Forme Ledger — Privacy Policy
1. Who we are
Forme Ledger is a multi-entity financial consolidation platform operated by Evan Williams, trading as Forme Ledger (ABN 64 291 413 591) ("Forme Ledger", "we", "us", "our"), a sole trader based in New South Wales, Australia.
Evan Williams is the entity responsible for the personal information described in this policy. Where this policy refers to the Privacy Act, it means the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs") in Schedule 1 to that Act.
We handle personal information in accordance with the APPs. We do this whether or not we are currently required to by law, and we do not rely on the small business exemption in section 6D of the Privacy Act.
2. What this policy covers
This policy explains how we collect, hold, use and disclose personal information in connection with:
- the Forme Ledger web application at formeledger.com and its subdomains;
- our connections to third-party accounting platforms that you authorise, being QuickBooks Online and Xero; and
- our marketing website, support channels and business communications.
It does not cover the privacy practices of the accounting platforms themselves, or of any other third party whose site or service you reach from ours. Those are governed by their own policies.
3. The two kinds of data we handle
It matters which of these we are talking about, because our obligations and your rights differ.
a. Personal information about our users. Names, email addresses, phone numbers, organisation details, authentication records and usage data belonging to the individuals who hold Forme Ledger accounts. We determine the purposes for which this is handled.
b. Customer Data. The accounting and financial records you connect to, or enter into, Forme Ledger — chart of accounts, trial balance figures, entity details, mappings, journals and related metadata. This is your data. We hold and process it on your instructions and for your benefit only, as described in our End-User Licence Agreement and Terms of Service.
Customer Data may contain personal information about third parties — your employees, your investors, your counterparties. Where it does, you are responsible for having a lawful basis to disclose it to us, and for notifying those individuals as required by APP 5. We act as your service provider in relation to that information and do not use it for our own purposes.
4. Information we collect
4.1 Account and identity information
Collected when you register and when you use the service:
- name;
- email address;
- mobile phone number (required, and verified at sign-up);
- organisation name and your role within it;
- authentication records, including multi-factor authentication enrolment, backup code status, device trust records and sign-in history.
Authentication is provided by Clerk (see the sub-processor table at section 8). We do not store your password. Passwords, one-time codes and authenticator secrets are held by Clerk, not by us.
4.2 Customer Data from connected platforms
When you authorise a connection to QuickBooks Online or Xero, we retrieve financial records from that platform using an access token you grant through the platform's own authorisation screen. We never see, ask for, or store your accounting platform password.
What we retrieve: the chart of accounts (account codes, names, types and classifications), trial balance figures, organisation and entity details, and — for Xero — profit and loss, balance sheet and journal report data. We retrieve this only from the organisations you select.
What our access permits. We disclose this precisely because the two platforms differ:
| Platform | Permissions we request | What they allow |
|---|---|---|
| Xero | accounting.settings.read, accounting.reports.trialbalance.read, accounting.reports.profitandloss.read, accounting.reports.balancesheet.read, plus OpenID identity scopes | Read only. Every accounting permission we request is a read permission. We are technically incapable of altering your Xero data. |
| QuickBooks Online | com.intuit.quickbooks.accounting | Intuit publishes a single accounting permission and does not offer a read-only variant. This permission therefore grants both read and write access to your QuickBooks accounting data. |
Our commitment on QuickBooks. Although the QuickBooks permission would permit it, Forme Ledger does not write to QuickBooks Online. The service reads your data and produces consolidated output within Forme Ledger. It does not create, amend or delete anything in your QuickBooks file. If that ever changes, we will amend this policy and notify you before the change takes effect. You can verify our access at any time from within QuickBooks and revoke it there.
4.3 Data you enter directly
Entity details (including ABN, ACN and addresses), mapping decisions, consolidation groups, eliminations, adjustments and journal entries you create within the Service.
4.4 Technical and usage information
- IP address;
- browser type, device type and operating system;
- application logs and error reports;
- timestamps of requests to the service.
4.5 Support communications
When you contact us at [email protected] or through the application, we collect the content of your message and any information you choose to include in it.
4.6 Billing information
Subscription and billing records, including plan, billing contact and invoice history. Payment processing is performed by Stripe. Card details are entered with and held by Stripe and never pass through our systems. We do not receive, transmit or store card numbers, expiry dates or security codes at any point.
5. How we collect information
We collect information:
- directly from you — when you register, configure your organisation, enter data or contact support;
- from platforms you authorise — when you connect QuickBooks Online or Xero and we retrieve records under that authorisation;
- automatically — through server logs and application monitoring as you use the service.
