0
Skip to Content
DoneByStudents
Contact Us
DoneByStudents
Contact Us
Contact Us
DoneByStudents Bookkeeping Assistant

Privacy Policy

Last updated 5 August 2026 · Provided by DoneByStudents

This application serves a single client business. It is operated by DoneByStudents from a server located in Canada.

What we access and store

  • QuickBooks connection credentials — the access and refresh tokens plus your company ID, so the app can create invoices without asking you to log in each time.
  • Invoice details you send us — customer name, items, amounts, province, currency and exchange rate, and any attachments included in your email.
  • Records read from your QuickBooks — your customer list, product and service categories, sales tax codes, payment terms, and company preferences. These are read so names can be matched to the right records, and are held only in memory for the duration of a run. We do not copy your books. Some of these details may be sent to the AI assistant service — see Automated processing below.
  • Operational logs — what ran and when, and any errors, for troubleshooting. These contain no credentials.

What we never collect

No credit card or bank card numbers, and no payment credentials. The app requests only the QuickBooks accounting permission — never payments — and it has no ability to delete records.

How the information is used

Solely to prepare draft invoices in your QuickBooks company and to support that service for you. We do not sell your data, share it for advertising, or use it for any unrelated purpose.

Permissions we request

Exactly one QuickBooks permission: com.intuit.quickbooks.accounting. We do not request the payments permission, and we do not request access to your Intuit profile, email address, or phone number.

Automated processing

The email you send us describing an invoice is interpreted with the help of an AI assistant service (Anthropic, “Claude”), which reads your wording and turns it into structured invoice details.

Records read from your QuickBooks company — such as your customer list, products and services, tax codes and payment terms — may also be sent to that service, so that it can match what you have written to the right records and help with bookkeeping questions about your own business. We send only what is needed for the task in hand; we do not upload your books wholesale, and we do not send records belonging to anyone else.

Your data is used only to provide this service to you. It is not used to train the AI provider’s models, is never pooled with another business’s data, and is never used to build a product for anyone else.

What the AI is not allowed to do: it does not decide tax treatment and does not calculate any amounts — tax is calculated by QuickBooks itself from the tax code we set. It cannot send an invoice to a customer, and it cannot delete anything. Every invoice it helps prepare is created as a draft for you to review.

Nothing is published, sold, or shared beyond what is required to provide this service to you.

Where it is kept, and who can see it

On a single private virtual server located in Canada. Credentials are held in permission-restricted files, readable only by the one operating-system account that runs the service, and stored outside the application code. Access is limited to DoneByStudents's operator and anyone with administrative (root) access to that server.

All communication with Intuit uses encrypted HTTPS connections. Your stored QuickBooks credentials are individually encrypted (AES-256-GCM) in the file that holds them.

To be precise rather than reassuring: we do not encrypt the server’s disk at rest. The encryption above protects the credential values specifically; the encryption key is held in a separate permission-restricted file on the same server, so it is a safeguard against a stray copy of the credential file rather than against someone who already has administrative access to the machine. Everything else we hold — including the invoice details you email us — is protected by operating-system file permissions and server access control, not by encryption.

How long we keep it

  • QuickBooks credentials — removed automatically once we confirm with Intuit that the connection has been revoked, and on request. We verify revocation with Intuit rather than assuming it.
  • Invoice details and attachments you email us — kept while needed to produce and support the invoice, and removed on request. We do not currently apply a fixed automatic expiry to them.
  • Operational logs — record what ran and when, plus errors. They do not contain credentials.

Your control

You can disconnect the app yourself at any time from inside QuickBooks (Settings → Apps → Disconnect), which immediately revokes its access. You may ask us for a copy of what we hold about you, or ask us to delete it, by emailing stucakov@donebystudents.com. On a deletion request we revoke the credentials with Intuit, overwrite and remove the stored credential files, and delete the retained invoice details and attachments.

Who else is involved (sub-processors)

  • Intuit Inc. — QuickBooks Online, the system the invoices are created in.
  • Google LLC — Gmail, which carries the email you send us.
  • Anthropic PBC — the AI assistant service that interprets invoice details and may process records read from your QuickBooks company.
  • DigitalOcean LLC — the Canadian data centre hosting the server.

We do not disclose your information to anyone else except where required by law.

Changes

Material changes will be communicated to you directly.

Questions: stucakov@donebystudents.com Terms & EULADoneByStudents

Contact

stucakov@donebystudents.com

+1 (604) 366-7351