Help center/Your account

Security and privacy

How Caribooks protects your QuickBooks access, what it keeps and for how long, which AI models read your documents, and how to disconnect or delete it all.

Updated

This page sums up how Caribooks handles your books and your files. The full texts are on the security page and in the privacy policy; where this summary and the policy differ, the policy wins.

Your QuickBooks connection

You connect a company by signing in to Intuit, on Intuit's own page. Caribooks never sees your QuickBooks password. Intuit hands Caribooks a token that opens that company's books, and Caribooks stores it encrypted (AES-256).

Every company starts Read-only: your assistant can read reports and records and cannot change anything. Only the account owner can switch a company to Full access, on Settings → Companies. Even with full access, deleting, voiding or sending a record needs your explicit confirmation in the conversation. Details in Access and confirmations.

Your account is closed to other accounts

Each account's data is kept apart in the database: every query runs on behalf of the signed-in account, and the database cannot be reached from the browser at all. Files sit in private storage under each account's own folder. A QuickBooks company can be connected to one Caribooks account only; anyone else who needs it asks to join your team, and you decide.

Signing in uses a link or an 8-digit code sent to your email, or your Google or Microsoft account. Caribooks has no password of its own to steal.

What Caribooks keeps

Your ledger stays in QuickBooks. When you ask your assistant a question, Caribooks reads QuickBooks and passes the answer along; it keeps no synchronized copy of your books.

Caribooks does keep:

  • your email, your companies' names and connection details, billing and usage records;
  • the rules and loop instructions you save;
  • for Autopilot, each run's history and the changes it proposed, which can quote QuickBooks data, plus what is needed to undo a change;
  • the files in your document box and the details read from them (vendor, date, total, lines).

How long:

  • A receipt file is removed from storage once it is attached in QuickBooks.
  • A copy of a document QuickBooks already has is removed after 30 days.
  • Every other file stays until you delete it.
  • Account data stays until the account is closed or you ask us to delete it.
  • Rules and Autopilot history stay until you disconnect their company, the account is closed, or you ask us to delete them.
  • Deleted data can remain in an encrypted database backup for up to 7 days.

Which AI reads what

Your assistant. Claude, ChatGPT or Microsoft Copilot receives your questions and the QuickBooks data that answers them, under that provider's policy and your settings with them.

Caribooks' own model use. Some work runs on an open model, GLM 5.3 Flash, reached through OpenRouter and hosted by Together AI, DigitalOcean, Modal or Parasail, and no other host:

  • reading each document once, to note its vendor, date, total and lines;
  • sorting a document between companies, only when your rules and the companies' details cannot settle it and you have several companies;
  • loops, turning your sentence into a loop, and vendor portal setup;
  • learning how a vendor's invoices arrive in a mailbox you connected.

Document reading and sorting require hosts that keep nothing and collect nothing. Loops are sent under a no-retention, no-training setting. A loop written earlier keeps the model it was set up with. The text sent is not anonymized and can contain personal or banking details. Caribooks does not sell your data or use it to train models of its own.

Where it is stored

The database and files are in Canada (AWS region ca-central-1). Some processing happens elsewhere: Autopilot run state is kept in the United States, vendor portal sessions run in the United States, and model hosts may process requests outside Canada. The privacy policy lists every provider.

Caribooks has no SOC 2 audit. To report a vulnerability, write to support@caribooks.com.

Signing out, disconnecting, deleting

Signing out of the portal (Sign out) ends the session in that browser only. Your assistants stay connected and keep working.

Stopping an assistant: remove the Caribooks connector in that assistant's own settings.

Disconnecting a company: on Settings → Companies, the owner presses Disconnect next to it and confirms. Caribooks revokes its token with Intuit and every assistant and loop loses access to that company at once. It also deletes the company's loops and their run history, its changes in Approvals, its rules, its vendor settings and portals, and its expense claims. Its documents stay in the document box until you delete them. See Connect QuickBooks. You can also revoke access from your Intuit account.

Removing a person: when the owner removes a team member, that person's assistant loses access to your companies right away.

Deleting your account: there is no delete button. Write to support@caribooks.com. We confirm the request and complete it within 30 days: every company and mailbox is disconnected, the files and the account are deleted, and our reply names anything that must be kept. Invoices and payment records are kept six years for Canadian tax law, at Stripe; they hold no QuickBooks data. The same address handles requests to see or correct your personal information.

Ask your assistant

  • "Which Caribooks companies can you reach, and are they read-only or full access?"
  • "Can you change anything in my books, or only read them?"

In this section

Didn't find the answer?

Write to support@caribooks.com, or use the Help button at the bottom right of every portal page. A person answers, in English or French.

→ Book a 30-minute demo