Privacy policy
Effective October 2, 2026. Operator: Alex Riley. Privacy contact: alex@alexfriley.com.
Purpose and information
This private internal integration connects authorized QuickBooks Online companies and retrieves selected accounting information for internal financial analysis on an owner-controlled computer. Connection information includes app credentials, company identifiers, authorization codes, access and refresh tokens and temporary authorization state. Accounting information may include account, transaction, customer, vendor and report information, including names and financial amounts. Collection is limited to explicitly enabled read operations and authorized company scope. Production activation and live sandbox verification remain pending.
Local storage and processing
The local application stores credentials, tokens and retained accounting data in an encrypted local vault with restricted file permissions. It checks the mounted vault identity before access and stops if custody checks fail. Token exchange, refresh, revocation and accounting requests occur directly between the local computer and Intuit using HTTPS. Tokens and accounting data are not sent to this public website or stored in AWS by this integration. Data is not automatically sent to an external AI service by this integration; any separate analysis service requires its own authorization and disclosures.
Public callback and providers
Intuit provides authentication, company consent and accounting APIs under its applicable terms and policies. Amazon Web Services hosts public pages and the HTTPS callback in US East (N. Virginia). During authorization, a short-lived code, company identifier and state pass through the AWS-hosted callback and browser. The owner copies a one-time response from that page and pastes it into a hidden prompt in the local tool. The response temporarily resides in the local clipboard and browser memory; clipboard-history or synchronization tools may retain a copy. Use a trusted computer, exclude this response from clipboard syncing, replace the clipboard after use and close the callback tab. The callback does not exchange codes or persist those fields. It removes the callback query from the current browser history entry when its script runs, disables caching and referrers, and does not intentionally log request parameters. Browser or provider operational metadata may still exist. API access logging is disabled; configured Lambda operational logs have fourteen-day retention.
Retention and disconnection
Pending authorization state is kept in local process memory and expires after ten minutes. Authorization codes also expire according to Intuit; expiry can require restarting the connection. Current connection records remain in the encrypted vault until disconnected or removed by the owner. Local disconnection revokes the provider token and clears the active local token record after success. Provider-side revocation is also available in QuickBooks. Existing financial exports and analysis records are retained for the authorized project until the owner applies its retention or deletion decision; disconnecting does not erase historical records. Encrypted volume snapshots or backups, if maintained, may retain older copies; disconnection is not a guarantee of physical erasure.
Access, choices and changes
This integration is for owner-authorized internal companies. It does not sell information, run advertising trackers or provide public self-service access. Administrators may request access, correction, disconnection or deletion at alex@alexfriley.com; authority must be verified. Do not email credentials or accounting files. This public site does not set application cookies. Material purpose or data-flow changes will be disclosed before the changed processing begins.