How it works
There is no server here. The accounting is hledger's own program, compiled and running in the page you have open, and your journal is a text file that stays one.
hledger is the program, not a copy of it
Plain-text accounting tools usually reimplement the format: they read a journal, decide what they think it means, and answer from that. This does not. hledger-lib — the library hledger itself is built on — is compiled to WebAssembly and asked the questions the screens ask.
So a balance here is the balance hledger reports, arrived at the same way, including the parts nobody thinks about until they bite: how a posting without an amount is worked out, what a commodity is, which of two dates counts. When hledger changes, this can follow it rather than catch up with it.
The journal stays the file it is
Entries are added at the end. Nothing already in the file is rewritten, reordered or reformatted, so a journal you have kept by hand stays as you wrote it and a diff shows what changed rather than everything.
Anything this app does not understand is carried through untouched — directives, comments, styles of writing it has no screen for. It is your file, and it is still a file: open it in hledger on a laptop and it is the same journal.
Nothing is kept that hledger would not read
Every write is offered to hledger before it is kept. The new text is read as a whole journal, and only if that read succeeds does it become the file. A change that would not parse leaves the journal exactly as it was, and says what hledger objected to and on which line.
This is why an entry written here and an entry typed by hand are the same thing: both have to get past the same reader.
Where the file is while you are working
On the device, in the browser's own storage, one journal per set of books. Nothing is uploaded to run it — the program is in the page and so is the file, which is why it works with no signal at all.
Sending it anywhere is a separate act, done to a repository of your own and only when you ask.
Money is never a float
Amounts are carried as a whole number and a scale — 1234 and 2, for 12.34 — and rendered from those. Nothing here ever adds two decimals as floating point, because that is how a column of figures comes to end in a penny nobody can account for.
It answers programs as well as people
Opening the app puts a `window.choai` in the page: the same core the screens use, answering a script, a test, or an agent. It is not a web API and cannot be reached by fetching an address — there is no server to ask.
What it offers are named acts, the same ones the screens perform. There is no way to run code through it, no way to write a file as raw text, and no way to read back the keys or tokens the app holds.