Privacy Policy
Prepared beta draft — not effective
At a glance: VODER reads accounting data for questions and reports. Optional VODER Actions processes contact and invoice changes in Xero. Creating a draft invoice does not require confirmation or create a duplicate-prevention record; the other six Actions require confirmation. We do not sell accounting data, use it for advertising or use it to train AI models. Questions? Email privacy@voder.ai.
What we collect
- Your email address, so we can sign you in.
- When you first visit Voder through an approved paid campaign, we may store the campaign source, campaign name, creative label and first-visit time in a first-party cookie for up to 30 days. If you create a new Voder account during that period, a later sign-in on that device can attach the earlier details to your account. The earliest valid visit wins and later visits do not replace it. We keep the account attribution until the account is deleted. We do not store the full page address, referrer, search term, advertising click ID, IP address or browser details for this purpose. We do not use Microsoft Clarity or third-party tracking pixels.
- Basic account information: the organisations you can access and the grants that link you to them.
- A single-use sign-in code (and the equivalent sign-in link) we email you when you log in. We store only a hashed copy of the code, never the code itself.
- When you verify your identity and create your account, we keep a limited record showing whether one non-promotional welcome email is pending or was accepted by our email provider. It stores your internal account identifier, document and message versions, event times and delivery state. After the first delivery attempt, it also stores the Voder release and a one-way fingerprint used to verify the message. It does not store your email address or the message body.
- Encrypted connection tokens and provider identifiers for the Xero, FreshBooks or QuickBooks Online organisation you connect.
- The tool calls your AI assistant makes on your behalf: the tool name and its parameters (for example a date range or an organisation), which we use to fetch the answer from your connected accounting service in real time. We don’t receive your chat with the assistant, and we don’t store the parameter values for read-only VODER operations. The separate Actions records are described below.
- Feedback notes you or your AI assistant choose to send. After the assistant records feedback, it tells you what it recorded for the VODER team and why. It stops recording feedback for that conversation if you object.
- If you subscribe, limited billing records from Stripe: checkout, customer, subscription and payment references; amount and currency; payment or subscription status; and the date your paid access runs through. We also record whether a required trial, transition, billing or cancellation notice was sent. Stripe collects your payment and billing details in its hosted checkout. Voder does not receive or store your full card number.
- Technical logs about the shape of each request: which tool ran, the names of its parameters and how long they were, whether it succeeded, and how long it took. These never contain the parameter values or your financial figures.
Optional VODER Actions for Xero
VODER Actions supports creating contacts and correcting their name or email; creating and editing draft invoices; approving draft invoices; sending approved invoices; and emailing overdue invoices again. Only an organisation owner can enable or use Actions. The owner controls all supported actions together for each organisation. Creating a draft invoice calls Xero after the required details, organisation selection and permission checks. The other six Actions require confirmation, including confirmation of the recipient before an invoice email. Other providers remain read-only.
We process the contact details, invoice details and other inputs needed for your requested action. Changes go to Xero. The result goes to the AI assistant you deliberately connected, whose provider handles it under its own privacy policy and settings. Xero sends invoice emails to the recipient you confirmed. Google Cloud runs this processing as described below.
Actions records and retention
We store whether Actions is enabled for the organisation. For each attempted action other than creating a draft invoice, we store a limited record to prevent duplicate actions. Depending on the action and its outcome, that record contains:
- the organisation identifier and action type;
- the action state and available timing information; and
- the provider record identifier and outcome.
These duplicate-prevention records do not contain contact names, invoice numbers, invoice line items or a copy of your chat. They have no automatic expiry and are not removed when you delete your account. This is an exception to the read-only data-disposal statements below.
Creating a draft invoice calls Xero directly after the required details, organisation selection and permission checks. It does not ask for confirmation first and does not create a duplicate-prevention record. Each of the other six Actions shows exactly what it will change or send and waits for confirmation in the conversation.
Turning Actions off stops further VODER Actions writes for that organisation. It does not undo completed changes or emails, delete retained action records, or remove permissions already authorised in Xero. There is no additional VODER Actions fee.
FreshBooks status and data handling
FreshBooks is available in VODER’s free read-only beta. When you choose FreshBooks, VODER takes you directly to FreshBooks to authorise the accounting connection. Creating or signing in to a VODER account with FreshBooks does not connect accounting data.
VODER stores the FreshBooks business and account identifiers needed to bind your organisation, encrypted access and refresh tokens and their expiry information. When you ask a question, VODER retrieves only the supported FreshBooks accounting information needed for the answer, returns the result to the AI assistant you deliberately connected and does not retain the financial figures.
VODER uses FreshBooks data only to provide, secure and troubleshoot the service and to complete a disconnect you request. VODER does not sell FreshBooks data, use it for advertising or model training, or add, edit or delete FreshBooks records. FreshBooks supplies the data you authorise; Google Cloud processes the request and stores encrypted connection records; your connected AI assistant receives the answer under its own provider’s terms and privacy policy.
