Accounting Apps

Privacy & Data Handling

This notice describes the personal and financial information this service holds on behalf of the accounting firms that use it, why it is held, where it lives, and how to have it removed. It is written to be read, not to be survived.

Last updated 2 September 2026

1. Who is responsible for what

Our customers are accounting and bookkeeping firms. Most of the information in this service is about their clients and employees, not about them. Under Canadian privacy law the firm is the organisation accountable for that information; we process it on the firm’s instructions and for no purpose of our own.

In practice that means: if you are a business owner or an employee whose information is in here, your first point of contact is your accountant. If they need us, this notice tells them — and you — exactly what we hold.

2. What we hold

InformationWhere it comes from
Bank and credit-card statement PDFs, exactly as uploadedUploaded by the firm
Transactions read out of those statements — date, description, amount, payee, categoryParsed from the PDF on our own server
Statement details — institution, account number as printed, period, opening and closing balancesParsed from the PDF
Cheque images — the front and back scans that appear inside a statementExtracted from the PDF
Payroll information — employee names, wages, hours, and Social Insurance NumbersEntered or imported by the firm, where the payroll feature is used
QuickBooks connection tokensIssued by Intuit when the firm authorises the connection
Vendor, customer and chart-of-accounts listsRead from the connected QuickBooks company
User accounts — username, email address, role, and a one-way hash of the passwordCreated by the firm’s administrator
Activity records — who did what and when, and which screens were visited, with timing and IP addressRecorded automatically

Activity records deliberately store the shape of a page address and never its contents — /statements/batches/:id, not the batch, and never a payee, an amount or a document.

3. Why we hold it

  • To do the work you asked for — read a statement, propose a category for each transaction, and post the ones you approve to your QuickBooks company.
  • To let you check the work — the original document stays available beside the parsed result, so a number can always be traced back to the page it came from.
  • To keep the service secure and accountable — sign-in records, the audit trail, and rate limiting against password guessing.
  • To keep the service running — aggregate usage figures showing which screens are used and how fast they respond.

Social Insurance Numbers are held for one reason only: they are required on the T4 and payroll filings the payroll feature produces. They are used for nothing else.

We do not sell this information, we do not share it for advertising, and we do not use it to train machine-learning models.

4. Where it is stored

On a single dedicated server in Boston, Massachusetts, in the United States. Both the database and the uploaded documents live there. We state the location plainly because it is the question that matters most and the one most often answered vaguely.

Storing Canadian personal information outside Canada is permitted under Canadian privacy law, provided you are told about it — which is the purpose of this section. While the information is in the United States it is subject to the laws of that country, including legal processes under which US authorities may compel access. Our contracts and our configuration cannot override that, and we will not pretend otherwise.

For firms with Canada Revenue Agency record-keeping obligations: the CRA takes the position that books and records should be maintained in Canada unless it has given written permission otherwise, and that being able to reach records from Canada is not the same thing. Your books of record remain your QuickBooks company and your own files; this service holds working copies of the documents you upload to it. If your practice requires Canadian residency for this data, tell us — it changes what we would need to build, and we would rather know before you sign than after.

5. Who else can see it

The most important fact in this notice: your statements are read on our own server. Document text is extracted by our own software, in our own process. No statement, cheque image or transaction is sent to any third-party document-scanning, OCR or artificial-intelligence service. There is no sub-processor that sees your documents.

The complete list of outside parties involved in running the service:

PartyRoleWhat they can reach
Hostinger InternationalHosting provider for the serverThe machine the service runs on. They do not use the data; they can, like any hosting provider, technically reach the disk.
Intuit (QuickBooks Online)The accounting system you are posting toOnly the transactions you explicitly approve and send. This is the purpose of the product, and it goes to your own QuickBooks company.
Google (Gmail)Outbound email, only if your firm turns it onMail is sent from your firm’s own mailbox using your own credentials, not through a shared relay. Only what you put in the message.
Let’s EncryptIssues the certificate that encrypts your connectionNothing. Certificate issuance involves no customer data.

6. How long we keep it

  • Statements, transactions, cheque images and payroll records are kept for as long as your firm keeps them in the service. Deleting a statement batch, a client or a whole firm removes the database records and the stored files. Deletion is permanent and is not reversible by us.
  • Activity records are deleted automatically after 90 days.
  • The audit trail of who did what is kept for as long as the firm’s account exists, because a record of activity that can be trimmed on request is not an audit trail.

Deletion is your decision, and it has a floor. Canadian tax law generally requires a business to keep its books and supporting documents for six years from the end of the last tax year they relate to. We will delete anything you ask us to delete, whenever you ask — but we will not decide on your behalf that a record has aged out, and you should satisfy yourself that you hold it elsewhere before removing it here.

7. How it is protected

  • In transit — every connection uses TLS with an automatically renewed certificate. There is no unencrypted route into the service.
  • Passwords are never stored. We keep a one-way PBKDF2-SHA256 hash at 260,000 iterations with a unique salt, so nobody — including us — can recover a password from what we hold.
  • QuickBooks tokens, Social Insurance Numbers and email credentials are encrypted at rest with AES before they are written to the database.
  • The database is not reachable from the internet at all. It listens only on a private network inside the server.
  • Access is re-checked on every single request against the database, not merely trusted from a sign-in token. Withdrawing someone’s access takes effect immediately rather than whenever their session happens to expire.
  • Each firm’s data is isolated at the query layer. A request for another firm’s records is answered “not found”, so nothing belonging to another firm is even discoverable.
  • Sign-in is rate-limited against password guessing, and the service refuses to start at all if it is configured with a default credential.

Security is a programme, not a state. We maintain a written assessment of our own gaps and a dated plan for closing them, and we will discuss it candidly with any firm evaluating us. Ask.

8. Who at our end can read it

Being straightforward about this is worth more than a reassuring sentence. Our platform administrator account can reach customer data — that is what makes support, recovery and investigation possible, and no small provider that tells you otherwise is being accurate. What constrains it:

  • It is a small number of named people, not a support department.
  • Actions are written to the audit trail, under the name of whoever took them.
  • It is used to operate the service and to answer your requests — never to browse.

Within your own firm, who sees what is your choice: the service has five roles, and a read-only role is genuinely read-only at the server, not merely hidden in the interface.

9. Your rights

Under the Personal Information Protection and Electronic Documents Act and its provincial equivalents you may ask what personal information is held about you, ask for a copy, ask that it be corrected, and challenge how it is handled.

If your accountant uses this service, ask them first — they hold the relationship and can usually answer immediately from within the application. If they need us, or if you would rather come to us directly, write to the address below. We will respond within 30 days, which is the period the Act allows.

If our response does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada, or to your provincial commissioner where one has jurisdiction. We will not treat that as a hostile act.

10. If something goes wrong

We maintain a written procedure for handling a security incident and a register of every incident we become aware of, whether or not it is reportable.

If a breach creates a real risk of significant harm to anyone whose information we hold, we will report it to the Office of the Privacy Commissioner of Canada and notify the affected firm as soon as feasible, with what we know, what we do not yet know, and what we are doing about it. We would rather tell you early and imprecisely than late and neatly.

11. Contact

Questions about this notice, requests about your own information, and reports of a security problem all go to the same place:

privacy@futuristicai.cloud

If you believe you have found a security vulnerability, please write to us before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.