Privacy Policy

Prepared beta draft — not effective

At a glance: VODER reads accounting data for questions and reports. Optional VODER Actions processes contact and invoice changes in Xero. Creating a draft invoice does not require confirmation or create a duplicate-prevention record; the other six Actions require confirmation. We do not sell accounting data, use it for advertising or use it to train AI models. Questions? Email privacy@voder.ai.

What we collect

Optional VODER Actions for Xero

VODER Actions supports creating contacts and correcting their name or email; creating and editing draft invoices; approving draft invoices; sending approved invoices; and emailing overdue invoices again. Only an organisation owner can enable or use Actions. The owner controls all supported actions together for each organisation. Creating a draft invoice calls Xero after the required details, organisation selection and permission checks. The other six Actions require confirmation, including confirmation of the recipient before an invoice email. Other providers remain read-only.

We process the contact details, invoice details and other inputs needed for your requested action. Changes go to Xero. The result goes to the AI assistant you deliberately connected, whose provider handles it under its own privacy policy and settings. Xero sends invoice emails to the recipient you confirmed. Google Cloud runs this processing as described below.

Actions records and retention

We store whether Actions is enabled for the organisation. For each attempted action other than creating a draft invoice, we store a limited record to prevent duplicate actions. Depending on the action and its outcome, that record contains:

These duplicate-prevention records do not contain contact names, invoice numbers, invoice line items or a copy of your chat. They have no automatic expiry and are not removed when you delete your account. This is an exception to the read-only data-disposal statements below.

Creating a draft invoice calls Xero directly after the required details, organisation selection and permission checks. It does not ask for confirmation first and does not create a duplicate-prevention record. Each of the other six Actions shows exactly what it will change or send and waits for confirmation in the conversation.

Turning Actions off stops further VODER Actions writes for that organisation. It does not undo completed changes or emails, delete retained action records, or remove permissions already authorised in Xero. There is no additional VODER Actions fee.

FreshBooks status and data handling

FreshBooks is available in VODER’s free read-only beta. When you choose FreshBooks, VODER takes you directly to FreshBooks to authorise the accounting connection. Creating or signing in to a VODER account with FreshBooks does not connect accounting data.

VODER stores the FreshBooks business and account identifiers needed to bind your organisation, encrypted access and refresh tokens and their expiry information. When you ask a question, VODER retrieves only the supported FreshBooks accounting information needed for the answer, returns the result to the AI assistant you deliberately connected and does not retain the financial figures.

VODER uses FreshBooks data only to provide, secure and troubleshoot the service and to complete a disconnect you request. VODER does not sell FreshBooks data, use it for advertising or model training, or add, edit or delete FreshBooks records. FreshBooks supplies the data you authorise; Google Cloud processes the request and stores encrypted connection records; your connected AI assistant receives the answer under its own provider’s terms and privacy policy.

FreshBooks connection tokens are kept encrypted while the connection is available and removed after a confirmed disconnect or account deletion. You can disconnect VODER in your VODER account or in FreshBooks under Connected Apps. Disconnecting does not delete source records held by FreshBooks or an answer already held by your AI assistant.

QuickBooks status and authorisation

QuickBooks Online is available in VODER’s read-only beta. VODER reads supported QuickBooks data only when you ask a question. It does not add, edit or delete QuickBooks records.

When you select QuickBooks Online while signed in, VODER takes you directly to Intuit to authorise the connection.

What QuickBooks data we collect

If you connect QuickBooks Online, VODER collects:

Voder never receives or stores your QuickBooks password. You sign in to Intuit directly.

How we use QuickBooks data

VODER uses QuickBooks data to connect the selected company, retrieve the supported QuickBooks accounting information needed to answer the question you ask, return the answer to the AI assistant you deliberately connected, keep the service secure and reliable, troubleshoot failures, and complete a disconnect you request. VODER does not sell QuickBooks data, use it for advertising, benchmark Intuit or QuickBooks, or use it to train, fine-tune, adapt, enhance or build an artificial intelligence or machine learning model.

Who receives QuickBooks data

The QuickBooks flow uses these services and recipients:

Resend sends Voder sign-in emails and Stripe handles separate subscription billing. They do not receive QuickBooks data as part of the QuickBooks read flow. Voder does not otherwise sell or share QuickBooks data for advertising or model training.

How long we keep QuickBooks data

Disconnecting and deleting QuickBooks data

You may disconnect QuickBooks Online from your authenticated VODER account or through Intuit’s connected-app settings at any time. Disconnection immediately blocks future live VODER reads and starts token deletion and deletion of other QuickBooks data VODER controls. A provider or deletion failure does not restore live read access.

Disconnection is separate from cancelling a subscription or deleting your VODER account. It does not delete your source records in QuickBooks or copies held by the AI assistant, its provider or another person outside VODER’s control. To reconnect later, select QuickBooks Online in your VODER account and authorise the connection with Intuit.

You may also ask for access, correction or deletion by emailing privacy@voder.ai. Voder may retain only the minimum record required by an applicable legal duty and will record the reason and disposal date privately.

Changes to this policy

VODER publishes a new version and effective date when this policy changes. The current Terms and Privacy Policy remain available on the VODER website.

What VODER reads from Xero

When you connect Voder to an AI assistant such as Claude or ChatGPT, the assistant can call more than 20 read-only tools on your behalf. Each tool takes a question (and parameters like a date range or an organisation) as its input, reads the matching data from Xero, and returns the answer to your assistant. The tools cover:

VODER’s accounting read tools do not create, edit or delete Xero records. The separate VODER Actions connector supports only the contact and invoice changes described above.

Read-only Xero data and Actions records

Financial data fetched for VODER’s read-only questions and reports is discarded after the answer is returned. VODER Actions retains the limited action records described above. We never receive or store your Xero password.

How we use it

We don’t use your data to train AI models, and we don’t use it for advertising.

Who we share it with

We rely on a small set of service providers to run VODER:

We do not sell your data or share it for advertising.

How long we keep it

When paid access ends

Ending paid access is not an account-deletion request. Voder stops reading the organisation’s Xero data and removes the Xero connection and encrypted token as described above. The Voder account, organisation details, access grants and members, invitations, feedback, entitlement, and limited billing and notice records remain. You can still ask us to delete your account under the choices below.

How we protect it

Sign-in is passwordless: you receive a single-use code (and an equivalent link) by email, so there’s no password to steal. Sign-in codes are hashed at rest, single-use, time-limited, and attempt-capped. Connection tokens are encrypted. Our server logs record only the shape of requests (which tool ran and how long it took), never your financial values.

Your choices

To make any of these requests, email privacy@voder.ai.

Changes to this policy

If we change how we handle your data, we’ll update this page and the version and effective date above.

Contact

Voder is operated by Windy Road Technology Pty Limited in Australia. Privacy questions: privacy@voder.ai.

Back to home