Legal

Privacy policy

Effective September 29, 2026. Applies to zenofirm.com, the Zeno cloud workspace at app.zenofirm.com, the Zeno MCP server, and Zeno for QuickBooks Desktop.

Who is responsible for your information

The service is operated by Zeno Services, LLC, and this policy describes what it does with your information. Where you use Zeno to keep your own books, Zeno Services, LLC is the controller of that information. Where you use Zeno to work on books belonging to your clients, your firm is the controller and Zeno is a processor acting on your firm's instructions; a data processing addendum is available on request.

Zeno Services, LLC also operates zenorent.com, a separate cloud ERP service. Zeno and Zenorent are two products of the same company, and some company infrastructure is shared between them. Desktop download, order, and licence records are currently held in storage named for the older service. Nothing in that arrangement discloses your information to another company.

Zeno Services, LLC
Brooklyn, New York, United States

Privacy: support@zenofirm.com
Security: security@zenofirm.com

The short version

Zeno processes the account information needed to run your workspace and the bookkeeping information you choose to connect. We do not sell it, we do not use it for advertising, and we do not train AI models on it. We share it only with the providers listed below, only to operate the service.

What we collect

Account and billing information

Name, email address, firm or company name, authentication credentials in hashed form, plan and subscription status, and the licence and order references for Desktop purchases. Card details are entered directly with our payment processor and are never received or stored by Zeno.

Connected bookkeeping data

When you authorise a QuickBooks connection, Zeno reads and stores working copies of ledger data for the companies you connect. This includes charts of accounts, names, items, transactions, attachments, reports, and related records. These copies allow work to be prepared and checked without querying the platform on every request. New entries and changes to names reach that ledger through a batch a person reviews and approves. A small set of other changes happen only when you ask for them: correcting, voiding or deleting an existing transaction, attaching a document, sending an invoice, setting up a recurring reminder, and company settings such as currencies, tax codes and company details. The ones that remove or send something ask you to confirm first, and every one of them is recorded in the work history. Zeno never sets up a transaction that posts by itself and never moves money.

Bank and card data

When you connect a bank or card account, Zeno uses Plaid Inc. ("Plaid") to reach it. You sign in to your bank on Plaid's own page; Zeno never sees or stores your bank username or password. With your consent, Zeno receives from Plaid the names, types and last four digits of the accounts you connect, their balances, and their transaction history: date, amount, description, merchant, and the cardholder name where the bank provides one. If you turn on statements for a connection, Zeno also receives the bank's monthly statement for each account it stages, as a PDF in your document inbox. Zeno uses this only to prepare bookkeeping entries for your review, and keeps the authorisation Plaid issues for the connection encrypted. You can disconnect a bank at any time, which removes the connection at Plaid and stops all further collection.

Firm memory you create

Coding rules, client knowledge entries, playbooks, reviewer decisions, and the work log. This is content you author or confirm.

Documents you send

Files uploaded to, or emailed into, the document inbox, and the data extracted from them.

AI interaction data

When an AI client connects to the Zeno MCP server, usage records include the tool name, the names of supplied arguments (not their values), the company when specified, timing, and success or failure. Separately, the bookkeeping journal retains the plans, decisions, and posting results needed to explain work performed. We do not receive or store the rest of your conversation with the AI client, and we do not request it.

Operational and security logs

IP address, timestamps, user agent, and request metadata needed to secure, debug, and support the service.

Website analytics

zenofirm.com uses Google Analytics to measure aggregate traffic. The marketing site does not require an account.

What we deliberately do not collect

Zeno does not collect payment card numbers, protected health information, government-issued identification numbers such as Social Security, tax identification or employer identification numbers, or the credentials you use with third-party services other than the authorisation tokens described below. Zeno's tools refuse a tax id, Social Security number or birth date rather than accept one, in the cloud workspace and in Zeno for QuickBooks Desktop from version 1.14.0; you enter those in QuickBooks directly. In the cloud, if QuickBooks Online returns a tax id when Zeno reads your lists, Zeno keeps only its last four digits; the Desktop edition reports only whether a vendor has one on file. Do not send these to support or into the document inbox. Zeno collects only what a tool needs to do its job; it does not gather conversation content beyond the tool calls themselves.

Why we process it

To provide and secure the service; to connect to the accounting platforms you authorise; to prepare, check, approve, apply, and reverse bookkeeping work you request; to keep the durable audit trail that is a core feature; to bill you; to answer support requests; to detect abuse; and to meet legal obligations.

Zeno is offered to customers in the United States and Canada. If you are in Canada, we rely on your express consent where we ask for it and implied consent where the purpose is obvious from how you use the service, together with the exceptions PIPEDA provides for business contact information and records we are required to keep. You may withdraw consent, subject to legal and contractual limits, by emailing us.

AI models and training

Zeno does not operate a foundation model and does not train one. We do not use your data, your clients' data, or your firm memory to train any AI model, and we do not permit our providers to do so on our behalf.

Zeno is designed so that you bring your own AI client. When you connect one, that client and its provider process your requests and Zeno's responses under the provider's terms and privacy policy, not ours. You decide which provider to trust with that traffic. We list the common providers below to help you make an informed choice.

Who we share it with

We share information with the following categories of recipient, only as needed to operate the service. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

How long we keep it

Zeno for QuickBooks Desktop

The Desktop product runs on your workstation and stores its operating history locally, beside the company file. Bookkeeping data and the local journal are not uploaded to Zeno by using the product. If you turn on its live bank connection, bank data reaches your workstation through Zeno's servers and Plaid, as described under Bank and card data above. The software checks a public release endpoint for updates and validates licence keys against our licensing service; those requests carry the licence and machine identifiers, not your ledger.

Security

Each firm's data is held in its own database schema. QuickBooks and Plaid authorisation tokens are held under envelope encryption and are never exposed to a connected AI client. Access to the MCP server uses OAuth 2.1 over HTTPS. Report a suspected vulnerability at zenofirm.com/security. No system is perfectly secure, and we do not claim otherwise.

Your choices

You can access and export your workspace data, correct account information, disconnect any connected company, revoke an AI client's authorisation at any time, and request deletion of your account and its data. Firm administrators control connected client data, subject to their own professional and legal recordkeeping duties; where Zeno processes data on a firm's behalf, we act on that firm's instructions and will refer an end client's request to them.

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to appeal a refusal. Exercise any of these by emailing support@zenofirm.com. We will not discriminate against you for doing so.

International transfers

Zeno is operated from the United States, and all information is processed and stored there. The service is offered to customers in the United States and Canada; if you are in Canada, using Zeno transfers your information to the United States, where it is subject to United States law, including lawful access requests by United States authorities. We do not currently offer the service in the European Economic Area, the United Kingdom, or Switzerland.

Children

Zeno is a business product, is not directed to children, and we do not knowingly collect information from anyone under 18.

Changes

We will update the effective date above when this policy changes, and will give notice in the product for material changes.

Contact

Privacy questions: support@zenofirm.com. Security reports: security@zenofirm.com.

By mail: Zeno Services, LLC, 1040 E 13th St., Brooklyn, NY 11230, United States.

We answer privacy requests within 45 days, and will tell you if we need longer. If you are in Canada and are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada. In the United States, residents of some states may appeal a refusal and may contact their state attorney general.