We do not buy personal information, and we do not collect it from data brokers or by scraping.
6. Why we collect, hold and use it
| Purpose | What this involves |
|---|---|
| Providing the service | Authenticating you, maintaining your account, retrieving and consolidating your financial records, generating reports |
| Account security | Multi-factor authentication, device trust checks, lockout on repeated failed sign-ins, detecting and investigating suspicious activity |
| Support | Responding to your enquiries and diagnosing faults you report |
| Service reliability | Error monitoring, debugging, capacity planning |
| Billing | Charging subscription fees, issuing invoices, collecting unpaid amounts |
| Legal and compliance | Meeting our obligations under Australian law, responding to lawful requests, enforcing our terms |
| Service communications | Notifying you of changes, outages, security matters and billing events |
We do not:
- use your Customer Data to build products or features for anyone other than you;
- combine or aggregate Customer Data across our customers;
- use Customer Data to train artificial intelligence or machine learning models;
- sell, rent or trade personal information to anyone.
7. Artificial intelligence processing
Forme Ledger uses a large language model to suggest mappings between your source accounts and your consolidated chart of accounts. This section describes exactly what that involves, because you are entitled to know precisely what leaves our systems.
7.1 What is sent
When you run a mapping suggestion, the following — and nothing else — is transmitted to our AI sub-processor:
- for each source account being mapped: an internal database identifier, the account name, its account class and its account type;
- the target chart of accounts you are mapping to: account names, classes, current/non-current designation and posting sub-category;
- a small number of previously confirmed mappings from your own account, used as worked examples (source account name, class and type, paired with the target name you chose).
7.2 What is never sent
The following categories are not transmitted to the model under any circumstances:
- account balances or any monetary amount;
- transaction amounts, line-item detail or dates;
- counterparty, supplier or customer names;
- entity legal names;
- your organisation identifier, in any form, whether raw or pseudonymised;
- account codes — only account names are sent;
- account descriptions.
7.3 Who processes it, and where
Anthropic, PBC, via its commercial API, acting as our sub-processor. Processing occurs in the United States.
Training. Anthropic does not use inputs or outputs submitted through its API to train its models. This is Anthropic's published position for API traffic and a condition of our use of the service.
Retention. Data submitted through the API is retained by Anthropic for a limited period under its commercial data retention policy, then deleted.
7.4 The model proposes; it does not decide
Every suggested mapping is presented to a person at your organisation for confirmation or rejection. No mapping takes effect in your consolidation until someone at your organisation accepts it. There is no automated decision-making that produces a legal or similarly significant effect on any individual.
7.5 You can avoid it entirely
The suggestion feature is optional and is triggered only by an explicit action taken by an administrator of your organisation. No scheduled task, background job, webhook or import invokes the model. You can map every account manually and complete a full consolidation without a single request being made to the model or any data leaving our systems for that purpose.
We make no warranty that a suggestion is correct. It is a statistical proposal, not professional judgement.
8. Who we disclose information to
We disclose personal information to the service providers below, each of which processes it on our behalf and under contract. None is authorised to use it for its own purposes.
| Provider | Purpose | Categories of data | Processing location |
|---|---|---|---|
| Railway Corporation | Application hosting, database hosting, background job processing, caching | All account information and all Customer Data | United States (US-West) |
| Clerk, Inc. | User authentication, multi-factor authentication, delivery of one-time codes and team invitation emails | Name, email address, mobile number, authentication and session records | United States |
| Anthropic, PBC | Account mapping suggestions (section 7) | The specific fields listed at 7.1 — no financial figures | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Application error reports, technical metadata, pseudonymised identifiers | United States |
| Cloudflare, Inc. | Bot protection on sign-up, delivered through Clerk | IP address, browser signals | Global edge network |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact details and payment card data, collected and held by Stripe | United States |
Identifiers in error reports. Our error monitoring is configured to strip request bodies, cookies, query strings, non-essential headers, exception messages, local variables and user context before any report leaves our systems. Where a report needs to identify which organisation or connection it relates to, a one-way cryptographic fingerprint is transmitted rather than the underlying identifier. This lets us correlate reports about the same organisation without revealing which organisation it is.
