FormeLedger

Forme Ledger — Privacy Policy

Effective date
12 September 2026
Last updated
12 September 2026

1. Who we are

Forme Ledger is a multi-entity financial consolidation platform operated by Evan Williams, trading as Forme Ledger (ABN 64 291 413 591) ("Forme Ledger", "we", "us", "our"), a sole trader based in New South Wales, Australia.

Evan Williams is the entity responsible for the personal information described in this policy. Where this policy refers to the Privacy Act, it means the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs") in Schedule 1 to that Act.

We handle personal information in accordance with the APPs. We do this whether or not we are currently required to by law, and we do not rely on the small business exemption in section 6D of the Privacy Act.

2. What this policy covers

This policy explains how we collect, hold, use and disclose personal information in connection with:

It does not cover the privacy practices of the accounting platforms themselves, or of any other third party whose site or service you reach from ours. Those are governed by their own policies.

3. The two kinds of data we handle

It matters which of these we are talking about, because our obligations and your rights differ.

a. Personal information about our users. Names, email addresses, phone numbers, organisation details, authentication records and usage data belonging to the individuals who hold Forme Ledger accounts. We determine the purposes for which this is handled.

b. Customer Data. The accounting and financial records you connect to, or enter into, Forme Ledger — chart of accounts, trial balance figures, entity details, mappings, journals and related metadata. This is your data. We hold and process it on your instructions and for your benefit only, as described in our End-User Licence Agreement and Terms of Service.

Customer Data may contain personal information about third parties — your employees, your investors, your counterparties. Where it does, you are responsible for having a lawful basis to disclose it to us, and for notifying those individuals as required by APP 5. We act as your service provider in relation to that information and do not use it for our own purposes.

4. Information we collect

4.1 Account and identity information

Collected when you register and when you use the service:

Authentication is provided by Clerk (see the sub-processor table at section 8). We do not store your password. Passwords, one-time codes and authenticator secrets are held by Clerk, not by us.

4.2 Customer Data from connected platforms

When you authorise a connection to QuickBooks Online or Xero, we retrieve financial records from that platform using an access token you grant through the platform's own authorisation screen. We never see, ask for, or store your accounting platform password.

What we retrieve: the chart of accounts (account codes, names, types and classifications), trial balance figures, organisation and entity details, and — for Xero — profit and loss, balance sheet and journal report data. We retrieve this only from the organisations you select.

What our access permits. We disclose this precisely because the two platforms differ:

PlatformPermissions we requestWhat they allow
Xeroaccounting.settings.read, accounting.reports.trialbalance.read, accounting.reports.profitandloss.read, accounting.reports.balancesheet.read, plus OpenID identity scopesRead only. Every accounting permission we request is a read permission. We are technically incapable of altering your Xero data.
QuickBooks Onlinecom.intuit.quickbooks.accountingIntuit publishes a single accounting permission and does not offer a read-only variant. This permission therefore grants both read and write access to your QuickBooks accounting data.

Our commitment on QuickBooks. Although the QuickBooks permission would permit it, Forme Ledger does not write to QuickBooks Online. The service reads your data and produces consolidated output within Forme Ledger. It does not create, amend or delete anything in your QuickBooks file. If that ever changes, we will amend this policy and notify you before the change takes effect. You can verify our access at any time from within QuickBooks and revoke it there.

4.3 Data you enter directly

Entity details (including ABN, ACN and addresses), mapping decisions, consolidation groups, eliminations, adjustments and journal entries you create within the Service.

4.4 Technical and usage information

4.5 Support communications

When you contact us at [email protected] or through the application, we collect the content of your message and any information you choose to include in it.

4.6 Billing information

Subscription and billing records, including plan, billing contact and invoice history. Payment processing is performed by Stripe. Card details are entered with and held by Stripe and never pass through our systems. We do not receive, transmit or store card numbers, expiry dates or security codes at any point.

5. How we collect information

We collect information:

We do not buy personal information, and we do not collect it from data brokers or by scraping.

6. Why we collect, hold and use it

PurposeWhat this involves
Providing the serviceAuthenticating you, maintaining your account, retrieving and consolidating your financial records, generating reports
Account securityMulti-factor authentication, device trust checks, lockout on repeated failed sign-ins, detecting and investigating suspicious activity
SupportResponding to your enquiries and diagnosing faults you report
Service reliabilityError monitoring, debugging, capacity planning
BillingCharging subscription fees, issuing invoices, collecting unpaid amounts
Legal and complianceMeeting our obligations under Australian law, responding to lawful requests, enforcing our terms
Service communicationsNotifying you of changes, outages, security matters and billing events

We do not:

7. Artificial intelligence processing

Forme Ledger uses a large language model to suggest mappings between your source accounts and your consolidated chart of accounts. This section describes exactly what that involves, because you are entitled to know precisely what leaves our systems.

