LEGAL DOCUMENT
Privacy Policy
Ledesconverter is a web application that helps users create, review, validate, and export LEDES 1998B and Excel billing files from invoice information.
| Field | Value |
|---|---|
| Last updated | 28 July 2026 |
| Provider / Operator | Asuka Yoshida |
| Website | ledesconverter.com |
| Contact | contact@ledesconverter.com |
| Legal form / address | Asuka Yoshida, sole proprietor / Einzelunternehmerin | Thurgaustr. 10, 81475 Munich, Germany | Not registered in the commercial register | VAT identification number: DE456448748 | Tax number: not published |
1. Overview
Ledesconverter is a web application that helps users create, review, validate, and export LEDES 1998B and Excel billing files from invoice information.
Invoice materials may contain confidential client, matter, billing, tax, timekeeper, vendor, and business information. Our privacy approach is that invoice content should be processed only as far as necessary to provide the conversion service and related support, security, billing, and compliance functions.
This Privacy Policy explains how we collect, use, store, share, transfer, and protect personal data and confidential invoice-related information when you use Ledesconverter for personal, professional, freelance, business, law-firm, company, or organizational purposes.
2. Short privacy summary
- Manual mode: you can create LEDES data manually without AI-assisted extraction. In manual mode, we do not intentionally send your PDF invoice to our backend for AI processing.
- AI-assisted mode: if you choose AI-assisted autofill, your PDF invoice is uploaded to our server and sent to our AI provider, currently OpenAI, so that invoice fields and line items can be suggested.
- Review first: AI output is only a draft. You review and edit the data before exporting or using it.
- No AI model training by us: we do not use your invoice PDFs, extracted invoice data, generated LEDES data, or user edits to train our own AI models.
- OpenAI data sharing: we have not opted in to OpenAI API data sharing for model training. According to OpenAI, API data is not used to train or improve models unless the API customer opts in.
- OpenAI retention: we configure supported OpenAI API requests with store:false. Unless Zero Data Retention or Modified Abuse Monitoring is approved and active for our account, OpenAI's standard abuse-monitoring retention may still apply.
- Filename minimization: we do not store original uploaded PDF filenames in application usage events. This reduces the risk that client names, matter names, or other confidential information contained in filenames are retained as usage metadata.
- Custom profile requests are different from ordinary conversions: if you upload reference files for a custom profile, we store those files, filenames, and related metadata temporarily so we can review and configure the requested profile.
- AI-assisted processing: when you select AI-assisted autofill, invoice files and extracted data are handled temporarily on our servers and by our AI provider to provide editable LEDES review data. This does not mean every subprocessor, backup, log, support system, analytics item, or service metadata item is processed in one location.
- No sale of invoice content: we do not sell invoice content and do not use invoice content for advertising.
3. Who we are
For this Privacy Policy, "Ledesconverter," "we," "us," and "our" mean Asuka Yoshida, operating the Ledesconverter service:
Asuka Yoshida | Thurgaustr. 10, 81475 Munich, Germany | Email: contact@ledesconverter.com
Legal form: sole proprietor / Einzelunternehmerin. Commercial register: not registered in the commercial register. VAT identification number: DE456448748. Tax number: not published.
4. Scope of this Privacy Policy
This Privacy Policy applies when you:
- visit ledesconverter.com;
- upload, view, or prepare invoice PDFs;
- use manual LEDES creation;
- use AI-assisted autofill;
- review, edit, validate, or export LEDES or Excel data;
- create an account or sign in;
- purchase a paid plan, subscription, custom profile, or prepaid credits;
- contact us for support, privacy requests, billing questions, or other communications.
This Privacy Policy does not replace any separate data processing agreement we may enter into with business, professional, law-firm, company, or organizational customers.
5. Our role under data protection law
Depending on the activity and user context, we may act in different roles:
- Controller: We usually act as controller for account registration, authentication, billing, subscriptions, analytics, security, product administration, legal compliance, and support.
- Processor: For invoice PDFs, extracted invoice data, generated LEDES review data, profile instructions, and related customer content that we process on behalf of a business, professional, law-firm, company, or organizational customer, we usually act as processor under that customer's instructions.
- Personal use: Where you use the Service for your own personal purposes and not on behalf of another controller, we generally process your personal data as controller under this Privacy Policy.