FreshBooks connection tokens are kept encrypted while the connection is available and removed after a confirmed disconnect or account deletion. You can disconnect VODER in your VODER account or in FreshBooks under Connected Apps. Disconnecting does not delete source records held by FreshBooks or an answer already held by your AI assistant.
QuickBooks status and authorisation
QuickBooks Online is available in VODER’s read-only beta. VODER reads supported QuickBooks data only when you ask a question. It does not add, edit or delete QuickBooks records.
When you select QuickBooks Online while signed in, VODER takes you directly to Intuit to authorise the connection.
What QuickBooks data we collect
If you connect QuickBooks Online, VODER collects:
- your authenticated Voder account identifier;
- the QuickBooks company identifier needed to bind the connection;
- encrypted OAuth access and refresh tokens, their expiry information and the authorised
com.intuit.quickbooks.accountingscope; - supported contact, invoice, bill, payment, quote, account, credit-note and organisation information returned by QuickBooks;
- supported financial report data needed to answer your question;
- the name and shape of the Voder request used to obtain the answer, without storing its parameter values in technical logs; and
- historical acceptance or withdrawal evidence created before the direct Intuit authorisation journey was introduced.
Voder never receives or stores your QuickBooks password. You sign in to Intuit directly.
How we use QuickBooks data
VODER uses QuickBooks data to connect the selected company, retrieve the supported QuickBooks accounting information needed to answer the question you ask, return the answer to the AI assistant you deliberately connected, keep the service secure and reliable, troubleshoot failures, and complete a disconnect you request. VODER does not sell QuickBooks data, use it for advertising, benchmark Intuit or QuickBooks, or use it to train, fine-tune, adapt, enhance or build an artificial intelligence or machine learning model.
Who receives QuickBooks data
The QuickBooks flow uses these services and recipients:
- Intuit authenticates the connection and supplies the QuickBooks data you authorised. Voder acts independently and does not process that data on Intuit’s behalf.
- Google Cloud runs Voder’s application service in Singapore and stores Voder’s primary database and encryption key in Australia. Encrypted QuickBooks tokens and private consent records are stored there; requested QuickBooks data passes through the application service to produce your answer.
- Your deliberately connected AI assistant receives the answer to the question you asked. Its provider handles that answer under its own privacy policy, terms and settings.
Resend sends Voder sign-in emails and Stripe handles separate subscription billing. They do not receive QuickBooks data as part of the QuickBooks read flow. Voder does not otherwise sell or share QuickBooks data for advertising or model training.
How long we keep QuickBooks data
- Encrypted QuickBooks tokens: kept while the connection and your acceptance are current. Withdrawal blocks their use immediately. Voder removes the stored tokens after Intuit confirms disconnection; if that confirmation is temporarily unavailable, the tokens stay encrypted only for bounded reconciliation while all live QuickBooks User Data reads remain blocked.
- QuickBooks accounting data: fetched in real time to answer your question, returned to your connected AI assistant and then discarded by Voder. The assistant provider may retain the answer under its own policy and settings.
- Technical logs: contain request shape, timing and outcome, not request values or QuickBooks financial figures, and are kept for one year.
- Historical acceptance and withdrawal evidence: user-linked evidence created before the direct Intuit authorisation journey was introduced is kept while your VODER account is active. Account deletion removes the current record and raw user-linked events. If a law or provider duty requires Voder to retain proof, Voder keeps only a privacy-minimised terminal receipt for the documented required period and then deletes it.
Disconnecting and deleting QuickBooks data
You may disconnect QuickBooks Online from your authenticated VODER account or through Intuit’s connected-app settings at any time. Disconnection immediately blocks future live VODER reads and starts token deletion and deletion of other QuickBooks data VODER controls. A provider or deletion failure does not restore live read access.
Disconnection is separate from cancelling a subscription or deleting your VODER account. It does not delete your source records in QuickBooks or copies held by the AI assistant, its provider or another person outside VODER’s control. To reconnect later, select QuickBooks Online in your VODER account and authorise the connection with Intuit.
You may also ask for access, correction or deletion by emailing privacy@voder.ai. Voder may retain only the minimum record required by an applicable legal duty and will record the reason and disposal date privately.
Changes to this policy
VODER publishes a new version and effective date when this policy changes. The current Terms and Privacy Policy remain available on the VODER website.
What VODER reads from Xero
When you connect Voder to an AI assistant such as Claude or ChatGPT, the assistant can call more than 20 read-only tools on your behalf. Each tool takes a question (and parameters like a date range or an organisation) as its input, reads the matching data from Xero, and returns the answer to your assistant. The tools cover:
- Profit and loss over time (by month, quarter, or year), revenue trends, and an executive overview of the business at a glance.
