Privacy Policy

How Claude MCP Handles Information

Effective
1 September 2026
Version
1.0
Operator
ZINA COSMETIC CLINIC INC

Claude MCP (the “Application”) is a private integration operated by ZINA COSMETIC CLINIC INC that connects our own QuickBooks Online company file to internal analysis tools. It has no public users and collects no information from anyone outside our organisation. This policy explains what it touches, where that information goes, and how to shut it off.

1

Scope

This policy covers only the Application. It connects to exactly one QuickBooks Online company — ours. It is not offered to the public, has no user accounts, and collects no information from visitors, customers, or any third party.

We are the sole data subject and the sole data controller. Any personal information the Application encounters is information already held in our own accounting records, such as the names and contact details of our customers, vendors, and employees.

2

What the Application accesses

The Application reads — and, where write access is enabled, modifies — data in our QuickBooks Online company through Intuit’s official API. It requests data only when an authorised person asks a question that requires it. There is no background syncing, scheduled harvesting, or bulk extraction.

CategoryExamplesWhy
Financial records Invoices, bills, payments, journal entries, accounts, reports To answer bookkeeping and reporting questions
Contact records Customer, vendor, and employee names and details held in QuickBooks Returned as part of the transactions they relate to
Company profile Company name, fiscal settings, chart of accounts To interpret figures correctly
Authorisation credentials OAuth client ID and secret, refresh token, company (realm) ID To authenticate to Intuit
3

What is stored, and where

The Application has no server, no database, and no hosted component. It runs as a local process on a computer we control.

  • Credentials are stored in a single configuration file on that computer, restricted to the owner account. Intuit rotates the refresh token periodically and the file is rewritten in place.
  • QuickBooks records are not written to disk. They are fetched on demand, used to answer the question at hand, and not retained by the Application.
  • No analytics, telemetry, advertising identifiers, or tracking of any kind are collected.
4

Where information is sent

Stated plainly: when an authorised person asks a question about our accounting data, the QuickBooks records needed to answer it are transmitted to Anthropic’s API, because that is where the AI assistant processing the question runs. Anyone relying on this Application should understand that before using it.

Information travels only along these paths:

  • To Intuit — API requests for our own company data, over TLS.
  • To Anthropic — the retrieved records, as part of the conversation in which they were requested. Handling is governed by Anthropic’s privacy policy and the terms of our account.

Information is sent nowhere else. We do not sell, rent, trade, or disclose it to any other party, and there are no advertising, marketing, or data-broker recipients.

5

Legal basis and purpose

We access this information for one purpose: internal bookkeeping, financial analysis, and reporting for our own business. It is not used for profiling, automated decision-making about individuals, marketing, or any secondary purpose.

6

Security

  • All communication with Intuit and Anthropic uses TLS.
  • Credentials live in a permission-restricted local file, never in shared configuration, and are excluded from version control.
  • Access tokens are short-lived and refreshed automatically; refresh tokens rotate and expire if unused.
  • The computer running the Application is access-controlled and disk-encrypted.
  • Write and delete capabilities can be disabled entirely, leaving read-only access.

No system is perfectly secure, but the design keeps the exposure small: nothing is hosted, nothing is centralised, and there is no accumulated store to breach.

7

Retention and deletion

The Application retains no QuickBooks data of its own, so there is nothing to expire. Credentials persist until deleted. Conversation history containing accounting data is retained under Anthropic’s policies and can be deleted through that account.

8

Revoking access

Access can be withdrawn at any time, and takes effect immediately:

  • In QuickBooks Online, go to Settings → Apps → Connected Apps and disconnect the Application. Its tokens stop working at once.
  • Delete the local configuration file to remove the stored credentials from the computer.
9

Canadian privacy law

We operate in Canada, and personal information in our accounting records is handled in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial legislation. Individuals whose personal information appears in our records may request access to it, ask that it be corrected, or raise a concern about how it is handled, using the contact details below.

10

Changes

We may update this policy. The effective date above always reflects the current version.

11

Contact

Privacy questions or requests may be sent to omar@zinaclinic.com.

ZINA COSMETIC CLINIC INC · Effective 1 September 2026 · Version 1.0