What we collect, what we do with it, and — the part that matters most for this service — how quickly it goes away.
Effective date: August 20, 2026
Sealed Ledger is a service offering of Ubiquitous LLC ("we", "our", or "us"). We capture accounting records from platforms such as QuickBooks Online and QuickBooks Desktop into cryptographically sealed, independently verifiable archives, and we run migrations between accounting platforms.
This policy describes how we handle information. The short version, because it is unusual enough to state up front: we are a non-custodial service. We capture your records, deliver them to you, and delete our copy. We do not keep an archive of past engagements, we do not maintain a searchable index of client data, and we cannot produce a copy of something we delivered to you last year. That design is described in full on the Custody & Handoff page, and this policy is the binding statement of it.
G-MP07W97N7R) to measure traffic. Analytics is not loaded on our tool pages or in any authenticated session.We use information solely to:
We do not use your accounting data to train machine-learning models, to build benchmarks or industry datasets, or for any purpose beyond the engagement you commissioned. We do not sell, rent, or trade your information, and we do not share it for anyone's marketing purposes.
For the accounting data we capture, you are the controller and we act as a processor on your documented instructions. We connect to the platform because you told us to, we retrieve what you asked us to retrieve, and we deliver it where you told us to deliver it.
We perform no independent review of the contents. Our systems parse, structure, hash, and seal the data; no person at Sealed Ledger reads your records except where you have specifically engaged us to analyse them, or where a defect requires investigation and cannot be diagnosed any other way.
Where your accounting records contain tax return information and we are engaged by or on behalf of a tax return preparer, additional obligations may apply to both of us under U.S. federal law. If you are a CPA, enrolled agent, or other preparer engaging us on behalf of a client, tell us at the outset so the engagement terms can reflect it.
We do not sell your data. We share it only with the following, and only as needed to operate the service:
We will disclose information where legally compelled to do so. Our retention practice means that for most past engagements there is nothing left to disclose — which is a deliberate consequence of the non-custodial design, not an accident of it.
No system is perfectly secure, and we do not claim otherwise. What we can say is that the quantity of client data resident on our systems at any moment is small and short-lived by design.
There is one point in our workflow where the non-custodial model does not hold, and we would rather state it than let you discover it.
QuickBooks Desktop capture runs on your own machine. Our capture tool writes its bundle as an encrypted file using AES-256-GCM under a per-bundle key that we generate and hold in our bundle registry. We release that key to you, and on release the key is deleted from the registry and the deletion time is recorded.
Between capture and release, we hold a key that would decrypt a bundle sitting on your machine. We do not hold the bundle. After release we hold neither. If you lose the key after we have deleted it, we cannot recover it and neither can anyone else.
QuickBooks Online bundles involve no such key. They are delivered unencrypted over an authenticated, TLS-protected connection, and confidentiality after delivery is yours to manage.
This section is the operative one for this service.
We hold a working copy of your captured data on our secured server for as long as the engagement is active, and use it only for the work you commissioned. Diagnostic logs written during capture and migration runs may contain identifying details from your records — customer and vendor names, document numbers, amounts — because that is what makes a failed record traceable.
We delete immediately: the working copy of your archive, any plaintext or encrypted bundle held on our systems, the staged migration ledgers, and the diagnostic logs from your engagement. Deletion happens at close, not on a schedule that runs later.
Engagement-record metadata only: an engagement identifier, its dates, a scope description, and a list of deliverables produced. No accounting data, no customer or vendor names, no financial figures. We keep this because we need a record that the work happened.
We keep your account credentials for as long as you have an account with us, and correspondence for as long as is reasonable for the business relationship.
You may request deletion of your account and any associated information at any time by writing to admin@ubiquitous.llc. We will action it within 30 days, subject to any legal obligation to retain limited records.
Once a sealed archive is in your hands, it is yours and its handling is yours. This is worth being explicit about, because a sealed archive is a complete and unusually convenient copy of your books.
The archive contains identifiable personal information about your customers, your vendors, and your employees, and where attachment capture was in scope, the supporting documents themselves. It is not encrypted by the seal — the seal proves the contents have not changed, which is a different property from preventing someone reading them. Anyone holding the file can read it.
We would encourage you to store it on encrypted storage, control who can reach it, and keep a record of who has handled it. If you open the archive with an AI assistant, a cloud analytics tool, or any other third-party service, you are disclosing that data to that provider under their terms, and the decision and its consequences are yours. None of this is a limitation of the seal; it is the ordinary responsibility that comes with holding your own records.
We capture only what the source platform exposes through its documented API. Where the platform does not expose something, we do not have it and the seal does not attest to it.
The clearest example is the QuickBooks Online audit log. QuickBooks Online provides no audit-log API, so we cannot retrieve it. If you export it yourself and give us the file, it can be carried alongside the archive and cross-checked, but it sits outside the sealed perimeter and carries none of the API-captured provenance that every other record in the archive carries. We say so in the archive itself rather than leaving you to work it out.
Every archive ships with a LIMITATIONS.txt disclosing what that particular capture did and did not cover, including anything that failed. The general boundaries are set out in our threat model.
Depending on where you live, you may have the right to access a copy of the personal information we hold about you, to have inaccurate information corrected, to request deletion, and to withdraw consent by revoking our access to a connected platform at any time.
Write to admin@ubiquitous.llc to exercise any of these. We do not charge for it and we will not treat you differently for asking.
One practical note: for personal information belonging to your customers, vendors, or employees that appears inside your accounting records, you are the controller. Requests from those individuals should be directed to you, and we will support you in responding to them.
Sealed Ledger is a business service and is not directed at children. We do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it.
We may update this policy. When we do, we will revise the effective date at the top. Where a change materially reduces the protections described here, we will say so rather than let it pass as a routine revision.
Questions about this policy or our data practices:
Ubiquitous LLC
Email: admin@ubiquitous.llc
See also our Terms of Service.