7.1 What is sent

When you run a mapping suggestion, the following — and nothing else — is transmitted to our AI sub-processor:

7.2 What is never sent

The following categories are not transmitted to the model under any circumstances:

7.3 Who processes it, and where

Anthropic, PBC, via its commercial API, acting as our sub-processor. Processing occurs in the United States.

Training. Anthropic does not use inputs or outputs submitted through its API to train its models. This is Anthropic's published position for API traffic and a condition of our use of the service.

Retention. Data submitted through the API is retained by Anthropic for a limited period under its commercial data retention policy, then deleted.

7.4 The model proposes; it does not decide

Every suggested mapping is presented to a person at your organisation for confirmation or rejection. No mapping takes effect in your consolidation until someone at your organisation accepts it. There is no automated decision-making that produces a legal or similarly significant effect on any individual.

7.5 You can avoid it entirely

The suggestion feature is optional and is triggered only by an explicit action taken by an administrator of your organisation. No scheduled task, background job, webhook or import invokes the model. You can map every account manually and complete a full consolidation without a single request being made to the model or any data leaving our systems for that purpose.

We make no warranty that a suggestion is correct. It is a statistical proposal, not professional judgement.

8. Who we disclose information to

We disclose personal information to the service providers below, each of which processes it on our behalf and under contract. None is authorised to use it for its own purposes.

ProviderPurposeCategories of dataProcessing location
Railway CorporationApplication hosting, database hosting, background job processing, cachingAll account information and all Customer DataUnited States (US-West)
Clerk, Inc.User authentication, multi-factor authentication, delivery of one-time codes and team invitation emailsName, email address, mobile number, authentication and session recordsUnited States
Anthropic, PBCAccount mapping suggestions (section 7)The specific fields listed at 7.1 — no financial figuresUnited States
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsApplication error reports, technical metadata, pseudonymised identifiersUnited States
Cloudflare, Inc.Bot protection on sign-up, delivered through ClerkIP address, browser signalsGlobal edge network
Stripe, Inc.Subscription billing and payment processingBilling contact details and payment card data, collected and held by StripeUnited States

Identifiers in error reports. Our error monitoring is configured to strip request bodies, cookies, query strings, non-essential headers, exception messages, local variables and user context before any report leaves our systems. Where a report needs to identify which organisation or connection it relates to, a one-way cryptographic fingerprint is transmitted rather than the underlying identifier. This lets us correlate reports about the same organisation without revealing which organisation it is.

We may also disclose personal information:

We maintain a current list of sub-processors. To be notified when it changes, email [email protected].

9. Overseas disclosure

Our infrastructure is located outside Australia. Read this section before connecting financial records to Forme Ledger.

Personal information and Customer Data are stored and processed in the United States. The specific recipients and locations are set out in the table at section 8.

Before disclosing personal information overseas we take steps reasonable in the circumstances to ensure the recipient does not breach the APPs, as APP 8.1 requires. Those steps are:

What this means for your rights. Under section 16C of the Privacy Act, we generally remain accountable to you for the handling of your personal information by these overseas recipients. You may complain to us, and to the Office of the Australian Information Commissioner, about their acts and practices as though they were ours. However, those recipients are not themselves subject to the Privacy Act, and you may not be able to enforce it directly against them. Information held in the United States may be subject to lawful access by United States authorities under that country's laws.

We do not currently offer Australian data residency.

10. How we protect information

10.1 In transit

All traffic between your browser and our systems, and between our systems and our providers, is encrypted using TLS.

10.2 At rest

Storage-level encryption. All data we hold — the database, its backups and attached volumes — is encrypted at rest at the storage layer by our hosting provider.

Additional encryption of credentials. The access and refresh tokens that permit us to connect to QuickBooks Online and Xero are encrypted a second time at the application layer, using authenticated symmetric encryption, before they are written to the database. They are unreadable to anyone with database access alone.

What this means for your financial records. Your accounting data — chart of accounts, trial balance figures, entity details, mappings and journals — is protected by storage-level encryption and by the access controls described below. It is not separately encrypted at the application layer in the way your platform credentials are. We tell you this rather than leave it to inference: application-layer encryption of financial records is not currently implemented.

10.3 Access controls

10.4 Operational controls

No system is perfectly secure. These controls reduce risk; they do not eliminate it.

11. Notifiable data breaches

If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm, we will assess it and, where the Privacy Act requires, notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, in accordance with Part IIIC of the Privacy Act.

Where the affected information is your Customer Data, we will notify you promptly so that you can meet your own notification obligations, and we will give you the information you reasonably need to do so.

