Privacy
Last updated: September 28, 2026
The connector
Your ledger stays in QuickBooks. What Caribooks stores depends on the features you use. The connector reads QuickBooks when you ask Claude, ChatGPT or Microsoft Copilot a question and passes the results to your assistant. Caribooks does not keep a synchronized copy of your ledger. We keep the account and connection details needed to provide the service, usage records, and any bookkeeping rules or task instructions you save. Your assistant handles the responses under its own privacy policy and your settings.
What we keep
Your account email, QuickBooks access tokens (AES-256 encrypted), connected company details, billing information and usage records. We also retain bookkeeping rules and task instructions you save through the connector. When you use document sorting across several companies, we cache company names, addresses and tax identifiers from QuickBooks to help identify the recipient. If you sign in with Google or Microsoft, that provider sends us your name, your email address and, if you have one, your profile photo.
Autopilot and in-app conversations
Autopilot stores your task instructions, in-app conversations, run history and proposals so you can review its work. This history can include QuickBooks data. For supported changes, we also keep the records needed to undo them. The models processing this information are described below. In-app conversations and run history remain available for review; archiving a conversation hides it from the list without deleting its messages. Contact support@caribooks.com to request deletion.
The optional document box
If you upload documents or email them to Caribooks, we store the files, extracted text and document details to sort them, find them and attach them to QuickBooks. The document box can be used with the connector or Autopilot. Receipt files are removed from our storage once attached to QuickBooks. A copy of a document QuickBooks already has is removed after 30 days. Every other file stays until you delete it. We clear the document box’s extracted text when a receipt is filed or a document is deleted. Details read from a document, such as its total and its lines, stay until you delete it. Document history remains. Text already included in conversations or Autopilot history can remain.
Where your data is hosted
The database and files are hosted on Supabase in the AWS Montréal region (ca-central-1); the application runs on Vercel in Montréal (yul1). Vercel Workflow keeps run state in Virginia (iad1), including model conversations and the QuickBooks data read during a run. Vendor portal sessions are hosted in the United States by Browserbase. AI requests and the other services described on this page may also process information outside Canada.
Your AI assistant and the models
When you query your books through Claude, ChatGPT or Microsoft Copilot, that provider processes your questions and the data that answers them under its policy and your settings. New loops, the step that turns your sentence into a loop and vendor-portal setup use GLM 5.3 Flash, an open model, through OpenRouter. OpenRouter runs it for us on Together AI, Fireworks AI or DeepInfra and nowhere else, with requests sent under a no-retention, no-training setting. A loop written earlier keeps the model configured for it, also through OpenRouter. The model receives the transactions and documents being examined, your rules and your instructions. Training and retention terms depend on the provider and service settings; they can differ from the document sorting described below. Caribooks does not sell your data or use it to train its own models.
Document sorting
AI sorting is used when rules and recipient details cannot settle which company a document belongs to. With one connected company, documents are assigned to it without a model call. With several companies, documents with an uncertain recipient wait for your choice on the Documents page. When needed, AI sorting sends the filename, sender, email subject, up to 12,000 characters of text, and the candidate companies' names, addresses and tax numbers. This text can contain personal or banking information; it is not automatically anonymized. Competing models are tested with fictional documents. The sorter uses GLM 5.3 Flash through OpenRouter, hosted by Together AI, Fireworks AI or DeepInfra. Every sorting request requires a zero-data-retention endpoint, disallows data collection and prohibits any host other than these three. These requirements apply to the three hosts; OpenRouter applies its own policy and account settings. They do not guarantee processing in Canada.
Document reading
Each document in the document box is read once by an AI model so you and your assistant can find it: the vendor, date, number, total, taxes, due date, last four digits of the card, recipient, a short summary and the lines bought. The model receives the filename and up to 6,000 characters of the document's text, or a picture of a photo or of a scanned PDF's first page. This text can contain personal or banking information; it is not automatically anonymized. Reading uses GLM 5.3 Flash through OpenRouter, hosted by Together AI, Fireworks AI or DeepInfra, with the same requirements as sorting: a zero-data-retention endpoint, no data collection and no host other than these three. They do not guarantee processing in Canada.
Optional vendor portals
If you connect a vendor portal to collect invoices, Browserbase hosts the browser in the United States and retains its sign-in session so it can be reused. Browser session recording and logging are disabled. To configure collection, billing-page navigation controls and invoice text may be sent to a model through OpenRouter. Removing that vendor connection deletes its saved browser context; invoices already collected remain in your document box.
