gooder-books is a private internal tool. It is not offered to the public, has no end-user sign-ups, and is used solely by the owner and authorised bookkeeping staff of Gooder Labs LLC and its affiliated companies (Mean Group LLC, Sam Lily Properties LLC, Trendensity LLC) to maintain those companies' own accounting records in QuickBooks Online.
Using the com.intuit.quickbooks.accounting scope, the application reads and writes the
company's own QuickBooks Online accounting data: chart of accounts, vendors, customers, items, and
transactions (purchases, deposits, journal entries, bills, payments), plus standard accounting
reports. It accesses only the QuickBooks companies (realms) explicitly connected by the owner.
The data is mirrored to a local database on the operator's own computer so the application can propose transaction categorisations and, when the operator approves, write those categorisations back to QuickBooks Online. The application does not use the data for advertising, profiling, resale, or training of machine-learning models, and it is never sold or shared with third parties.
All mirrored data stays on the operator's local machine (a Mac). There is no gooder-books cloud server, no hosted database, and no third-party analytics. OAuth credentials are stored in the operator's 1Password vault and read at runtime; they are never written to plaintext files or logs.
We do not share accessed QuickBooks data with any third party. Data may be exported by the operator (for example, a CSV for the company's accountant) at the operator's own initiative and under the operator's control.
The local mirror can be deleted at any time by removing the application's data directory. Revoking the application's access from within QuickBooks Online (Apps → Manage) immediately ends all further access. No copy of the data is retained by any gooder-books-operated service, because none exists.
Secrets live in 1Password and are read at runtime; refresh tokens rotate on every use and are written back to 1Password immediately. The local recovery cache of the refresh token is encrypted. The application binds its optional web dashboard to localhost only and adds no external network surface beyond Intuit's own APIs.
The application is a business accounting tool and is not directed to children.
Because this is an internal tool with a single operator, changes to this policy are recorded in the application's repository. The "last updated" date above reflects the current version.
Questions about this policy: Gooder Labs LLC — homebase@kensteam.com.