Privacy Policy of QuickConverter.app

At a glance

  • QuickConverter converts bank and credit-card statements into QuickBooks imports. The conversion itself runs entirely in your browser — your statements are never uploaded to us.
  • We store only what the service needs: your email, your encrypted QuickBooks lists (account, payee, and class names you choose to save), anonymous duplicate-detection fingerprints, billing status, and privacy-friendly, cookieless usage analytics.
  • We never sell or share your personal information for advertising. Ever.
  • Personal fields are encrypted at rest (AES-256-GCM). Only Stripe processes payments; only Microsoft Azure delivers our email; the site is hosted on Vultr in Los Angeles.
  • You can delete your account and all server-side data yourself, any time, from Account → Delete Account.

Effective: September 2026

Contents

Who we are

QuickConverter.app is operated by A Robot Can Dream, Huntington Beach, CA 92649, USA. We are the “data controller” (GDPR) / “business” (California law) for the personal data described here. Questions, requests, and complaints go to privacy@quickconverter.app.

What we collect

Account information

  • Email address — your login identity and where we send service messages.
  • Name — optional; shown in your account settings.
  • Profile picture and basic profile — only if you sign in with Google, Microsoft, or LinkedIn; those providers tell us your name, email, and avatar.

QuickBooks list data you save

To map statement rows to your QuickBooks chart of accounts, you can import or type account names, payee/vendor names, and class names. Lists keep names, types, hierarchy, and the contact details they contain; when you save them, these lists are stored on our servers encrypted (AES-256-GCM) so even we cannot read them without your session key. Statements themselves are never uploaded — see the next section.

Importing a QuickBooks list automatically discards Social Security numbers, tax IDs, bank account numbers, and account balances — these fields never reach our servers.

Duplicate-detection fingerprints

So we can tell you “you already imported this row,” we store an anonymous fingerprint of each transaction row: a keyed hash (HMAC-SHA-256) of its date, amount, and description, scrambled with a secret unique to your account. Fingerprints cannot be reversed into transactions and are meaningless outside your account.

Billing information

Payments are handled entirely by Stripe. We never see or store your card number. We keep the billing status of your subscription and the card brand/last-4 digits shown on your receipts, which Stripe returns to us.

Usage data

  • Conversion counters — how many files and rows you have converted (used for plan limits and basic service metrics).
  • Analytics — page views and button clicks, measured by our self-hosted Plausible instance. No cookies, no cross-site tracking, no device fingerprints; data is aggregated and never linked to your account.
  • Technical logs — our server keeps standard short-lived request logs (such as IP address) for security and error diagnosis.

Support correspondence

If you email us, we keep your message and email address to answer you.

What we do not collect

We do not ask for, and do not want, Social Security numbers, tax IDs, bank account or routing numbers, account balances, bank login credentials, or copies of identity documents. QuickBooks list imports drop the fields holding that data automatically, so they are never stored; please don't put sensitive information like that into account names or list entries either.

What stays on your device

The conversion work happens in your browser. Parsed statements and your working history are stored in your browser's indexed database (Dexie), encrypted on-device with a key only your session holds. This data never reaches our servers; it lives and dies with your browser profile. Logging out erases it (we warn you first), and deleting your account wipes it as well. A plain-English overview of every protection we use is on our security page.

What we never do

  • We never sell your personal information to anyone.
  • We never share it for cross-context behavioral advertising, and we run no advertising trackers.
  • We never use your data to train AI models.
  • We never read your encrypted lists or view your statements — the data we store is encrypted, and statements are not stored at all.
  • We never email you asking for your password, card number, or bank details.

Service providers (subprocessors)

The only companies that touch your data, and why:

  • Stripe (payments) — processes subscriptions and card data under its own PCI-DSS-compliant privacy policy. It is the only party that sees payment details.
  • Microsoft Azure (transactional email) — delivers sign-in codes and service notifications on our behalf.
  • Vultr (hosting) — runs the servers (see hosting section below). Plausible analytics also runs self-hosted on our own servers; no third party receives your usage data.

We add no other providers without reviewing their security and data-processing terms, and we keep a register of subprocessors available on request.

Analytics and Global Privacy Control

We measure aggregate usage with Plausible, self-hosted on our own servers: cookieless, no personal profiles, no data leaves our infrastructure. Because we don't sell or share personal information, there is no “sale” to opt out of — and if your browser sends a Global Privacy Control (GPC) signal, we honor it by disabling analytics tracking for you entirely.