Your mailbox, if you connect it
If you, or someone on your team, connect a Gmail or Outlook mailbox on the Vendors page, Caribooks reads it with read-only access, and only for the vendors paid in the last year by the Autopilot companies that mailbox serves. For each of them, Caribooks first learns how its invoices arrive: it looks for the vendor's name, or a close variant, in the sender and subject of messages, and GLM 5.3 Flash, through OpenRouter on Together AI, Fireworks AI or DeepInfra with no retention and no training, reads the sender, subject, a short preview, the invoice and the links of a few of those messages to compare the amount and date with the vendor's expenses in QuickBooks, or to spot the portal where the vendor posts its invoices. Once it knows the sender (or the one you name), it reads only that sender's messages: the past year's invoices that match an expense still missing its document, then each new one. A kept invoice is filed in the document box (its attachment, or the email itself as a PDF) and read like any other document; the other messages it looks at are not kept. Caribooks never sends mail from your account. The access token is stored AES-256 encrypted. You can disconnect the mailbox on the Vendors page at any time: Caribooks then deletes the token and, for Gmail, gives Google its consent back. This data is not used for advertising, not sold, and not used to train AI models. Caribooks' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies and visit analytics
The only tracking cookies the site sets are those that measure our ChatGPT ads, described below. On the public pages, and never in the portal, PostHog records how visitors move through the site: clicks, scrolling and a recording of the visit with form fields hidden. PostHog keeps a visit identifier in your browser tab. It is gone when you close the tab, so one visit cannot be linked to the next. This data is hosted in the United States and recordings are kept for up to 30 days. PostHog does not keep your IP address, and we have opted out of PostHog using this data to train its models. When you create an account, we attach to it the first page of your visit, the site that sent you there, the link’s campaign tags (UTM) and that visit identifier; until then, these stay in your browser tab. PostHog then receives, under that identifier, the account’s first steps: first sign-in, first company connected, first assistant connected, first request and first subscription. It receives no name, email address, company name or QuickBooks data. Fathom counts visits without cookies. If you open any page of the site with ?analytics=off at the end of its address, neither PostHog nor Fathom counts your visits any more, and your browser remembers that choice until you open a page with ?analytics=on. We advertise in ChatGPT. On the public pages, except the sign-in page, OpenAI’s measurement pixel tells OpenAI when it loads and keeps two first-party cookies: the identifier of the ChatGPT ad you clicked, for 30 days, and a random browser reference, for up to a year. If you create an account after clicking one of our ads, we attach both to the account and tell OpenAI, under that identifier, when the account is created, when its first company is connected and when it first subscribes. OpenAI receives no name, email address, company name or QuickBooks data, and learns nothing about accounts that did not come from an ad. ?analytics=off turns this pixel off too. Anything else your browser keeps is there to sign you in to the portal.
Access and deletion
You can disconnect a QuickBooks company from the portal. Disconnecting stops its connector access; it is not a request to erase all stored history or documents. To request access to, correction of or deletion of your personal information, or deletion of your Caribooks account, contact support@caribooks.com. We will explain the scope of the deletion and any records that must be retained.
Provider privacy policies
Which providers receive your information depends on the features you use. Resend processes emails and their attachments; Sentry receives diagnostics and service usage logs. The policies below explain each provider’s practices.
- SupabaseDatabase, files and authentication
- VercelApplication hosting and workflow state
- StripeBilling
- ResendAccount emails and incoming documents
- SentryError diagnostics and service logs
- OpenRouterModel requests
- Together AIOpen model host: loops, document sorting and reading
- Fireworks AIOpen model host: loops, document sorting and reading
- DeepInfraOpen model host: loops, document sorting and reading
- BrowserbaseOptional vendor portal sessions
- OpenAIChatGPT and OpenAI models, and measurement of our ChatGPT ads
- AnthropicClaude and Anthropic models
- MicrosoftSign-in with Microsoft, and Microsoft Copilot and Outlook when you connect them
- GoogleSign-in with Google, and Gmail when you connect it
- CloudflareBot check on the sign-in page (Turnstile)
- FathomCookieless audience analytics
- PostHogVisit recordings and heatmaps of the public site, and the sign-up funnel
Caribooks · Peich Technologies Inc., Montréal