- Independent providers: Some third-party providers, such as payment providers, authentication providers, and AI providers, may act as processors, subprocessors, or independent controllers depending on the service and their own terms.
6. Data we collect and process
6.1 Account and authentication data
If you create an account or sign in, we may process:
- name;
- email address;
- authentication identifiers;
- account ID;
- session and sign-in metadata;
- account plan and entitlement information;
- private account metadata needed to manage billing and feature access.
Authentication is currently provided through Clerk.
6.2 Billing and subscription data
If you purchase a plan, subscription, credit pack, custom profile, or paid feature, we may process:
- Stripe customer ID;
- subscription ID;
- plan name;
- billing status;
- payment status;
- invoice and tax metadata;
- credit or usage allowance metadata;
- billing-period information.
Payments are processed by Stripe. We do not intentionally store full payment card numbers or card security codes on our own servers.
6.3 Invoice and LEDES content
Depending on the invoice and how you use the Service, invoice-related data may include:
- PDF invoice files;
- invoice numbers;
- invoice dates;
- billing periods;
- law firm and vendor details;
- client and matter references;
- patent, trademark, design, utility model, PCT, EPO, DPMA, EUIPO, WIPO, USPTO, or other IP/legal references;
- timekeeper names, roles, initials, rates, and classifications;
- task, activity, and expense descriptions;
- official fees and disbursements;
- amounts, currencies, VAT/tax information, and totals;
- extracted structured fields;
- AI assumptions, warnings, source references, and confidence information;
- user edits;
- generated LEDES preview text;
- exported LEDES or Excel files.
Invoice materials may contain confidential business information and personal data relating to employees, lawyers, paralegals, billing staff, clients, inventors, applicants, agents, vendors, foreign associates, or other people mentioned in invoice materials.
If you deliberately upload reference files for custom profile setup, such as invoice PDFs, accepted LEDES files, accepted Excel files, billing guidelines, or code lists, we store those files and related metadata for profile setup and review. These custom-profile request files are separate from ordinary AI invoice conversions.
6.4 Usage, security, and quota data
To operate and protect the Service, we may process:
- IP-derived rate-limit information;
- hashed rate-limit bucket identifiers;
- user ID;
- route/request timestamps;
- request counts;
- AI usage event IDs;
- plan and profile IDs;
- processing status, such as pending, succeeded, or failed;
- error status or error message;
- browser, device, performance, and referrer information;
- application logs needed for security, debugging, abuse prevention, and reliability.
We aim not to log full invoice contents in production. The application database is designed for account, billing, usage, credit, rate-limit, webhook, and custom-profile request records rather than permanent storage of ordinary invoice-conversion PDFs or full extracted invoice contents. Files deliberately uploaded with a custom-profile request may be stored for owner review and profile setup.
We do not store original uploaded PDF filenames in application usage events. If a technical identifier is needed for usage accounting, support, or debugging, it should not contain the original filename or human-readable client/matter information.
6.5 Analytics data
We may use Vercel Web Analytics and privacy-limited internal product analytics to understand how the website and conversion workflow are used, diagnose performance issues, and improve the product. Vercel Web Analytics is designed as a privacy-focused analytics service that does not use cookies and provides aggregated statistics rather than individual user profiles.
Analytics data may include page views, visited URLs or routes, referrers reduced to hostnames, approximate country, device type, browser, operating system, event timestamps, workflow stages, processing mode, profile identifiers, field names, validation categories, export formats, performance measurements, sanitized UTM source/medium/campaign labels, and the first landing-page path. For signed-in accounts, we may record first-touch attribution and account milestones such as registration, first upload, first successful conversion, first export, and first payment so we can understand product activation and acquisition performance.
First-touch attribution is stored once and is not overwritten by later visits. We do not store full referrer URLs, raw IP addresses for analytics, invoice values, descriptions, filenames, PDFs, client names, matter names, tokens, or other invoice content in internal product analytics.
The Service may use essential cookies, local storage, IndexedDB, or similar browser storage for authentication, security, checkout recovery, account-related flows, and core application functionality. These are separate from optional analytics or marketing technologies.
Where legally required, we will ask for consent before using non-essential cookies or similar technologies.
6.6 Support communications
If you contact us, we may process your name, email address, message content, attachments you choose to send, and related support history.
