Security

The connector

Your ledger stays in QuickBooks. What Caribooks stores depends on the features you use. The connector reads QuickBooks when you ask Claude, ChatGPT or Microsoft Copilot a question and passes the results to your assistant. Caribooks does not keep a synchronized copy of your ledger. We keep the account and connection details needed to provide the service, usage records, and any bookkeeping rules or task instructions you save. Your assistant handles the responses under its own privacy policy and your settings.

What we keep about your account

Your account email, QuickBooks access tokens (AES-256 encrypted), connected company details, billing information and usage records. We also retain bookkeeping rules and task instructions you save through the connector. When you use document sorting across several companies, we cache company names, addresses and tax identifiers from QuickBooks to help identify the recipient.

Autopilot and in-app conversations

Autopilot stores your task instructions, in-app conversations, run history and proposals so you can review its work. This history can include QuickBooks data. For supported changes, we also keep the records needed to undo them. The models processing this information are described in our privacy policy. In-app conversations and run history remain available for review; archiving a conversation hides it from the list without deleting its messages. Contact support@caribooks.com to request deletion.

The optional document box

If you upload documents or email them to Caribooks, we store the files, extracted text and document details to sort them, find them and attach them to QuickBooks. The document box can be used with the connector or Autopilot. Receipt files are removed from our storage once attached to QuickBooks. A copy of a document QuickBooks already has is removed after 30 days. Every other file stays until you delete it. We clear the document box’s extracted text when a receipt is filed or a document is deleted. Details read from a document, such as its total and its lines, stay until you delete it. Document history remains. Text already included in conversations or Autopilot history can remain.

Where all of this lives

The database and files are hosted on Supabase in the AWS Montréal region (ca-central-1); the application runs on Vercel in Montréal (yul1). Vercel Workflow keeps run state in Virginia (iad1), including model conversations and the QuickBooks data read during a run. Vendor portal sessions are hosted in the United States by Browserbase. AI requests and the other services described on this page may also process information outside Canada.

A token, never your password

Connecting a company goes through the standard Intuit authorization (OAuth). Intuit hands us a token that only opens your books; we never see your QuickBooks password. You can revoke that token at any time, from the Caribooks portal or directly with Intuit, and access dies immediately.

Read-only by default

A connected company starts read-only: the assistant looks, nothing moves. Write access is enabled company by company, by you alone, and every delete requires an explicit confirmation in the conversation.

A loop starts by asking

A new loop proposes and waits: nothing moves in your books without your approval. You then decide, action by action, what it may do on its own. Deleting, voiding and sending a document always require your confirmation, whatever the setting. Every applied change can be undone, and you can pause one loop, or all of them.

Passwordless sign-in

Your Caribooks account opens with a magic link sent to your email. No Caribooks password exists, so there's no password to steal.

AI model providers

When you query your books through Claude, ChatGPT or Microsoft Copilot, that provider processes your questions and the data that answers them under its policy and your settings. New loops, the step that turns your sentence into a loop and vendor-portal setup use GLM 5.3 Flash, an open model, through OpenRouter. OpenRouter runs it for us on Together AI, Fireworks AI or DeepInfra and nowhere else, with requests sent under a no-retention, no-training setting. A loop written earlier keeps the model configured for it, also through OpenRouter. The model receives the transactions and documents being examined, your rules and your instructions. Training and retention terms depend on the provider and service settings; they can differ from the document sorting described below. Caribooks does not sell your data or use it to train its own models.

What the model sees

AI sorting is used when rules and recipient details cannot settle which company a document belongs to. With one connected company, documents are assigned to it without a model call. With several companies, documents with an uncertain recipient wait for your choice on the Documents page. When needed, AI sorting sends the filename, sender, email subject, up to 12,000 characters of text, and the candidate companies' names, addresses and tax numbers. This text can contain personal or banking information; it is not automatically anonymized. Competing models are tested with fictional documents. The sorter uses GLM 5.3 Flash through OpenRouter, hosted by Together AI, Fireworks AI or DeepInfra. Every sorting request requires a zero-data-retention endpoint, disallows data collection and prohibits any host other than these three. These requirements apply to the three hosts; OpenRouter applies its own policy and account settings. They do not guarantee processing in Canada.

Document reading

Each document in the document box is read once by an AI model so you and your assistant can find it: the vendor, date, number, total, taxes, due date, last four digits of the card, recipient, a short summary and the lines bought. The model receives the filename and up to 6,000 characters of the document's text, or a picture of a photo or of a scanned PDF's first page. This text can contain personal or banking information; it is not automatically anonymized. Reading uses GLM 5.3 Flash through OpenRouter, hosted by Together AI, Fireworks AI or DeepInfra, with the same requirements as sorting: a zero-data-retention endpoint, no data collection and no host other than these three. They do not guarantee processing in Canada.

Access and deletion

You can disconnect a QuickBooks company from the portal. Disconnecting stops its connector access; it is not a request to erase all stored history or documents. To request access to, correction of or deletion of your personal information, or deletion of your Caribooks account, contact support@caribooks.com. We will explain the scope of the deletion and any records that must be retained.

What Caribooks cannot do

Intuit's API does not open everything, and we won't pretend otherwise. A loop cannot see the bank feed's For review queue, cannot reconcile an account, cannot move money and cannot read payroll. What it touches is the entries and the documents inside QuickBooks.

What we don't have

No SOC 2 audit yet: we're a small team and we won't claim certifications we don't hold. The day we earn one, it will be listed here. To report a vulnerability or ask anything: support@caribooks.com, and we answer fast.

→ Full privacy policy