We may also disclose personal information:
- to our professional advisers (lawyers, accountants, auditors) under obligations of confidentiality;
- where required or authorised by law, including to courts, regulators and law enforcement acting under lawful process;
- to an acquirer, in connection with a sale of our business or assets, subject to the acquirer being bound to this policy in respect of information collected under it;
- with your consent, for any other purpose.
We maintain a current list of sub-processors. To be notified when it changes, email [email protected].
9. Overseas disclosure
Our infrastructure is located outside Australia. Read this section before connecting financial records to Forme Ledger.
Personal information and Customer Data are stored and processed in the United States. The specific recipients and locations are set out in the table at section 8.
Before disclosing personal information overseas we take steps reasonable in the circumstances to ensure the recipient does not breach the APPs, as APP 8.1 requires. Those steps are:
- contracting with each provider on terms that restrict processing to our documented instructions and prohibit use for the provider's own purposes;
- requiring each provider to maintain security measures appropriate to the sensitivity of the data;
- limiting what is disclosed to each provider to what that provider needs — notably, our AI sub-processor receives no financial figures at all (section 7.2);
- transmitting pseudonymised rather than direct identifiers where the provider's function does not require the real value.
What this means for your rights. Under section 16C of the Privacy Act, we generally remain accountable to you for the handling of your personal information by these overseas recipients. You may complain to us, and to the Office of the Australian Information Commissioner, about their acts and practices as though they were ours. However, those recipients are not themselves subject to the Privacy Act, and you may not be able to enforce it directly against them. Information held in the United States may be subject to lawful access by United States authorities under that country's laws.
We do not currently offer Australian data residency.
10. How we protect information
10.1 In transit
All traffic between your browser and our systems, and between our systems and our providers, is encrypted using TLS.
10.2 At rest
Storage-level encryption. All data we hold — the database, its backups and attached volumes — is encrypted at rest at the storage layer by our hosting provider.
Additional encryption of credentials. The access and refresh tokens that permit us to connect to QuickBooks Online and Xero are encrypted a second time at the application layer, using authenticated symmetric encryption, before they are written to the database. They are unreadable to anyone with database access alone.
What this means for your financial records. Your accounting data — chart of accounts, trial balance figures, entity details, mappings and journals — is protected by storage-level encryption and by the access controls described below. It is not separately encrypted at the application layer in the way your platform credentials are. We tell you this rather than leave it to inference: application-layer encryption of financial records is not currently implemented.
10.3 Access controls
- Tenant isolation. Every record belonging to a customer organisation is segregated at the database level by row-level security policies enforced by the database engine itself, not merely by application code. A query issued in the context of one organisation cannot return another organisation's rows.
- Enforced multi-factor authentication. Every user must enrol in multi-factor authentication — it is mandatory, not optional. Authenticator applications, SMS codes and single-use backup codes are supported.
- Device trust. Sign-ins from an unrecognised device require additional verification.
- Account lockout. Repeated failed sign-in attempts lock the account.
- User enumeration protection. Our sign-in flows do not reveal whether a given email address or phone number has an account.
- Bot protection. New sign-ups pass a browser verification step.
10.4 Operational controls
- Secrets management. Application credentials, including accounting platform client secrets, are held in a dedicated secrets manager, injected at runtime, and never committed to source code or exposed to the browser.
- Restricted egress. Outbound connections from our application to accounting platforms originate from a fixed set of registered IP addresses.
- Diagnostic hygiene. Our error monitoring is configured to fail closed: if the scrubbing of an error report cannot be completed, the report is discarded rather than transmitted.
- Backups. The production database is protected by two independent mechanisms: continuous write-ahead log archiving supporting point-in-time recovery across a rolling window of approximately three weeks, and scheduled daily volume snapshots. Additional snapshots are taken before significant changes.
- Change control. Changes affecting data handling are reviewed against a documented security baseline before release.
No system is perfectly secure. These controls reduce risk; they do not eliminate it.
11. Notifiable data breaches
If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm, we will assess it and, where the Privacy Act requires, notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, in accordance with Part IIIC of the Privacy Act.
Where the affected information is your Customer Data, we will notify you promptly so that you can meet your own notification obligations, and we will give you the information you reasonably need to do so.
12. How long we keep information
| Category | Retention |
|---|---|
| Account and identity information | For the life of your account, then 12 months after closure |
| Customer Data | For the life of your account, then deleted in accordance with section 12.1 |
| Application logs and error reports | 90 days |
| Security audit records | Retained — see section 12.1 |
| Billing and transaction records | 7 years, as required by Australian tax and corporations law |
| Support correspondence | 24 months |
12.1 Deletion on termination or request
For 30 days after your subscription ends you may request an export of your Customer Data. After that window closes we will delete it within a further 30 days. You may also ask us to delete it at any time, and we will do so within 30 days.