Please do not send invoice PDFs, client-confidential materials, or sensitive personal data to support unless necessary for your support request. If you do send such materials, we may process them to respond to your request and as described in this Privacy Policy.
7. Manual mode
Manual LEDES creation is designed for users who want to enter and edit LEDES data without AI-assisted invoice extraction.
In manual mode:
- the Service creates an editable LEDES workspace;
- no AI-assisted extraction is used;
- no OCR or automated PDF text extraction is performed by our AI workflow;
- generated LEDES and Excel exports are created from the data you enter or edit.
Temporary data may remain in your browser session while you work. You are responsible for downloading and saving your exports and source records. Manual mode is not intended to be your archive, accounting system, billing system of record, document-management system, or legal file.
If you start checkout or account-related flows after selecting a PDF, the application may temporarily store the pending PDF upload locally in your browser's IndexedDB for up to one hour so that the upload can be restored after checkout. This local browser copy is not uploaded to our server unless you choose AI-assisted processing or submit the file through another server-side feature.
If you complete a custom-profile request before checkout, the application may temporarily store the request draft and selected reference files locally in your browser's IndexedDB for up to one hour so the request can be restored after checkout. The draft and files are not submitted to our server until profile access or payment is confirmed and you submit the request.
8. AI-assisted mode
AI-assisted autofill requires sign-in.
When you choose AI-assisted processing:
- You upload a PDF invoice.
- Our server performs basic validation and preflight checks.
- The invoice PDF is transmitted to our AI provider, currently OpenAI, for extraction.
- The Service returns editable structured data, including invoice fields, line items, assumptions, warnings, source references, and suggested codes.
- A second AI review pass may be used to improve consistency of the structured result.
- You review, correct, validate, and export the final result.
AI-assisted output may be incomplete or incorrect. You are responsible for reviewing all fields, amounts, codes, dates, taxes, descriptions, client/matter references, and exported files before use. For contractual review, recordkeeping, and submission responsibilities, see the Terms of Service.
LEDES and Excel export files are generated for download by the user. The Service is not intended to retain exported files as a document repository.
9. OpenAI and AI processing
We currently use the OpenAI API for AI-assisted invoice extraction and review.
We do not use invoice PDFs, extracted invoice data, generated LEDES data, or user edits to train our own AI models.
We have not opted in to OpenAI API data sharing for model training. According to OpenAI's current API data controls, API inputs and outputs are not used to train or improve OpenAI models unless the API customer explicitly opts in.
We currently use the standard OpenAI API endpoint and do not currently use OpenAI regional data residency, Zero Data Retention, or Modified Abuse Monitoring unless a different endpoint or retention configuration is enabled in our deployment environment.
Invoice PDFs and extracted invoice content sent to OpenAI for AI-assisted processing may be processed in locations determined by OpenAI's applicable API terms, data processing terms, infrastructure, and transfer safeguards.
We configure supported OpenAI Responses API requests with store:false. We have not opted in to OpenAI API data sharing for model training.
Unless Zero Data Retention or Modified Abuse Monitoring is approved and active for our account, OpenAI's standard abuse-monitoring retention may still apply. Using store:false is not the same as OpenAI Zero Data Retention.
10. Hosting and processing location
Our application is hosted on cloud infrastructure. When AI-assisted autofill is selected, invoice files and extracted data are handled temporarily on our servers and by our AI provider to provide editable LEDES review data.
However, the Service also relies on third-party providers, including AI, authentication, payment, analytics, database, hosting, and infrastructure providers. Those providers may process certain data in other locations according to their own infrastructure, contracts, data processing terms, and transfer safeguards.
We do not claim that every subprocessor, backup, log, support operation, analytics item, or category of service metadata is processed exclusively in one country or region.
11. Purposes and legal bases
Where GDPR or similar laws apply, we process personal data for the following purposes and legal bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Provide manual LEDES creation | User-entered invoice/LEDES data | Contract performance; legitimate interests; controller processing for personal use where applicable |
| Provide AI-assisted extraction | Uploaded PDFs, extracted data, generated review data | Contract performance for personal/controller-side processing; processor activity under business-customer instructions where applicable |
| Authenticate users | Account and session data | Contract performance; legitimate interests |
| Manage subscriptions, credits, and payments | Billing, plan, subscription, usage, credit, tax/payment data | Contract performance; legal obligation; legitimate interests |
| Enforce AI usage limits | Usage events, plan data, profile ID, status, and technical metadata | Contract performance; legitimate interests |
| Secure the Service and prevent abuse | IP-derived data, hashed rate-limit buckets, logs | Legitimate interests; legal obligation where applicable |
| Improve reliability and usability | Analytics, performance, error data, operational metadata | Legitimate interests or consent where required |
| Provide support | Contact data, support messages, voluntary attachments | Contract performance; legitimate interests |
| Comply with law and enforce rights | Relevant account, billing, security, transaction, and support data | Legal obligation; legitimate interests |
When we process invoice content as processor on behalf of a business, professional, law-firm, company, or organizational customer, that customer is responsible for determining the lawful basis for the underlying personal data contained in the invoice.
