AgentLedger

Privacy

Last updated 2026-09-13 · plain-language summary, not legal advice. Questions: entradox@icloud.com

What is stored

Per spend entry: the agent id, the payment rail, the service label, the amount, token counts, the model name and a timestamp. Per workspace: the workspace id, a hash of the workspace key, the plan and billing state, and — if you register one — an alert webhook URL. Keys and secrets are stored as hashes or as files readable only by the service.

What is never stored

Prompts and model responses. There is no field for them: the ledger records cost metadata, and the service has no code path that writes message content to storage. That is true of the hosted ledger today and is a design constraint on the proxy, which will meter cost without retaining payloads. The service and model fields are free-text labels you supply — do not put anything sensitive in a service name.

Who processes it

Railway hosts the service and its storage volume. Stripe processes payments and receives the billing details you give it — we never see your card number. Alert webhooks, if you register one, carry cost metadata to the URL you chose. The product does not send email to arbitrary addresses on your behalf. Nothing else receives your data.

What we do not do

We do not sell, rent or share your data, and we do not use it to train models.

Retention and deletion

Ledger data is kept while your workspace exists. Deleting an agent removes its ledger and secret; the operator can delete a workspace and its data on request. Alert delivery receipts are kept to a rolling window.

Cookies and tracking

The marketing page and API set no advertising cookies. Aggregate counters (workspaces minted, requests) are collected without storing IP addresses — the service hashes them with a salt and keeps only the hash.

Contact

AgentLedger is operated by Parmanand LLC. Privacy questions and deletion requests: entradox@icloud.com.

← AgentLedger