Privacy Policy

Last updated: 9 September 2026

This policy covers the QuickBooks Online integration ("the App") operated by Copper & Cloud ("we", "us"). The App connects a QuickBooks Online company to an AI assistant (Claude Code) running on our own computer.

Who this App is for

The App is private and single-tenant. It is used solely by Copper & Cloud to access our own QuickBooks Online company data. It is not offered to, marketed to, or usable by the public, and it does not onboard third-party users.

What data the App accesses

When authorised, the App can read and write records in the connected QuickBooks Online company via Intuit's API, including: invoices, bills, payments, customers, vendors, employees, chart of accounts, journal entries, and financial reports.

The App accesses this data only when we actively run it. It does not run on a schedule and does not continuously sync.

Where data goes

Credentials

OAuth client credentials and refresh tokens are stored in a single local file with owner-only file permissions on our own machine. They are excluded from version control. They are not transmitted anywhere except to Intuit, for authentication.

Retention

We retain no separate copy of QuickBooks data. The authoritative record remains in QuickBooks Online. Access can be revoked at any time from the QuickBooks company's connected-apps settings, which immediately invalidates the App's tokens.

Security

Access is limited to authorised personnel of Copper & Cloud. Communication with Intuit's API uses TLS. Tokens rotate automatically and are stored with restricted file permissions.

Changes

Material changes to this policy will be published at this URL with an updated date above.

Contact

Questions about this policy: info@coppercloud.com.au