12. How long we keep information

CategoryRetention
Account and identity informationFor the life of your account, then 12 months after closure
Customer DataFor the life of your account, then deleted in accordance with section 12.1
Application logs and error reports90 days
Security audit recordsRetained — see section 12.1
Billing and transaction records7 years, as required by Australian tax and corporations law
Support correspondence24 months

12.1 Deletion on termination or request

For 30 days after your subscription ends you may request an export of your Customer Data. After that window closes we will delete it within a further 30 days. You may also ask us to delete it at any time, and we will do so within 30 days.

What deletion removes. Your organisation's records — chart of accounts, balances, entity details, mappings, journals, consolidation groups and platform connection records — together with your user accounts and the identity records held by our authentication provider.

What is retained, and why.

Security audit records. We keep an immutable log of administrative actions taken in the service: who did what, to which record, when, and the before-and-after state of the configuration that changed. These records contain no financial figures, balances or transaction amounts. They cannot be altered or removed by anyone, including us — that is what makes them worth keeping — so they persist for the life of the service as a security and integrity control. Where a log entry identifies a user, we sever the link to that person's identity when their account is deleted: the identity record is destroyed at our authentication provider and the local record is de-identified, leaving the log referring to an identifier that no longer resolves to a person.

Records we must keep by law. Billing and transaction records, retained for 7 years under Australian tax and corporations law.

Backups. Deleted data may persist in encrypted backups for up to 30 days, until those backups age out of their retention cycle. Backed-up data is not restored into the live service and is not accessible through it.

Disconnecting is not deletion. Disconnecting QuickBooks Online or Xero revokes our access token and stops further retrieval. Records already retrieved remain in your Forme Ledger account so that your historical consolidations continue to work. To have them deleted, ask us.

13. Your rights

Access (APP 12). You may ask for a copy of the personal information we hold about you. We will respond within 30 days. If we refuse, we will tell you why and how to complain about the refusal. We do not charge for making a request; we may charge a reasonable cost-based fee for giving access to a large volume of information, and we will tell you before we do.

Correction (APP 13). You may ask us to correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading. Much of your account information can be corrected directly in the application.

Customer Data. You may request an export of your Customer Data at any time. We will provide it in a machine-readable format within 10 business days. If an individual whose information appears in your Customer Data asks us for access or correction, we will refer them to you, because that data is yours and we hold it on your instructions.

Withdrawing a connection. You can disconnect QuickBooks Online or Xero at any time from within the application, and separately revoke our access from within the platform itself.

Anonymity. It is not practicable for us to provide the service to anonymous or pseudonymous users, because the service is tied to an authenticated account and to financial records that identify an organisation.

To exercise any of these, contact [email protected].

14. Complaints

If you think we have breached the APPs, contact us first at [email protected]. Tell us what happened and what outcome you are seeking. We will acknowledge within 5 business days and give you a substantive response within 30 days.

If you are not satisfied with our response, you may complain to:

Office of the Australian Information Commissioner GPO Box 5218, Sydney NSW 2001
1300 363 992 — oaic.gov.au

15. Cookies and browser storage

We use only what the service needs to function. Specifically:

Authentication cookies, set by Clerk, keep you signed in and maintain your session. Without them you cannot use the service.

Browser local storage, set by us, remembers three interface preferences: whether the navigation rail is collapsed, whether developer tools are visible, and your per-organisation table and filter settings. These stay in your browser and are never transmitted to us.

Bot protection, provided by Cloudflare through Clerk, sets values necessary to verify that a sign-up is made by a person.

We do not use product analytics, session recording, heatmap tools, A/B testing tools or advertising cookies. We do not permit third parties to track you across other websites through our service. There is no tracking technology in the Forme Ledger application beyond what is described above.

Because we set only strictly necessary storage, no consent banner is required. Most browsers let you block or delete cookies; blocking authentication cookies will prevent you from signing in.

16. Direct marketing

We may send you information about features, changes and offers relating to Forme Ledger. Every such message contains an unsubscribe facility, as required by the Spam Act 2003 (Cth), and we will act on an unsubscribe request within 5 business days.

Service messages — security notices, billing notices, outage notices and changes to these terms — are not marketing and cannot be unsubscribed from while you hold an account.

We do not disclose personal information to third parties for their direct marketing purposes.

17. Users outside Australia

United States. Where United States state privacy laws apply, we do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined in those laws.

18. Changes to this policy

We may update this policy. The current version is always at formeledger.com/privacy. If a change materially affects how we handle your personal information, we will notify account holders by email at least 14 days before it takes effect.

19. Contact us

Privacy enquiries: [email protected]
Support: [email protected]

Evan Williams trading as Forme Ledger — ABN 64 291 413 591 — New South Wales, Australia

If you need to send us physical correspondence, email [email protected] and we will provide a postal address.


Read with our End-User Licence Agreement and Terms of Service.