12. Required and optional data
Some data is necessary to provide the Service. Account and billing data is needed for account-based and paid features. Invoice content is needed only if you choose AI-assisted processing or submit files for a custom profile. If you do not provide the necessary data, the relevant feature may not work. Manual LEDES creation may be available without uploading invoice content to our server.
13. Sharing, service providers, and subprocessors
We use carefully selected third-party service providers to operate Ledesconverter. These may include providers for hosting, infrastructure, database services, authentication, payment processing, analytics, email or support communications, security, logging, and — if you choose AI-assisted processing — AI-assisted invoice extraction and review.
In AI-assisted mode, invoice PDFs and extracted invoice content are sent to our AI provider, currently OpenAI, for the purpose of generating editable invoice and LEDES review data.
Payment data is processed by our payment provider, currently Stripe. Authentication and account data may be processed by our authentication provider, currently Clerk. Hosting, infrastructure, database, analytics, logging, and support providers may process technical, account, usage, security, and operational data as needed to provide, secure, and maintain the Service.
Where these providers process personal data on our behalf, we enter into data processing agreements where required. Some providers may act as independent controllers for certain activities, such as payment processing, fraud prevention, tax, legal compliance, account-security, analytics, or account-administration functions, depending on their own terms and the processing context.
A current list of subprocessors and relevant provider details is maintained in our Data Processing Addendum / Subprocessor List.
We do not sell invoice content. We do not knowingly share invoice content for behavioral advertising.
14. International transfers
Some providers may process personal data outside your country or region.
Where required by law, we rely on appropriate safeguards, such as adequacy decisions, standard contractual clauses, data processing agreements, the EU-U.S. Data Privacy Framework where applicable, and additional technical or organizational measures.
If you require specific regional processing commitments, contact us before using AI-assisted mode. At this stage, unless separately agreed in writing, we do not promise that all subprocessors process all data exclusively in one region.
In particular, we currently use the standard OpenAI API endpoint for AI-assisted invoice processing unless a different endpoint is configured.
15. Retention
We retain personal data only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required by law.
| Data type | Retention period |
|---|---|
| Manual-mode browser session data | Until you reset the workflow, refresh/close the browser session, clear browser storage, or export/save it yourself. |
| Pending checkout and custom-profile request recovery data in browser IndexedDB | A pending PDF upload, or a completed custom-profile request draft with selected reference files, may be stored locally in your browser for up to one hour to restore the workflow after checkout. This local copy is not submitted to our server unless you choose AI-assisted processing or submit the custom-profile request through the relevant server-side feature. |
| AI-uploaded PDFs in our application | Temporary processing only; not intentionally stored permanently in our application database. |
| AI extraction results in our application database | Not intentionally stored permanently in our application database. |
| AI provider API data | Subject to OpenAI's API data controls and retention terms; default API abuse-monitoring retention may apply. |
| AI usage events | Failed or stale pending events are deleted after 90 days. All AI usage events are deleted after 24 months. |
| AI usage periods | Deleted after 24 months once related AI usage events are gone. |
| Original uploaded PDF filenames | Not stored in application usage events. |
| Rate-limit buckets | Deleted after expiry through retention cleanup. |
| Processed Stripe webhook event IDs | Deleted after 12 months. Used to prevent duplicate processing of Stripe webhook retries. |
| Internal product analytics events | Deleted after 180 days. These events are limited to workflow stages, conversion/session identifiers, account ID when signed in, processing mode, profile identifiers, field names, validation categories, export formats, and timestamps; they do not intentionally contain invoice values, descriptions, filenames, PDFs, client names, or matter data. |
| Account attribution and activation milestones | First-touch source, medium, campaign, referrer hostname, landing-page path, approximate country, and first upload/conversion/export/payment timestamps are kept with the account until account deletion, unless a longer period is required for billing, legal, security, or dispute purposes. Full referrer URLs and raw IP addresses are not stored for this analytics purpose. |
| Custom profile configuration and access metadata | Kept while the profile is active. If a subscription or membership ends, profile access may be suspended and kept available for reactivation for up to 90 days, then archived or deleted unless longer retention is needed for legal, billing, support, security, or dispute purposes. |
