Privacy Policy
This policy describes how the QuickBooks Online integration operated by PR1SM (“the Application”) handles data. The Application is a private, internal tool. It is not offered to the public and is not listed on the QuickBooks App Store.
1. Who operates the Application
PR1SM, 174 Clarkson Rd, Ellisville, MO 63011, USA. Questions about this policy may be sent to prisma@pr1sm.ai.
2. What data the Application accesses
With the authorising user's consent, the Application accesses data in the connected QuickBooks Online company, which may include:
- Company profile, preferences and chart of accounts
- Customer, vendor and employee records, including names, addresses, email addresses, phone numbers and tax identifiers
- Transactions, including invoices, bills, estimates, payments, purchases, deposits, transfers, credit memos and journal entries
- Financial reports, including balance sheet, profit and loss, cash flow, trial balance, general ledger and ageing reports
The Application accesses this data only through Intuit's official QuickBooks Online API, and only for the company the authorising user explicitly connects.
3. Where the data goes
The Application runs locally on a machine controlled by PR1SM. It is not a hosted service and does not transmit QuickBooks data to any server operated by PR1SM. Data is transmitted in two directions only:
- To and from Intuit. API requests and responses over HTTPS.
- To the connected AI assistant. The Application exposes QuickBooks data to the Model Context Protocol client it is connected to. Where that client is an AI assistant, data returned in response to a request is transmitted to that assistant's provider and is subject to that provider's own privacy policy and data retention terms.
The second point is material and users should understand it before connecting: the purpose of the Application is to make QuickBooks data available to an AI assistant, and data so requested necessarily leaves the local machine.
4. What is stored
The Application stores OAuth credentials — a client ID, client secret, refresh token and company (realm) ID — in a local configuration file on the machine where it runs. Refresh tokens are rotated by Intuit and the updated value is written back to that file. No QuickBooks business data is written to disk, cached or retained by the Application beyond the duration of a request.
5. Retention and deletion
Because no business data is retained, there is nothing to delete beyond the stored credentials. Access may be revoked at any time from the QuickBooks Online company settings, or by deleting the local configuration file. Revoking access immediately and permanently ends the Application's ability to read the company's data.
6. Sharing
PR1SM does not sell, rent or share QuickBooks data obtained through the Application with any third party, other than the transmission to the connected AI assistant provider described in section 3.
7. Security
Access is authorised via OAuth 2.0; the Application never receives or stores QuickBooks account passwords. All API traffic uses HTTPS. Stored credentials are held in a file excluded from version control and protected by the operating system's file permissions on the host machine.
8. Changes
Material changes to this policy will be reflected on this page with an updated revision date.