Website and demo privacy
This notice covers phpledger.com and its temporary public demo. Last updated 15 September 2026.
This page explains the separate privacy boundaries of the PHP Ledger website, hosted demo and installed application.
The public website
The marketing pages serve their fonts, images and scripts locally. They contain no analytics or advertising trackers. The support form prepares an email draft in your email application or copies a message for you to review; the website does not submit or store that form.
Following links to GitHub, LinkedIn, supporting companies or an email service takes you to services with their own privacy practices. If you send an email, the maintainer and email providers receive the information you choose to send.
Temporary demo records and sessions
The demo creates a separate fictional company for each visitor and uses a necessary session cookie to keep that visitor's access separate. The cookie is restricted to the demo path, is unavailable to page scripts and is sent securely over HTTPS. It is a browser-session cookie; server session cleanup is configured with a 30-minute lifetime, which is not an exact deletion guarantee.
Demo records reset at the next scheduled UTC hour. Old visitor access stops after the generation expires or changes. A reset may briefly make the demo unavailable. Do not enter customer details, credentials, real financial records or other sensitive information.
Country and currency suggestion
On demo entry, the server may send your public IP address to country.is over HTTPS to suggest a country and base currency. It attempts this once per session, caches failures and skips local/private addresses. You can change the suggestion. The session cache retains the country result, not the raw address or provider response. This lookup does not establish your accounting jurisdiction.
Operational logs and retention
Web-server and hosting logs can include IP addresses, requested paths, timestamps, browser information and error details. Login throttling uses hashes of account/client identifiers. The hourly demo reset clears its database records; it does not promise deletion from web-server logs, session files, email or operational backups.
A fixed retention period for hosting logs and backups has not been established in the application configuration. Access and retention are operator-managed. Avoid putting personal or secret information in URLs or demo fields.
Your own installation
Self-hosted installations store their records on the operator's infrastructure. Their operator controls users, backups, hosting logs and retention. This website notice does not replace that operator's notice or responsibilities.
Contact
For a privacy question or a request concerning information you sent to the project, contact rmak78@gmail.com. Include enough context to identify the request without sending passwords or financial records.
