Privacy Policy
Last updated: 7 September 2026
What we collect
- Account data: your email, hashed password (Argon2id), the firm name and slug you choose, and the role of each teammate you invite.
- QuickBooks connection state: realm IDs of the QBO companies you connect, the encrypted OAuth refresh tokens needed to call QBO on your behalf, and the most recent token-refresh timestamp.
- Usage data: per-tool-call records (firm, realm, tool name, success/failure, duration, error code, timestamp) for billing, debugging, and abuse detection.
- Product analytics: a
tool_callevent per tool call, sent to PostHog. It carries your firm ID, the QBO realm ID, the tool name, success/failure, duration, and error code. It isnot tied to you as an individual, and it does not carry your QBO records, report contents, or message text. See Product analytics below. - Report runs: when you save a report, we store its output — the text your AI assistant produced for that company — along with the report type, company, and timestamps, so you can read it again from the dashboard. Deleting the company or your firm deletes these too.
- Generated PDFs (temporary): when you generate a report PDF, the file is held on our server only long enough for you to download it — up to 24 hours — and is then deleted automatically. We don't keep a copy or use it for anything else.
- Billing: we don't store your card. Stripe does. We store the Stripe customer ID and subscription status that Stripe sends us via webhook.
- Server logs: request metadata (IP, user agent, timestamps, structured event names) shipped to Better Stack.
What we don't do
- We don't sell your data.
- We don't train AI models on your QBO data.
- We don't run advertising or cross-site tracking inside the product. Every page behind your login is free of ad networks and third-party trackers: no Google Analytics, no Meta pixel. We do use one privacy-focused product-analytics tool for our own product metrics — see Product analytics.
- One exception, and it is on the public pages only: our sign-up, legal, status and help pages carry the LinkedIn Insight Tag, so we can see which LinkedIn ads lead to a sign-up. Our sign-in, password-reset and email-verification pages do not: those URLs and forms carry credentials. See Advertising.
Advertising
We advertise Numbers Game on LinkedIn, and our public pages carry the LinkedIn Insight Tag so we can tell which of those ads led to a sign-up. It sets LinkedIn cookies, and reports the public page you are on to LinkedIn, which may use that for ad measurement and for targeting on its own platform under LinkedIn's privacy policy.
- Where it runs: the public pages only —
/signup,/login, password reset and email verification,/legal/*,/guide,/quick-start,/statusand/support. - Where it does not run: anywhere behind your login. The dashboard, your companies, your reports and the admin pages don't load it, so it never sees your firm, your client companies, or anything from QuickBooks.
- Turning it off: LinkedIn members can switch off ad tracking in LinkedIn's own advertising settings. Any tracker-blocking extension or browser also blocks it, and nothing in Numbers Game depends on it — block it and the product works exactly the same.
Product analytics
We use PostHog to understand which features are used and where they fail. PostHog is hosted in the European Union (eu.i.posthog.com), so this data does not leave the EU.
- From the AI connector: one
tool_callevent per tool call, containing the tool name, whether it succeeded, how long it took, a normalized error code, the QBO realm ID, and your firm ID as the identifier. - From this web dashboard: page views (which page, when) and session replays — see below. Autocapture is deliberately off, because it would record the text of whatever you click, and on this dashboard that is client financial data.
- What we don't send: any per-user identifier, your QBO data, report contents, file contents, message text, email addresses, names, or passwords. Analytics are recorded at the firm level only, so these events are not tied to an individual teammate.
- Why: product improvement, reliability monitoring, and diagnosing errors — not advertising or resale.
We deliberately do not send a per-user identifier from either surface — the dashboard and the AI connector both report against your firm. Because PostHog retains events for 7 years, we keep them tenant-level so no individual's activity is tracked over that period.
Session replay
We record replays of dashboard sessions to diagnose bugs and confusing screens, with strict masking on: every input and all on-screen text is masked before the recording leaves your browser. A replay shows the shape of a page and where you clicked — never account balances, customer names, amounts, or anything else you can read on screen. Replays are attributed to your firm, not to you individually, and PostHog deletes them after 3 months. Replay does not run on your QuickBooks data itself, only on this dashboard.
