We handle QuickBooks OAuth tokens and real transaction data. Here is exactly how we protect it, with no marketing fluff.
We connect to QuickBooks using Intuit's official OAuth 2.0 protocol, the same standard used by major enterprise software. Here is exactly what we can and cannot do.
You log in to Intuit directly. LedgerAI never sees your QuickBooks username or password. Intuit issues us a short-lived access token (valid 60 minutes) and a refresh token. We use these tokens to read your transactions and update categories. Tokens are stored in our managed PostgreSQL database, which uses volume-level encryption at our hosting provider. We do not currently apply application-layer encryption to individual token fields.
We follow a minimal data principle. We only store what is necessary to run your books review and improve accuracy over time.
| What We Store | Why | Retention |
|---|---|---|
| Your name and email | Account login and notifications | Until account deleted |
| QuickBooks OAuth tokens | Access your QB account during reviews | Deleted when you disconnect QB |
| Transaction summaries (vendor, amount, date, category) | Display your books review history; apply vendor rules | Until account deleted |
| Vendor rules you create | Remembers how to categorize specific vendors for your business | Until you delete them or cancel |
| Audit job history | Track review progress, retry failed updates | 90 days |
| Session tokens | Keep you logged in | 30 days (or until logout) |
| Stripe billing ID | Manage your subscription | Until account deleted |
Full transaction raw data beyond what's needed for your review · Your QuickBooks password · Bank account numbers · Social Security numbers · Tax returns · Any data from third parties.
Technical details for those who want them.
You own your data. We do not.
We use a small number of trusted services to run LedgerAI. Here is exactly what each one sees.
| Service | What They See | Why |
|---|---|---|
| Anthropic Claude API | Vendor name, transaction amount, date, current QB category | AI categorization of unknown vendors. No personal identifiers are sent. |
| Intuit / QuickBooks | OAuth tokens (they issued them) | Required to read and update your QuickBooks data |
| Stripe | Your email and billing info | Subscription billing and payment processing |
| Resend | Your email address and email content | Sending transactional emails (login links, reports) |
| Railway | Hosts all application data | Cloud infrastructure and database hosting |
We do not use Google Analytics, Facebook Pixel, or any advertising tracking on the dashboard or login pages. No one is watching what you do inside your account.
We serve businesses in the United States. We are committed to complying with applicable privacy laws.
We'll answer any question about what we store, how we protect it, and how to delete it. No run-around.
Email [email protected]