- Expenses by category and supplier, invoices, bills, credit notes, payments, aged receivables and payables, and bank transactions.
- Contacts, accounts, the trial balance, GST status, and your organisation’s details.
- Recording and reviewing feedback you or your AI assistant choose to send about VODER.
VODER’s accounting read tools do not create, edit or delete Xero records. The separate VODER Actions connector supports only the contact and invoice changes described above.
Read-only Xero data and Actions records
Financial data fetched for VODER’s read-only questions and reports is discarded after the answer is returned. VODER Actions retains the limited action records described above. We never receive or store your Xero password.
How we use it
- To sign you in, acknowledge a newly created account once and keep your session secure.
- To connect your AI assistant to your Xero data, with your consent.
- To answer the questions your assistant asks, by reading from Xero in real time.
- To carry out the VODER Actions you request and prevent duplicates for actions other than creating a draft invoice.
- To start and manage a subscription, confirm paid access, prevent duplicate charges, and handle cancellation or billing support.
- To act on feedback you or your AI assistant choose to send and to keep VODER working, secure, and improving. After the assistant records feedback, it tells you what it recorded for the VODER team and why. It stops recording feedback for that conversation if you object.
We don’t use your data to train AI models, and we don’t use it for advertising.
Who we share it with
We rely on a small set of service providers to run VODER:
- Google Cloud: VODER’s primary database and encryption key are in Australia, and its production application service runs in Singapore.
- Resend: sends your sign-in emails and the one non-promotional welcome email after you verify your identity and create your account.
- Xero, FreshBooks and Intuit: supply accounting data you authorise VODER to read.
- Stripe: hosts subscription checkout and processes payments, billing details, tax information, and fraud-prevention signals. Stripe may process personal information in Australia and overseas under Stripe’s privacy policy.
- Your AI assistant (such as Claude or ChatGPT): when you ask a question, the answer is returned to the assistant you connected. Your assistant’s provider handles that answer under its own privacy policy.
We do not sell your data or share it for advertising.
How long we keep it
- Sign-in codes: the hashed code is single-use and deleted automatically 15 minutes after it is issued.
- Your session: your signed-in session expires after 7 days, after which you sign in again.
- Xero connection token: kept encrypted while the connection is available. It is removed when you disconnect Xero, delete your account, or paid access ends and Xero confirms that Voder’s connection has been removed. If Xero cannot confirm removal, Voder blocks access and keeps the encrypted token only for a limited retry period.
- FreshBooks connection tokens: kept encrypted while the connection is available and removed after a confirmed disconnect or account deletion.
- Email and account records: kept while your account is active, and deleted when you ask us to delete your account.
- Welcome-email record: kept while your account is active so Voder can send the acknowledgement once and avoid duplicates, and deleted with your account.
- Feedback notes: kept so we can act on them and improve Voder, and deleted on request.
- Billing and notice records: limited subscription, payment-status, deadline, cancellation, and notice records are kept while your account is active and as needed for tax, accounting, fraud, dispute, and legal obligations. They do not include your full card number.
- Technical logs: kept for one year for security investigation and to meet Xero’s audit requirements, then automatically deleted. Deleting your account does not remove these entries early; they contain no request values or financial figures.
- Read-only Xero financial data: fetched for questions and reports, then discarded. The separate Actions records have no automatic expiry and remain after account deletion.
When paid access ends
Ending paid access is not an account-deletion request. Voder stops reading the organisation’s Xero data and removes the Xero connection and encrypted token as described above. The Voder account, organisation details, access grants and members, invitations, feedback, entitlement, and limited billing and notice records remain. You can still ask us to delete your account under the choices below.
How we protect it
Sign-in is passwordless: you receive a single-use code (and an equivalent link) by email, so there’s no password to steal. Sign-in codes are hashed at rest, single-use, time-limited, and attempt-capped. Connection tokens are encrypted. Our server logs record only the shape of requests (which tool ran and how long it took), never your financial values.
Your choices
- Disconnect Xero at any time. After Xero confirms the connection is gone, Voder removes the stored connection token.
- Disconnect FreshBooks or QuickBooks Online from your VODER account or the provider’s connected-app settings at any time.
- If you subscribe, cancel before the next billing date. Access continues through the current trial, transition, or paid period, then Voder automatically removes its Xero connection. Cancellation is separate from deleting your VODER account.
- Ask us for a copy of the account information we hold about you, or ask us to correct it.
- Ask us to delete your account and the deletable data associated with it. We may keep limited billing, notice, tax, fraud, dispute, and legal records when required or needed for those purposes. The Actions records described above also remain after account deletion.
To make any of these requests, email privacy@voder.ai.
Changes to this policy
If we change how we handle your data, we’ll update this page and the version and effective date above.
Contact
Voder is operated by Windy Road Technology Pty Limited in Australia. Privacy questions: privacy@voder.ai.
Back to home