| Custom profile request metadata | Request details, requester contact details, selected reference-file categories, listed reference-file names, and uploaded-file metadata are kept while the request is reviewed and for up to 24 months afterward unless longer retention is needed for legal, billing, support, security, or dispute purposes. |
| Custom profile request file contents | If you upload custom-profile setup files, their contents are stored for profile setup and review. After a profile is activated or implemented, file contents are normally retained for up to 30 days for troubleshooting and then deleted. Pending or unresolved request file contents may be retained for up to 180 days while setup/review is ongoing and then deleted if no longer needed. Longer retention may apply where required for legal, billing, support, security, or dispute purposes. |
| Account data | Until account deletion request plus any backup, legal, security, billing, dispute, or accounting period that applies. |
| Billing, subscription, invoice, and tax records | As required by tax/accounting law. |
| Support communications | We generally retain support communications for up to 24 months after the last support interaction, unless a longer period is needed for legal claims, disputes, billing, security, or compliance. |
| Security logs | We generally retain security logs for up to 180 days, unless a longer period is needed for investigation, abuse prevention, legal claims, security, or compliance. |
16. Security
We use technical and organizational measures designed to protect personal data and confidential invoice information, including:
- HTTPS/TLS encryption in transit;
- server-side protection of API keys and secrets;
- authentication for account-based and AI-assisted features;
- file type and size checks before AI processing;
- PDF preflight checks before AI processing;
- request rate limiting;
- hashed rate-limit identifiers;
- database access controls;
- limited operational access;
- no intentional permanent database storage of ordinary invoice-conversion PDFs;
- no original uploaded PDF filenames stored in application usage events;
- no-store headers for AI extraction responses;
- supported OpenAI Responses API calls configured with store:false;
- vendor data processing agreements where applicable.
No online service can guarantee absolute security. You are responsible for using strong credentials, limiting account access, and ensuring that invoices are appropriate for processing through the Service.
If a personal data breach occurs that affects your personal data, we will assess it without undue delay and, where the breach is likely to result in a risk to your rights and freedoms, notify the competent supervisory authority and, where required by law, the affected individuals, in line with applicable data-protection law.
17. Your responsibilities when providing invoice materials
If you upload or process invoice materials relating to another person, client, employer, law firm, company, or organization, you are responsible for ensuring that you have permission and an appropriate legal basis to provide the data to Ledesconverter and to use the relevant processing mode.
For service-use, review, billing, export, recordkeeping, deadline, and submission responsibilities, see the Terms of Service.
Ledesconverter is a software tool. It does not provide legal, tax, accounting, billing, e-billing, or professional-responsibility advice.
18. Sensitive data
You should not upload special-category personal data, health data, children's data, government identification numbers, criminal-offence data, or other highly sensitive data unless it is strictly necessary, lawful, and permitted by your organization's policies or your own legal basis and applicable law.
Invoice materials should be limited to information necessary for billing, review, LEDES creation, and related workflows.
19. Your rights
Depending on your location, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- delete personal data;
- restrict processing;
- object to processing;
- receive a portable copy of certain data;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority.
To exercise rights, email contact@ledesconverter.com. Please include enough information for us to identify your account and respond to your request.
If you use the Service for personal purposes and we act as controller, we will handle your request directly where applicable. If we process invoice content as processor on behalf of a business or organization, we may direct your request to that customer or cooperate with that customer as required by law.
20. Children
Ledesconverter is not directed to children, and we do not knowingly collect personal data from children. The Service is intended for users who are legally capable of using the Service, whether for personal, professional, freelance, business, law-firm, company, or organizational purposes.
21. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice.
22. Contact
Asuka Yoshida | Thurgaustr. 10, 81475 Munich, Germany | Email: contact@ledesconverter.com
Questions about these documents? Contact contact@ledesconverter.com.