measurement: While marketing measurement is enabled, Reddit Pixel receives events only on eligible public pages on
quaestorledger.com. Microsoft Advertising Universal Event Tracking (UET) uses the same public-page boundary and may also receive three canonical account milestones only from the exact clean HTTPS root ofapp.quaestorledger.com, after a fixed operator-controlled rollout cutoff; it never initializes from private/account routes, query strings, or fragments. Google Analytics and Google Ads browser delivery is currently paused behind a separate operator-controlled release gate and, if later enabled, is subject to the public-apex boundary. These providers receive only bounded actions, sanitized page categories or attribution values, and only for the three Microsoft milestones, an opaque stable event identifier; we do not send ledger entries, balances, receipt content, linked-bank details, chat content, email addresses, phone numbers, or other profile fields to them.
8. Connected Financial Accounts
If you choose to connect financial accounts, you authorize us and our financial-data connection partners to access, process, and transmit read-only account, balance, transaction, institution, and related financial data as needed to provide the Service. We do not receive or store your bank login credentials.
9. Cookies and Similar Technologies
We use cookies, pixels, local storage, and similar technologies in the categories below. When opt-out launch mode is enabled, first-party acquisition measurement and separately enabled public-page advertising tags are on by default unless you select Decline marketing or your browser sends a supported Global Privacy Control signal. When strict mode is enabled, those technologies remain off until you select Allow marketing. You can change this choice at any time through Your Privacy Choices in the footer. Google browser delivery has an additional release gate that is currently off.
- Essential and preference storage: Authentication and security mechanisms keep your session working. A first-party cookie named
ql_marketing_consent_v1, shared only betweenquaestorledger.comandapp.quaestorledger.com, and a local-storage mirror remember an affirmative allowance or denial. When you choose Allow marketing, a companion shared cookie namedql_marketing_consent_granted_at_v1records the time of that choice so that account milestones from before it are not reported to Microsoft. It is browser-scoped, client-stored, unsigned, retained for no more than one year, kept unchanged by a repeated Allow, cleared when you decline, withdraw, or send a Global Privacy Control signal, started again from the current time if measurement later resumes, and never sent to Microsoft. An explicit choice whose recorded time cannot be read reports nothing. In opt-out mode, the absence of the choice cookie means measurement may be enabled by default; it is not recorded as an affirmative consent choice. - Global Privacy Control: If your browser sends
Sec-GPC: 1or exposes an enabled Global Privacy Control signal, we treat it as a request to disable marketing measurement before acquisition capture or advertising-tag initialization. This browser-level signal takes priority; turn it off before making a different explicit choice through Your Privacy Choices. - Operational monitoring: Azure Application Insights helps us detect errors, investigate outages, and understand application health. It remains active regardless of your marketing choice. Browser-generated telemetry excludes acquisition context when marketing measurement is disabled; canonical server milestone telemetry may still use bounded attribution previously retained in your account record.
- First-party acquisition storage: While marketing measurement is enabled,
ql_telemetry_acquisition_v1and its local-storage counterpart retain a validated, sanitized first/last-touch record for up to 90 days. Landing pages are limited to public-page categories or/other. External referrer hosts are retained only when they are the exact domain or a subdomain of this closed reviewed list:bing.com,reddit.com,google.com,google.ca,duckduckgo.com,search.brave.com,yahoo.com, oryahoo.ca. The path and query are not retained, and referring hosts are not sent to Google. Any other external referrer is treated as direct unless validated campaign parameters independently identify a campaign. - Google Analytics and Google Ads: Google browser delivery is intentionally paused while automatic Google-tag measurements are being disabled and independently verified. If the separate release gate is later enabled, delivery while marketing measurement is enabled is limited to allowlisted public pages on
quaestorledger.com, excludes authenticated app pages, and explicitly suppresses the browser referrer. Advertising personalization signals remain disabled. Prior permission remains required wherever applicable law or Google policy requires it. See the Google Privacy Policy. - Reddit Pixel: While marketing measurement is enabled, Reddit may receive manual page-visit actions only from allowlisted, clean public URLs on
quaestorledger.com; it does not initialize or receive events onapp.quaestorledger.comor private/account routes. Because the pixel can inspect the live URL and inbound referrer, external delivery is allowed only for an origin-only referrer from the closed reviewed domain list above or a clean same-site public-page referrer. Paths, queries, IP literals, unapproved or special/private-use hostnames, and private-looking tokens suppress delivery. We do not currently send signup milestones or use Reddit advanced matching. See the Reddit Privacy Policy. - Microsoft Advertising UET: While marketing measurement is enabled, Microsoft may receive manual public-apex page views and allowlisted public interactions such as landing views, trial-button clicks, and authentication starts. UET loads lazily only from an eligible action. After both the production tag ID and a fixed UTC rollout cutoff are enabled, it may additionally receive
signup_completed,trial_started, andactivated_trialfrom the committed account-milestone projection, but only at the exact clean HTTPS root ofapp.quaestorledger.com. Canonical UET alone may accept the exact origin-only Entra External ID referrerhttps://quaestorledger.ciamlogin.com/; a path beyond/, query, fragment, credentials, port, alternate host, or use from public UET is rejected. A milestone is reported only if it occurred at or after the rollout cutoff and not more than five minutes before your Allow choice. Each such event contains only its action name and an opaque stable event identifier; no timestamp is sent. A denied or Global Privacy Control state, private paths, queries, fragments, unsafe inbound referrers, and malformed or missing rollout configuration all fail closed. An org-scoped, at-most-three-ID local-storage marker onapp.quaestorledger.comsuppresses repeat delivery in this browser across browser sessions; it is cleared there on denial, Global Privacy Control, or withdrawal, or at the next app load while measurement is closed, and a milestone already reported before a withdrawal is not reported again after a later Allow. The stable identifier supports provider deduplication, but browser or network failure can still create a reporting gap. Automatic initial and single-page-application page views and automatic consent handling are disabled. Because UET can remain resident on the authenticated SPA after an eligible canonical initialization, provider-side Insights/Clarity, automatic data enhancement, advanced matching, and automatic SPA/raw-URL tracking must remain disabled as a production release gate. We do not send profile fields, customer-list uploads, financial content, or arbitrary event properties. Prior permission remains required wherever applicable law or Microsoft policy requires it. Microsoft states that UET event data may be retained for up to 390 days and that UET cookies may persist for up to 13 months. See the Microsoft Privacy Statement.
