Privacy Policy
Effective July 20, 2026
The Bookkeeper is built around one promise: we store nothing. Your entire accounting system lives as plain text files in your own Google Drive. This page explains, in plain language, what information moves where and what never moves at all.
What We Store On Our Servers
Nothing. There is no user database, no stored books, no analytics warehouse. Our servers are a static website and a stateless relay that processes each request and retains none of it. If you stop using The Bookkeeper, there is nothing on our side to delete, because nothing was ever kept.
Where Your Books Live
In a folder named The Bookkeeper in your own Google Drive, as readable plain text files. You can open them, copy them, or delete them at any time in Google Drive itself. Deleting that folder deletes your books everywhere, because there is no other copy.
What Google Access We Ask For
We request the narrowest Drive permission Google offers, called drive.file. It allows the app to see only files the app itself created. We cannot see your other Drive files, your email, or anything else in your Google account. We also receive your email address and name from Google sign in, which are used to label your edits in your own audit trail and are stored only inside your books, in your Drive.
How Sign In Works Without Storage
When you sign in, Google issues access credentials. Our relay seals them with strong encryption (AES-256-GCM) and hands the sealed result back to your browser or your AI assistant, which holds it. On each request the relay unseals the credential in memory, performs the action against your Drive, and forgets it when the request completes. Revoking The Bookkeeper in your Google account permissions instantly invalidates every sealed credential everywhere.
Your AI Assistant
If you connect an AI assistant such as Claude over MCP, that assistant reads your books with your credentials, per request, through the same stateless relay. What the assistant does with what it reads is governed by the assistant provider's own terms and privacy policy, not this one.
Optional Connections
QuickBooks import: if you connect QuickBooks Online, we relay your data from Intuit's servers directly into your browser, which writes it into your Drive. We keep none of it. Bank sync: when the paid bank sync feature launches, it will use Plaid, and its terms will be presented before you connect a bank. Until you explicitly connect these services, no data flows to or from them.
Cookies and Tracking
The product uses no analytics, no advertising trackers, and no third party cookies. Your browser's local storage holds only app state, such as your demo edits and your session, on your device.
Infrastructure
The static site and the stateless relay run on Cloudflare's network, which processes requests as any host must in order to serve them. Your books do not transit our infrastructure at rest, only within individual requests you initiate.
Children
The Bookkeeper is a business tool and is not directed to children under 13.
Changes
If this policy changes, the effective date above changes with it, and the full history is public in the project's open source repository.
Contact
Questions about privacy are welcome as issues on the public repository.