Legal
Privacy policy
Last updated August 28, 2026. This policy covers ledger.breatheasy.net, the marketing site, and the BreathEasy Ledger accounting application, including bank account connections.
Who we are
BreathEasy Ledger is operated by BreathEasy Administrative Services LLC, 201 Lupin Street, Pahrump, Nevada 89048. We are the controller of the information described here. For anything in this policy, write to sales@breatheasy.net.
Information you give us on this site
When you submit the quote request form, we collect the name, email address, and any business name, phone number, account details, and message you choose to include. We use that information for one purpose: to respond to your request and to discuss whether BreathEasy Ledger fits your business.
We do not sell your information, we do not share it with advertisers, and we do not add you to a marketing list unless you ask us to. Submissions are stored in our systems and emailed to our sales address so a person sees them.
Information in the accounting application
If you have an account, we hold what is needed to run your books: your email address and authentication records, your workspace and role, the businesses, categories, and tracking levels you set up, the bank files you upload, the transactions you review and post, any receipts you attach, and the reports generated from them.
Your workspace is isolated in the database. Another customer cannot reach your records, and our staff access production data only when it is necessary to operate the service or to help you with a support request.
Connecting a bank account
Connecting a bank account is optional. If you choose to, the connection is made through Plaid Inc., a financial data provider. You enter your bank credentials inside Plaid's own secure screen. We never see, receive, or store your online banking username or password.
With your permission, we receive an access token plus read-only data: your transactions, account balances, and the account holder details the bank reports so we can confirm the account belongs to you. Access is read-only. We cannot initiate payments, transfers, or any movement of money.
Access tokens are encrypted inside the application before they are stored, are never sent to your browser, and are never written to logs or exports. Before the connection screen opens, we show you exactly what will be requested, what it will be used for, and how long it will be kept, and we record your consent. Plaid's own handling of your data is described in Plaid's privacy policy at plaid.com/legal.
You can disconnect any bank at any time from inside the application. Disconnecting revokes the connection at Plaid and deletes the stored token and the account data we received through it.
Assistive features
Some features suggest categories, read receipt images you upload, or answer questions about your numbers. To do that, transaction descriptions, amounts, category names, and summary totals may be sent to a model provider. Bank credentials, access tokens, and full account numbers are never included, and your data is not used to train third-party models.
Analytics without cookies
This site does not use cookies, advertising pixels, or third-party trackers, which is why you will not see a cookie banner. To understand which pages are useful, we record a minimal, anonymous record of each public page view: the page path, the time, the referring website's domain, and whether the visit came from a desktop, tablet, or phone. Pages inside the signed-in application are not tracked this way.
To count repeat visits within a single day, we generate a one-way hash that mixes your network address, your browser's user agent string, and a salt that changes daily. The network address itself is never stored, the hash cannot be reversed, and because the salt rotates every day the record cannot be linked from one day to the next or back to you.
The application does use strictly necessary browser storage to keep you signed in. That is not tracking, and it does not follow you to other websites.
How long we keep it
- Bank access tokens and account holder identity: only while the connection is active. Deleted immediately when you disconnect or close the account.
- Transactions, receipts, and reports: for the life of your account, and up to seven years if you rely on them as tax records. Deleted on request, or within 30 days of account closure unless you ask us to keep them.
- Account and authentication records: for the life of your account, then deleted within 30 days of closure.
- Quote requests and sales correspondence: for as long as we have an active conversation or relationship, then deleted on request.
- Anonymous page view records: kept in aggregate for trend reporting. They contain no personal data.
- Application and security logs: 12 months, then rotated automatically.
Deleted records also age out of encrypted backups within the backup platform's retention window. We keep only what the law requires us to keep.
Your rights and how to use them
You can ask us what information we hold about you, ask for a copy, ask us to correct it, ask us to delete it, or ask us to stop using it for a particular purpose. You can delete much of it yourself inside the application, including disconnecting banks, removing receipts, and deleting businesses.
For anything else, email sales@breatheasy.net. We acknowledge requests within 5 business days and complete them within 30 days. We will never charge you for a request or treat you differently for making one. If we ever send you a marketing message, every one will include a working unsubscribe link, and we will honor it promptly.
Who we share it with
We share data only with the service providers that make the product work: our hosting and database platform, Plaid for bank connections you set up, our transactional email provider, and the model provider behind assistive features. Each is listed with its purpose on our security and trust page. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Security
Every request travels over TLS 1.2 or better, data is encrypted at rest with AES-256, bank tokens get a second layer of application encryption, and multi-factor authentication protects accounts. Our full information security policy, including our incident response and breach notification commitments, is published on the security and trust page. No system is perfect, but we treat what you send us as something you trusted us with.
Children
BreathEasy Ledger is a business tool and is not directed to children under 13. We do not knowingly collect information from them. If you believe a child has given us information, contact us and we will remove it.
Changes and contact
If this policy changes we will update the date at the top of this page, and we will tell account holders directly before a material change takes effect. Questions about privacy can go to sales@breatheasy.net.