| Destination | What it receives | Retention and choice boundary |
|---|---|---|
| Your browser | An explicit marketing preference, when one is made, and the time it was made; an org-scoped bounded marker of opaque canonical Microsoft event IDs delivered from this browser; and a validated sanitized first/last-touch acquisition record while measurement is enabled. The choice time and the marker are not sent to Microsoft. | Explicit preference and its choice time: up to 1 year. Acquisition: up to 90 days. The bounded delivery marker is browser-scoped and persists across browser sessions. Opt-out, withdrawal, or Global Privacy Control clears accessible acquisition and marketing storage on the current origin, including the marker and choice time, while retaining denial and opt-out signals. |
| Quaestor Ledger account record (Azure Cosmos DB) | Authoritative product-state milestone identifiers and timestamps, plus validated acquisition fields when those fields were captured while measurement was enabled. Product milestones are operational records and may exist without marketing attribution. | Generally retained with the account until account deletion, subject to the legal, security, backup, and dispute exceptions in this Policy. Cookie withdrawal stops future browser acquisition collection but is not a per-field or product-record deletion request. |
| Azure Application Insights workspace | Operational events, errors, and sanitized page categories. Browser acquisition dimensions appear only while marketing measurement is enabled; canonical server milestone copies may include bounded attribution previously collected and retained in the account record. | Currently 30 days, with a 1 GB daily ingestion cap. Workspace rows expire on schedule and are not individually hard-deleted through Cookie choices. |
| Microsoft Advertising UET | Lazy, manual allowlisted public-apex actions plus, only after fixed rollout gates pass, three canonical account/trial/activation actions from the exact clean app root. Canonical payloads contain only the action and opaque stable event identifier; no profile fields, financial content, Insights/Clarity, automatic data enhancement, or advanced matching. | Provider-controlled: UET event data may be retained up to 390 days and cookies up to 13 months. Withdrawal stops future delivery by our code and clears accessible UET cookies. |
| Google Analytics 4 and Google Ads | Currently paused. If separately enabled after automatic-measurement verification: manual sanitized public-apex page views and bounded public funnel actions, with browser referrer suppressed and no authenticated-app delivery. | The current GA4 event-data setting is 2 months; Google controls its systems and cookie lifecycle. Applicable prior-consent requirements still apply after the release gate is enabled. Opt-out stops future delivery by our code and clears accessible Google marketing cookies. |
| Reddit Pixel | Manual page-visit actions from allowlisted clean URLs, without signup milestones or advanced matching. | Provider-controlled under Reddit's policies. Withdrawal stops future delivery by our code and clears accessible Reddit marketing cookies. |
You can choose Your Privacy Choices in the footer at any time. Turning off marketing measurement stops future delivery through our marketing wrappers; clears the Quaestor browser acquisition record, the bounded canonical-delivery marker on that origin, and accessible Google, Reddit, and Microsoft marketing cookies; and retains your denial and Microsoft opt-out signals. We also honor supported Global Privacy Control signals. These controls do not delete acquisition fields already retained with your account or canonical operational copies; use account deletion for the account-record lifecycle described above. Browser restrictions, provider-controlled storage, or records already transmitted may not be removable through this control; you can also use browser privacy controls and the provider choices linked above.
10. Data Security
We use administrative, technical, and organizational safeguards designed to protect personal and financial data, including encryption in transit and at rest, access controls, authentication controls, logging, monitoring, and third-party security review where appropriate. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Security Incidents
If we determine that a security incident requires notice under applicable law, we will provide notice to affected users and regulators as required. We may also notify users of security issues when we believe notice is appropriate to help protect accounts or data.
12. Your Rights
Depending on your location, you may have the right to access, correct, delete, or obtain a portable copy of personal data we maintain about you. You may also have the right to opt out of certain processing activities, including targeted advertising, sale or sharing of personal data, or certain profiling activities, where applicable. We do not sell personal data for money. Use Your Privacy Choices, enable Global Privacy Control, or contact support@quaestorledger.com to exercise applicable rights. We may verify your identity before fulfilling a request. If we deny a request, you may appeal by replying to our denial notice or contacting support@quaestorledger.com with the subject line "Privacy Appeal." We will not discriminate against you for exercising privacy rights.