Marketing emails

We only send product news to people who opted in. New accounts start optedout; you can change email preferences in your account settings at any time, or email us to unsubscribe. Service messages (sign-in codes, billing notices, security alerts) are not marketing and are always sent when needed.

How we protect your data

  • All traffic is encrypted (TLS).
  • Personal fields — including your saved lists, name, and encryption keys — are encrypted at rest with AES-256-GCM; keys are held outside the database.
  • Duplicate-detection fingerprints are keyed per user, so they can't be matched across accounts or brute-forced.
  • Access to production systems is limited to the operator. Passwords (if you use email sign-in) are stored only as salted hashes by our auth library.
  • If a breach ever affects your personal data, we will notify affected users and regulators within 72 hours of confirming it, as GDPR and US state laws require.

Where your data is hosted

All service data is stored on virtual servers we lease from Vultr in their Los Angeles, California data center. We do not transfer your data outside the United States. Stripe and Azure process data under their global infrastructures; see their privacy policies for details. For EU/UK visitors: because hosting is US-based, your data will be stored in the US — we rely on the protections described in this policy, and you may contact us for a copy of our data-processing terms.

How long we keep data

  • Account, lists, fingerprints, settings — until you delete your account or your subscription ends and the account lapses. Deletion removes server copies immediately. Encrypted backups roll off within 30 days.
  • Billing records — kept as long as tax and accounting rules require (typically 7 years), stored by Stripe.
  • Analytics — aggregate only, rotated by our Plausible configuration.
  • Technical logs — short-lived, days not months.
  • Device data — erased on logout, or whenever you clear your browser data.

Deleting your account

Use Account → Delete Account while signed in. After you confirm, we cancel your Stripe subscription, delete your Stripe customer record, and erase your account and every record attached to it (sessions, saved lists, fingerprints, settings) from our database. Your browser-stored data is wiped at the same time. If you can't sign in, email privacy@quickconverter.app from your account address and we'll delete it for you.

Your privacy rights

You can exercise any of these yourself in the app, or by emailing privacy@quickconverter.app. We answer within the timeframes required by law (45 days under most US state laws, one month under GDPR).

  • Know / access & portability — see and export the personal data we hold.
  • Correct — fix inaccurate data (name, email, settings) in your account panel.
  • Delete — remove your account and data (button or email).
  • Opt out of sale/sharing or targeted advertising — we never sell or share, so there is nothing to opt out of; GPC signals are honored anyway.
  • Withdraw consent / object — stop marketing emails or analytics (GPC) at any time.
  • Non-discrimination — exercising your rights never changes your price or service level.
  • Appeal — if we decline a US-state-law request, you can appeal by replying to our decision email; residents of Colorado, Connecticut, and certain other states also have the right to contact their state attorney general.

EEA/UK residents also have the rights to restrict processing, object to processing based on legitimate interests, and lodge a complaint with their national data protection authority. Our lawful bases: performing the service you signed up for (contract), keeping the service secure (legitimate interests), analytics and optional emails (consent, withdrawable at any time).

California residents: the CCPA as amended gives you the rights above, including the right to know what personal information is collected and the right to delete it. We do not “sell” or “share” personal information as those terms are defined by the CCPA, and we offer no financial incentives tied to your data.

Children

QuickConverter is a business accounting tool and is not directed to children. We don't knowingly collect data from anyone under 16 (or under 13 where a lower age applies). If you believe a minor created an account, contact us and we'll remove it.

Cookies

We use only the cookies strictly needed to run the service: a sign-in session cookie and a matching security token. No advertising, analytics, or social-media cookies exist — our analytics is cookieless. Because nothing non-essential is set, there is no cookie consent banner to click through. Your browser storage also holds encrypted working data (see What stays on your device), which is erased on logout or account deletion.

Changes to this policy

We update this page when our practices change. If a change materially affects your rights, we'll notify you by email or with a notice in the app before it takes effect. The effective date above shows which version applies.

Contact

A Robot Can Dream — operator of QuickConverter.app
Huntington Beach, CA 92649, USA
Privacy questions, requests, and complaints: privacy@quickconverter.app

QuickConverter Logo iconQuickConverter