Privacy
Privacy Policy
Last updated 31 August 2026. Written in English; the English text governs.
The short version
We collect what we need to quote for work, to do the work, and to answer questions about your books. We do not sell anything about you to anybody. Your accounting data is read, not copied — with one narrow exception described below, we do not keep a second copy of your ledger.
Who we are
Diversified Accounting PLLC operates this website and the bookkeeping services described on it. For anything in this policy, contact [email protected].
What we collect, and why
When you ask for a quote
The pricing questionnaire records your answers — business type, states you operate in, transaction volumes, whether you have staff — along with the name, email address, and phone number you give us. We use this to produce a price and to contact you about it. If you go on to become a client, it becomes part of your client record.
When you text us
If you text our number, we keep the conversation — your number, what you sent, and what we sent back — on your record, the same way we would keep an email thread. If you tick the consent box on the quote form, we also store the date you ticked it and the exact wording you were shown, so that what you agreed to is on file even after we reword the page.
No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party. Our Text Messaging Terms & Consent page sets out what we send, how often, and how to stop.
When you use the site
We record page views and interactions to understand which parts of the site work. These events are deleted automatically after 24 months. Events that belong to an identified lead are kept for as long as that client relationship lasts, because at that point they are part of your history with us rather than anonymous traffic.
When you sign in
Signing in to the client portal or the admin uses a single-use link sent to your email address. Those links expire, and expired ones are purged automatically. We do not store passwords, because we do not use any.
When you ask the books assistant a question
If your engagement includes the Slack assistant, we keep a record of every question put to it. That record contains:
- the text of the question, exactly as it was typed;
- a summary of the answer that was given;
- which reports were fetched to answer it;
- the reference number QuickBooks returned for each request, so a problem can be traced with their support;
- the Slack channel it was asked in, and the Slack user id of whoever asked;
- timing and size measurements used for billing and diagnosis.
We keep this because an assistant that reads financial records without an audit trail is not one we would be willing to run. It is how we can tell you who asked what, and when.
Your accounting data
When your books are connected, we hold a credential for them. QuickBooks, Xero and Zoho Books grant that credential for reading and writing together — none of them offers one that can only read — so what we do with it is limited by how our system is built, as set out here.
The assistant only reads. The part of the system that answers questions in Slack is never given the ability to change anything in your books.
Categorisation writes, and only what has been approved. If we categorise your transactions for you, the system proposes a plan in your Slack channel, and only what a person in that channel approves is written. It changes the account a transaction is coded to, records transfers between your own accounts, and attaches receipts. It does not create invoices or bills, pay anyone, or move money: nothing in this system can send a payment or start a bank transfer.
Reports are fetched when a question needs them and used to compose the answer. We do not take a standing copy of your ledger. The exception is the record described above: the answer summary can contain figures drawn from your books, and those figures persist in that record.
Access is granted per Slack channel, not per person. Everyone in a channel connected to your books can ask about them and see the answers. Who is in that channel is therefore a decision about who can see your finances — see the Terms for what that means for you.
Who else is involved
We use these services to run ours. Each receives only what its job requires.
- Render — hosts the website and its database.
- Resend — delivers our email, including sign-in links.
- Intuit (QuickBooks) — the source of the accounting data we read, and where approved categorisations are written.
- Slack — where assistant questions are asked and answers delivered, and where categorisation plans are reviewed.
- Anthropic — composes the assistant's answers, suggests how transactions should be categorised, and reads written replies to a plan.
- Google — the appointment booking calendar embedded on the site; Google Meet, for meetings we hold with you, whose recording or transcript we read afterwards to produce notes and action items; and Google Drive, which holds the shared folder for each of your businesses where you upload documents, and the receipts collected for categorisation.
- Twilio — carries our phone calls and text messages.
- Deepgram — transcribes recorded calls.
- Google (Gemini) — live interpretation of a phone call into another language, where we offer it. While a call is being interpreted, the audio of both sides is streamed to Google's Gemini API; calls that are not interpreted are never sent to it.
- Anchor — prepares and collects signatures on engagement letters, and bills clients. It receives your name, email address, phone number, the businesses we will work on, and the services and fees agreed. Card and bank details are entered with Anchor and its payment processor, never on our site, and we do not see or store them.
The Anthropic one deserves plain speech, because it is the least obvious. To answer a question about your books, the question and the report figures needed to answer it are sent to Anthropic's API and processed there. Some subjects are withheld before anything is sent — individual compensation is withheld by default, so pay columns are stripped from the data at source rather than the model being asked not to mention them.
If we categorise your transactions, each uncategorised transaction's date, amount and bank description is sent to Anthropic's API along with your chart of accounts, the vendor and line items of any matching receipt, how similar transactions were categorised before, and any categorisation notes you have given us. Anthropic returns a suggestion only — it cannot read or change your books itself. When you reply to a plan in your own words, your reply is sent too, so it can be turned into changes to specific items; those changes are shown back to you in the channel before anything is written.
We do not sell personal information, and we do not share it for advertising. In particular, no mobile information is shared with third parties or affiliates for marketing or promotional purposes, and text messaging originator opt-in data and consent are not shared with anyone. Twilio receives a number solely in order to deliver a call or a message to it.
How long we keep things
- Anonymous analytics: 24 months, then deleted automatically.
- Sign-in links: until they expire, then purged.
- Lead and client records: for the life of the relationship, and afterwards for as long as tax and professional record-keeping rules require.
- Assistant question records: for the life of the engagement, as an audit trail.
Your choices
Write to us and we will tell you what we hold about you, correct it, or delete it. Some records we are obliged to keep — accounting and tax records have retention rules that override a deletion request — and we will say so plainly if that applies.
You can disconnect your books from QuickBooks at any time, from inside QuickBooks, without asking us. Doing so ends our access immediately.
Security
Traffic is encrypted in transit. Credentials for your books are encrypted at rest with a key held outside the database, stored separately from the records that get displayed, and rotate on every use. Sign-in is by single-use link rather than a password, and admin access is restricted to a fixed list of addresses.
No system is perfect, and we would rather say so than imply otherwise. If we discover a breach affecting your data, we will tell you.
Children
This is a service for businesses. It is not directed at children.
Changes
If we change this policy we will update the date at the top. Material changes affecting how your data is used will be sent to clients by email rather than left here to be noticed.
Questions about this page
Write to [email protected] and we will answer. If you want a copy of what we hold about you, or want it deleted, that is the address to use.