Bookkeeper AI

Privacy policy

Last updated September 14, 2026

Bookkeeper AI is a private bookkeeping tool operated by Critz Labs LLC dba North Oak Ventures. This policy explains how the tool handles information for its authorized internal users.

Information we handle

We may handle authorized users’ account information; business names and identifiers; charts of accounts; transactions; financial reports; supporting documents; and bookkeeping review notes. When a QuickBooks Online company is connected, we also handle its company identifier and OAuth credentials needed to access the authorized company. Bank transaction data may be obtained through the operator’s existing SimpleFIN connection.

How we use information

We use this information to authenticate users, restrict access to their organizations, maintain books, reconcile accounts, identify discrepancies, prepare reports, and review or apply authorized accounting corrections. We do not sell bookkeeping information or use it for advertising.

Storage and access

The bookkeeping database and portal authentication use Supabase. The portal and these public information pages are hosted on Cloudflare. The current QuickBooks integration runs on the operator’s Mac; saved connection credentials and working snapshots are stored locally. Credentials are excluded from source control and local files are restricted to the file owner. The integration does not currently add application-level encryption to those local files.

Access to the private portal requires authentication and membership in the appropriate organization. Authorized operators and service providers process information only as needed to operate the tool. The operator may use OpenAI’s Codex to assist with an authorized review of selected records; information submitted for that review is processed under the applicable OpenAI account terms.

Service providers and disclosures

Providers involved in the workflow may include Intuit for QuickBooks authorization and data access, SimpleFIN for bank transaction access, Supabase for database and authentication services, Cloudflare for hosting, GitHub for source code and scheduled import workflows, and OpenAI for authorized assisted review. We may also disclose information when required by law or when necessary to protect the service and its users.

Cookies and technical information

The private portal uses cookies for sign-in and organization selection. Hosting providers may process request metadata and technical logs needed to operate the service. These public pages do not add advertising cookies.

Retention, access, and deletion

Financial records and review notes are retained for bookkeeping operations and applicable recordkeeping requirements. Locally saved snapshots and credentials remain until the operator removes them or replaces the connection. Disconnecting an integration does not delete historical records held in QuickBooks. Authorized users may request access, correction, or deletion, subject to accounting and legal retention requirements.

Contact

For privacy questions or requests, contact Critz Labs LLC dba North Oak Ventures through the North Oak Ventures website.

Changes

We will update this policy as the service or its data handling changes. The date above identifies the latest version.