DRAFT — placeholder legal text for CubeLedger, LLC, a Wyoming limited liability company. It has not been reviewed by counsel and is not a legal agreement.
Privacy
This draft describes how CubeLedger, LLC expects to handle information. It is not a finished privacy notice and it has not been reviewed by counsel.
Account data includes name, email, a password hash, optional authenticator secrets, and passkey public keys. Financial data includes entities, balances, transactions, wallet addresses the customer chooses to add, imported CSV rows, and connector tokens. Connector tokens are envelope-encrypted. The key-encryption key is an environment secret, not a column in the database.
The service uses that information to show the ledger, produce reports, and collect subscription status. It does not sell personal information. It does not request a scope that can move money or place a trade.
A monthly report hash may be written to the XRP Ledger testnet. The hash is not the report. Balances are not written on-ledger. The transaction is public on that network.
Processors expected in production are a host (such as Vercel), a Postgres provider, Stripe for card billing, and the data sources the customer connects. The demo can run with none of the paid processors configured.
The customer may ask for export or deletion. A production process for those requests will be published with the final notice. Security reports can be sent to the address published with the production site. This demo does not publish a mailbox.
The public origin comes from APP_BASE_URL. On Vercel, an unset value falls back to https:// and VERCEL_PROJECT_PRODUCTION_URL. The production hostname for this product is cubeledger.app. Passkeys and Stripe return URLs use that origin.