The short version
Aethelgard is a local-first application. Your financial data is stored exclusively on your own device and never transmitted to us. We do not collect, store, or process your personal financial information. Two optional AI features work differently and are described in full below: Sentinel's AI features send only sanitised, anonymised aggregates (section 3), while Aethelgard's AI Assistant — off by default, and local-only unless you change it — sends your ledger data directly to a cloud provider of your choosing if you configure one (section 4).
1. Who we are
Aethelgard is a software product developed and sold by its creator ("we", "us"). You can contact us at contact@aethelgard.finance.
2. Your financial data
All data you enter into Aethelgard — transactions, account balances, entity information, documents — is stored locally on your device in a SQLite database. Backups exported from the app are encrypted with AES-256-GCM (with an Argon2id-derived key from your passphrase) before they leave your machine. At-rest encryption of the live vault file via SQLCipher AES-256 is available as an option — off by default, switched on by you in Settings → Vault, and unlocked with your PIN at startup (with a one-time recovery code issued as a backup way in). This data is:
- Never transmitted to our servers
- Never shared with third parties
- Not accessible to us under any circumstances
- Fully under your control at all times
If you choose to configure encrypted backups via WebDAV, those backups are sent to your own storage endpoint — not ours. They are encrypted on your device before leaving it, and we never receive or have access to them.
3. Aethelgard Sentinel — AI features
Aethelgard Sentinel includes optional AI features (summaries, investment memos, and narrated exports). These are off by default and only run when you switch them on. When they are on, this is exactly what happens:
- What leaves your device: only sanitised, anonymised aggregates. Before any AI call, an on-device sanitisation layer strips names, account numbers, and security identifiers (ISINs), and coarsens amounts to broad magnitude bands. Your raw positions, balances, and identities never leave your machine. A leak-test suite fails our build if any identifier would escape.
- Where it goes: in bring-your-own-key mode, requests go directly to Anthropic under your own API key. In managed mode, requests route through our proxy to Anthropic; the proxy logs only a hashed licence identifier, the model name, and a token-count estimate — never the content of any request or response.
- Retention: Anthropic does not use this data to train its models. Anthropic may retain API inputs and outputs for up to 30 days for trust-and-safety purposes before deletion, under its commercial terms. We are pursuing a zero-data-retention agreement with Anthropic and will update this policy when it is in place.
Every accepted AI output is recorded in a tamper-evident audit ledger inside your local vault, so you can always see what was generated and when. If you never enable AI, nothing is ever sent.
4. Aethelgard AI Assistant — optional, off by default
Aethelgard includes an optional AI Assistant that can answer questions about your ledger and draft journals, reversals, reconciliations and categorisations for you to approve. It is off by default, and it works in one of two ways depending on how you configure it. This is a different feature from Sentinel's AI features in section 3, and it behaves differently — please read this section rather than assuming it is the same.
- Local model (the default): if you point the assistant at a model running on your own machine — Ollama, LM Studio, or similar — nothing leaves your device. This is how it ships.
- Cloud model (only if you choose it): if you point it at a cloud provider using your own API key, then each time you ask a question, Aethelgard sends that provider your question and the ledger data needed to answer it. That can include entity names, account names and codes, account balances, and individual transaction dates, descriptions and amounts. Transaction descriptions often contain the names of people and organisations you deal with. This data is not anonymised or redacted before it is sent — unlike Sentinel's AI features, there is no sanitisation layer on this path.
- Who you are dealing with: you choose the provider and hold the account with them. We never see this data and are not a party to it. Your relationship is directly with the provider, under their terms and privacy policy. If your records contain other people's personal data, you are the controller and should satisfy yourself that you have a lawful basis and an appropriate data processing agreement with that provider.
- Retention and training: your provider decides how long it keeps this data and whether it is used to train models. That depends on your account and plan with them, not on us. Check your provider's data-controls settings before enabling.
Before a cloud endpoint can be saved, the app requires an explicit acknowledgement naming the destination and what will be sent. Plain unencrypted connections to remote hosts are refused. No question, answer or conversation is stored in your vault or written to any log, and your API key is held in the Windows Credential Manager — never in the vault, and never in a backup. Privacy Mode redacts what is shown on your screen; it does not redact what is sent to a provider.
5. Information we do collect
When you purchase a license, our payment processor Paddle collects your payment details and email address in order to process the transaction and deliver your license key. This is subject to Paddle's Privacy Policy.
We receive your email address from Paddle solely to deliver your license key. We do not add you to marketing lists without your consent.
The Aethelgard application itself collects no telemetry, crash reports, usage analytics, or any other data from your device.
6. This website
This website (aethelgard.finance) is hosted on Vercel. Vercel may collect standard web server logs (IP address, browser type, pages visited) for infrastructure and security purposes, subject to Vercel's Privacy Policy. We do not use any analytics, tracking, or advertising scripts on this website.
7. License key delivery
After purchase, we send your license key to the email address provided at checkout. We use Resend to deliver this email. Your email address is used only for this purpose and is not retained for marketing.
8. Your rights
Under UK GDPR and applicable data protection law, you have the right to access, correct, or request deletion of any personal data we hold about you. Given that we hold only your email address (for license delivery), requests can be made to contact@aethelgard.finance.
9. Changes to this policy
We will post any material changes to this policy on this page and update the "last updated" date above. Continued use of the software after changes constitutes acceptance.
10. Contact
Questions about this policy: contact@aethelgard.finance