Where data lives
Application data sits in a Postgres database hosted on Oracle Cloud (Amsterdam region). Nightly backups go to Cloudflare R2 for off-cloud durability. Encrypted QBO tokens use AES-256-GCM with keys stored separately from the database. Server-to-AI calls go through Anthropic and OpenAI under their own privacy terms when you use their MCP clients with Numbers Game.
Who we share with
- Intuit (QuickBooks Online): when you authorize Numbers Game, Intuit issues OAuth tokens that let us call QBO on your behalf. Tool calls move between Numbers Game and Intuit as you direct them.
- Anthropic / OpenAI: when you connect Numbers Game to their AI clients, the requests you make and the data those requests return pass through them under their own privacy terms.
- PostHog (EU): product-analytics events as described above.
- Stripe: for billing.
- Resend: for transactional email (verification, password reset, invites).
- Better Stack: for log search and alerting.
- Cloudflare: R2 for backups and data exports.
- LinkedIn: visits to our public pages, via the Insight Tag described under Advertising. Never anything from behind your login.
We don't share with anyone else without your explicit consent except where compelled by law.
How long we keep things
- Account and QBO connection data: for as long as your firm exists. On deletion, see Your rights.
- Backups: nightly database backups in Cloudflare R2 are deleted automatically after 30 days by bucket lifecycle policy. Data you delete can therefore persist in backups for up to 30 days before ageing out.
- Generated report PDFs: deleted automatically 24 hours after they are generated, whether or not you downloaded them. Download links expire on the same schedule.
- Report runs: kept until you delete the company or your firm, or until the retention period set for that report type elapses, whichever comes first. Where no retention period is set, they are kept until you delete them.
- Log archive: we also keep a rolling local copy of shipped logs on our own server for about 7 days.
- Expired credentials: OAuth authorization codes are purged 7 days after expiry; access tokens, refresh tokens, sessions, and verification tokens 30 days after they expire or are revoked.
- Server logs: retained in Better Stack for 3 days, then deleted. Metrics derived from them are retained for 30 days.
- Product analytics: PostHog retains analytics events for 7 years on our plan, and session replays for 3 months. We don't send AI prompts or responses to PostHog. These events identify your firm, not individual users.
- Usage and audit records: per-tool-call usage records and audit-log entries are retained after firm deletion as business records — we need them for billing history, security investigations, and legal obligations. They identify the firm and tool activity, not your QBO record contents.
Slack integration
When you connect Slack to Numbers Game (“NumbersGame AI agent”), we request only the access needed to post task updates and route them correctly.
- What we store: your workspace's bot token (encrypted at rest with AES-256-GCM), your workspace ID and name, the IDs and names of channels you assign to companies, a cached channel-canvas ID, and a mapping of your firm's members to their Slack user IDs (matched by email or manual self-link) so only authorized members can act on tasks.
- What we read: your channel list (so you can pick a channel) and Slack user email/identity (to match Slack users to Numbers Game members). We read a channel's canvas only to locate and update our own section. We do not read your channel messages, files, or direct messages.
- What we write: task messages and updates, and a “Numbers Game” section in the canvas of the channels you assign — nowhere else.
- What we never do: we don't post to channels you haven't assigned, and we don't sell or share your Slack data with third parties.
- Removal: disconnect Slack anytime from Settings (revokes our access and clears channel assignments); uninstalling the app from Slack revokes our bot token immediately.
- Bot permissions requested:
chat:write,channels:read,groups:read,users:read,users:read.email,canvases:read,canvases:write.
Your rights
- Access / export: request a zip of your firm's data from the dashboard at any time.
- Deletion: delete your firm from the billing page. Soft-deleted immediately, hard-deleted 30 days later. You can also delete a single connected company from the dashboard. After hard deletion, copies may persist in backups for up to 30 days, and usage and audit records are retained as described in How long we keep things.
- Correction: email us if data we hold about you is wrong — we'll fix it.
- Objection: email us if you want your firm's product-analytics events excluded, and we'll suppress them.
Contact
Questions: [email protected]
