Effective 30 August 2026
ZhuQue is a tool for bookkeepers and accountants that reviews QuickBooks Online books for errors. Using it means trusting us with another person's accounting records, so this policy describes exactly what is stored, where, and for how long — in specifics rather than generalities.
ZhuQue is operated by Brandon Mu, an independent developer based in Texas, United States. Questions, access requests and deletion requests: support@usezhuque.com.
We use Google Sign-In. We request only your basic profile and email address, and we store your email address, your name, your profile picture URL, and Google's stable account identifier. We never receive or store your Google password.
With your authorisation, we store an OAuth access token and refresh token for that company, the company's name, and Intuit's identifier for it. Tokens are encrypted at rest and are used only to read and write the data described below.
We then read, and cache in our database, the following for expense transactions (QuickBooks Purchase and Bill records):
We do not read invoices, customers, employees, payroll, banking credentials, or bank account numbers. Our QuickBooks permission is limited to accounting data, and within that we request only what the three rules need.
Proposed changes with the reasoning behind them; a permanent audit record of each decision, including the email address of the person who approved or rejected it and the time; and a per-company mapping of vendors to expected categories.
Payments are processed by Stripe. We never see or store your card number. We store only Stripe's customer and subscription identifiers, your subscription status, and your renewal date.
A session cookie, stored in our database only as an irreversible SHA-256 hash, along with your browser's user-agent string. Cloudflare, our hosting provider, processes request logs on our behalf. We use no advertising or analytics trackers of any kind.
Solely to provide the service: to detect duplicate payments, miscategorised expenses and missing receipts, to show you those findings for approval, to write approved changes back to QuickBooks, to maintain your audit trail, and to bill you.
We do not sell your data. We do not share it with advertisers. We do not use your data, or your clients' data, to train machine-learning models — the detection rules are database queries, not a model, and no accounting data is sent to any AI service.
| Provider | Role |
|---|---|
| Cloudflare | Hosting, database, and request logs |
| Intuit | Source of the accounting data, at your direction |
| Sign-in only | |
| Stripe | Payments and card handling |
That is the complete list. We disclose data otherwise only if legally compelled, and will tell you unless prohibited from doing so.
You can see everything we hold about a company inside the app, export your audit trail as CSV from the Audit trail page at any time, disconnect a company yourself, and request full deletion of your account and all associated records by emailing support@usezhuque.com. We respond within 30 days.
Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, including access, correction, portability, deletion, and the right to complain to a supervisory authority. We honour these requests regardless of where you live. We do not sell personal information as those laws define it.
If you are a bookkeeper connecting a client's books, you are the controller of that data and we are your processor: you are responsible for having the authority to connect it, and we act only on your instructions.
QuickBooks tokens are encrypted at rest with a key held outside the database. Session tokens are stored only as hashes, so a copy of our database does not let anyone log in as you. All traffic is TLS-encrypted. Card data never reaches our servers. No system is perfectly secure, and if a breach ever affects your data we will tell you promptly and directly.
Our providers operate globally and your data may be processed outside your country, including in the United States.
ZhuQue is a professional tool and is not directed to anyone under 18. We do not knowingly collect data from children.
If we change this policy materially we will update the effective date above and email account holders before the change takes effect.