Privacy Policy
Last updated: July 21, 2026
- We store the ledger entries you (or your AI agent) choose to submit — nothing is pulled from your bank.
- Statement files are parsed by your own AI agent. The files themselves never reach Quietbooks; only the structured entries do.
- We never sell your data, never show ads, and never use your data to train AI models.
- You can export everything or delete your account and all data at any time.
1. Who we are
Quietbooks ("we", "us") is operated by Shenzhen Bluecoast Zhixing Technology Co., Ltd. (深圳市蓝岸知行科技有限公司). We provide an agent-native bookkeeping service: your AI agent records transactions into your ledger through our MCP interface, and you review them on this web console. Contact: rickliang85@foxmail.com.
2. Information we collect
- Account information. When you sign in with Google we receive your Google account identifier and email address. We do not receive or store your Google password.
- Ledger data you submit. Transactions (date, amount, currency, description, notes), payment-source labels (e.g. "Amex", "PayPal"), categories, and categorization rules — submitted by you or by an AI agent you have authorized.
- Authorization records. OAuth client registrations, grants, and hashed access tokens, kept so that only clients you approved can reach your ledger and so you can revoke them.
- Technical data. Basic request logs (such as IP address and user agent) processed by our infrastructure providers for security and reliability.
3. What we deliberately do not collect
- No bank, card, or wallet connections — Quietbooks never asks for your banking credentials.
- No statement files — parsing happens inside your own AI agent; only structured entries are sent to us.
- No payment card numbers, no government identifiers, no advertising identifiers.
4. How we use information
- To provide the service: store your ledger, apply your rules, generate reports and exports.
- To authenticate you and the clients you authorize, and to let you revoke access.
- To keep the service secure — abuse prevention, rate limiting, debugging.
- To comply with legal obligations.
We do not sell or rent your personal data, do not use it for advertising, and do not use your ledger data to train AI or machine-learning models.
5. Legal bases (EEA/UK users)
We process your data to perform our contract with you (providing the ledger service), for our legitimate interests (securing the service), with your consent (Google sign-in), and to comply with law. You may withdraw consent at any time by deleting your account.
6. Where your data lives
- Neon (AWS, United States) — ledger database hosting.
- Cloudflare — edge compute, OAuth storage, and web hosting.
- Google — sign-in only.
Your data is stored in the United States. If you access Quietbooks from another region, you consent to this transfer; we protect it with the safeguards described below regardless of region.
7. Retention and deletion
We keep your data while your account is active. Committed ledger entries are corrected by adjustment records rather than silent edits — this is a bookkeeping-integrity feature, not a retention claim: when you delete your account, your ledger, sources, rules, and authorization records are deleted entirely.
8. Your rights and controls
- Export — download your full ledger as CSV at any time (built into the product).
- Correct — edit staged entries; correct committed entries via adjustments.
- Delete — delete your account and all associated data from Settings or by emailing us.
- Revoke — disconnect any authorized agent or client at any time.
- Depending on your region (including the EEA/UK, California, South Korea, and Japan) you may also have statutory rights of access, rectification, erasure, portability, restriction, and objection, and the right to complain to your local supervisory authority. We honor these on request. California residents: we do not sell or share personal information as defined by the CCPA/CPRA.
9. Security
All traffic is encrypted in transit (TLS); data is encrypted at rest by our hosting providers. Access to your ledger requires OAuth 2.1 with PKCE; access tokens are stored hashed and can be revoked. Every query is scoped to your account (row-level tenant isolation).
10. Children
Quietbooks is not directed at children under 16, and we do not knowingly collect their data.
11. Changes
We will post any changes to this policy on this page and update the date above. For material changes we will notify you via the service or email.
12. Contact
Questions or requests: rickliang85@foxmail.com.
This policy is provided in English as the authoritative version.