This policy explains how Penny, a private internal accounting review tool operated by PoGo All In One Services LLC (“we,” “us,” or “our”), handles information obtained through QuickBooks Online.
1. Scope
Penny is used by authorized personnel to review the company’s own books. It is not offered as a public consumer application. This policy applies to the Penny QuickBooks connection, its public connection pages, and the redacted review packets it creates.
2. Information processed
With the QuickBooks company administrator’s authorization, Penny may read company metadata, accounts, invoices, payments, sales receipts, credit memos, deposits, purchases, bills, bill payments, journal entries, and financial report totals. OAuth connection data—including authorization codes, access tokens, refresh tokens, and the QuickBooks company identifier—is also processed to maintain the authorized connection.
3. Purpose and legal basis
We use this information only for internal bookkeeping review, reconciliation, duplicate and exception detection, financial reporting, connection security, and audit evidence. Processing is performed for our legitimate internal business operations and under the explicit authorization of the QuickBooks company administrator.
4. Current read-only boundary
Penny’s current production stage does not create, update, delete, void, refund, pay, email, or otherwise mutate QuickBooks records. It does not initiate money movement. The Intuit Accounting API permission is broad, so Penny enforces this narrower boundary in application code through a GET-only allowlist and review controls.
5. Storage and retention
QuickBooks credentials and tokens are stored separately by environment in an owner-controlled system and are not placed in source control, chat, or public review files. Raw QuickBooks responses are processed transiently for the current review. Redacted review packets may be retained locally for accounting and audit purposes. Connection credentials are retained until access is revoked, the connection expires, or the owner deletes them.
6. Sharing and sale
We do not sell QuickBooks data. We do not use it for advertising or unrelated profiling. Data is disclosed only to service providers necessary to operate the secure connection and hosting infrastructure, to authorized company personnel, or when required by law. Service providers may process limited technical data under their own security and privacy obligations.
7. Security
Controls include encrypted transport, environment-specific credentials, local secret protection, OAuth state validation, redacted identifiers, fixed read-only endpoint allowlists, deterministic packet verification, privacy scanning, and a prohibition on sending QuickBooks secrets to AI prompts or chat.
8. Your choices
The QuickBooks company administrator may revoke Penny through QuickBooks connected-app settings at any time. Authorized personnel may also delete local Penny credentials and review artifacts subject to legal and accounting retention obligations.
9. International and regulated use
Penny is not designed to provide lending, insurance, investment, financial-planning, payment-processing, payroll, or tax-filing services. It is used for the operator’s internal accounting review.
10. Changes and contact
We may update this policy when Penny’s data practices change. The effective date above identifies the current version. Questions or privacy requests may be submitted through the PoGoAIOS contact page.