This policy explains what data the QuickBooks AI Categorizer ("the Service") accesses, how it is used, and how it is protected. The Service is operated by Dilan Del Valle Mijangos, an independent software developer ("we", "us").
The Service connects to a customer's QuickBooks Online company, reads transactions that have not yet been assigned an account, proposes a category for each one, and — only after the customer approves — writes that category back to QuickBooks.
Through Intuit's official API, and only with the customer's explicit authorization, the Service reads:
The Service writes back exactly one thing: the account assigned to a transaction, and only after that assignment has been approved by the customer.
We never request, receive or store: QuickBooks passwords, bank or credit card login credentials, full card or account numbers, payroll or employee records, or Social Security numbers. Authorization happens entirely on Intuit's own pages, so credentials are never entered into, or transmitted through, our systems.
To propose a category, the Service may transmit a limited description of a transaction — typically the vendor or payee name, the description text, and the amount — to a third-party large language model provider (Anthropic) for analysis. This is disclosed plainly because it is a real transfer of data outside our systems.
Authorization uses OAuth 2.0. We store the access and refresh tokens issued by Intuit solely to maintain the connection. Tokens are stored encrypted, are never shared with third parties, and are deleted when the connection is revoked.
Data is used exclusively to operate the Service for the customer it belongs to: proposing categories, learning that customer's correction rules, and producing reports and dashboards for that customer. We do not sell, rent, license or share customer data with any party for advertising, profiling, resale or any purpose unrelated to providing the Service.
A customer may disconnect the Service at any time from QuickBooks under Settings → Apps, or by contacting us. Revocation immediately ends all access; no further data can be read or written.
All communication with Intuit and with third-party providers occurs over encrypted HTTPS connections. Credentials and tokens are stored encrypted and access is limited to what is required to operate the Service. No system is perfectly secure, and we make no claim otherwise; we do commit to notifying affected customers promptly if we become aware of a breach involving their data.
The Service is a business accounting tool and is not directed to, or intended for use by, anyone under 18.
If this policy changes in a way that materially affects how customer data is handled, connected customers will be notified before the change takes effect.
Questions, deletion requests, or privacy concerns: dilandelvallemijangos@gmail.com