What deletion removes. Your organisation's records — chart of accounts, balances, entity details, mappings, journals, consolidation groups and platform connection records — together with your user accounts and the identity records held by our authentication provider.
What is retained, and why.
Security audit records. We keep an immutable log of administrative actions taken in the service: who did what, to which record, when, and the before-and-after state of the configuration that changed. These records contain no financial figures, balances or transaction amounts. They cannot be altered or removed by anyone, including us — that is what makes them worth keeping — so they persist for the life of the service as a security and integrity control. Where a log entry identifies a user, we sever the link to that person's identity when their account is deleted: the identity record is destroyed at our authentication provider and the local record is de-identified, leaving the log referring to an identifier that no longer resolves to a person.
Records we must keep by law. Billing and transaction records, retained for 7 years under Australian tax and corporations law.
Backups. Deleted data may persist in encrypted backups for up to 30 days, until those backups age out of their retention cycle. Backed-up data is not restored into the live service and is not accessible through it.
Disconnecting is not deletion. Disconnecting QuickBooks Online or Xero revokes our access token and stops further retrieval. Records already retrieved remain in your Forme Ledger account so that your historical consolidations continue to work. To have them deleted, ask us.
13. Your rights
Access (APP 12). You may ask for a copy of the personal information we hold about you. We will respond within 30 days. If we refuse, we will tell you why and how to complain about the refusal. We do not charge for making a request; we may charge a reasonable cost-based fee for giving access to a large volume of information, and we will tell you before we do.
Correction (APP 13). You may ask us to correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading. Much of your account information can be corrected directly in the application.
Customer Data. You may request an export of your Customer Data at any time. We will provide it in a machine-readable format within 10 business days. If an individual whose information appears in your Customer Data asks us for access or correction, we will refer them to you, because that data is yours and we hold it on your instructions.
Withdrawing a connection. You can disconnect QuickBooks Online or Xero at any time from within the application, and separately revoke our access from within the platform itself.
Anonymity. It is not practicable for us to provide the service to anonymous or pseudonymous users, because the service is tied to an authenticated account and to financial records that identify an organisation.
To exercise any of these, contact [email protected].
14. Complaints
If you think we have breached the APPs, contact us first at [email protected]. Tell us what happened and what outcome you are seeking. We will acknowledge within 5 business days and give you a substantive response within 30 days.
If you are not satisfied with our response, you may complain to:
Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
1300 363 992 — oaic.gov.au
15. Cookies and browser storage
We use only what the service needs to function. Specifically:
Authentication cookies, set by Clerk, keep you signed in and maintain your session. Without them you cannot use the service.
Browser local storage, set by us, remembers three interface preferences: whether the navigation rail is collapsed, whether developer tools are visible, and your per-organisation table and filter settings. These stay in your browser and are never transmitted to us.
Bot protection, provided by Cloudflare through Clerk, sets values necessary to verify that a sign-up is made by a person.
We do not use product analytics, session recording, heatmap tools, A/B testing tools or advertising cookies. We do not permit third parties to track you across other websites through our service. There is no tracking technology in the Forme Ledger application beyond what is described above.
Because we set only strictly necessary storage, no consent banner is required. Most browsers let you block or delete cookies; blocking authentication cookies will prevent you from signing in.
16. Direct marketing
We may send you information about features, changes and offers relating to Forme Ledger. Every such message contains an unsubscribe facility, as required by the Spam Act 2003 (Cth), and we will act on an unsubscribe request within 5 business days.
Service messages — security notices, billing notices, outage notices and changes to these terms — are not marketing and cannot be unsubscribed from while you hold an account.
We do not disclose personal information to third parties for their direct marketing purposes.
17. Users outside Australia
United States. Where United States state privacy laws apply, we do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined in those laws.
18. Changes to this policy
We may update this policy. The current version is always at formeledger.com/privacy. If a change materially affects how we handle your personal information, we will notify account holders by email at least 14 days before it takes effect.
19. Contact us
Privacy enquiries: [email protected]
Support: [email protected]
Evan Williams trading as Forme Ledger — ABN 64 291 413 591 — New South Wales, Australia
If you need to send us physical correspondence, email [email protected] and we will provide a postal address.
Read with our End-User Licence Agreement and Terms of Service.