Who is responsible for your information
The service is operated by Zeno Services, LLC, and this policy describes what it does with your information. Where you use Zeno to keep your own books, Zeno Services, LLC is the controller of that information. Where you use Zeno to work on books belonging to your clients, your firm is the controller and Zeno is a processor acting on your firm's instructions; a data processing addendum is available on request.
Zeno Services, LLC also operates zenorent.com, a separate cloud ERP service. Zeno and Zenorent are two products of the same company, and some company infrastructure is shared between them. Desktop download, order, and licence records are currently held in storage named for the older service. Nothing in that arrangement discloses your information to another company.
Zeno Services, LLC
Brooklyn, New York, United States
Privacy: support@zenofirm.com
Security: security@zenofirm.com
The short version
Zeno processes the account information needed to run your workspace and the bookkeeping information you choose to connect. We do not sell it, we do not use it for advertising, and we do not train AI models on it. We share it only with the providers listed below, only to operate the service.
What we collect
Account and billing information
Name, email address, firm or company name, authentication credentials in hashed form, plan and subscription status, and the licence and order references for Desktop purchases. Card details are entered directly with our payment processor and are never received or stored by Zeno.
Connected bookkeeping data
When you authorise a QuickBooks connection, Zeno reads and stores working copies of ledger data for the companies you connect. This includes charts of accounts, names, items, transactions, attachments, reports, and related records. These copies allow work to be prepared and checked without querying the platform on every request. New entries and changes to names reach that ledger through a batch a person reviews and approves. A small set of other changes happen only when you ask for them: correcting, voiding or deleting an existing transaction, attaching a document, sending an invoice, setting up a recurring reminder, and company settings such as currencies, tax codes and company details. The ones that remove or send something ask you to confirm first, and every one of them is recorded in the work history. Zeno never sets up a transaction that posts by itself and never moves money.
Bank and card data
When you connect a bank or card account, Zeno uses Plaid Inc. ("Plaid") to reach it. You sign in to your bank on Plaid's own page; Zeno never sees or stores your bank username or password. With your consent, Zeno receives from Plaid the names, types and last four digits of the accounts you connect, their balances, and their transaction history: date, amount, description, merchant, and the cardholder name where the bank provides one. If you turn on statements for a connection, Zeno also receives the bank's monthly statement for each account it stages, as a PDF in your document inbox. Zeno uses this only to prepare bookkeeping entries for your review, and keeps the authorisation Plaid issues for the connection encrypted. You can disconnect a bank at any time, which removes the connection at Plaid and stops all further collection.
Firm memory you create
Coding rules, client knowledge entries, playbooks, reviewer decisions, and the work log. This is content you author or confirm.
Documents you send
Files uploaded to, or emailed into, the document inbox, and the data extracted from them.
AI interaction data
When an AI client connects to the Zeno MCP server, usage records include the tool name, the names of supplied arguments (not their values), the company when specified, timing, and success or failure. Separately, the bookkeeping journal retains the plans, decisions, and posting results needed to explain work performed. We do not receive or store the rest of your conversation with the AI client, and we do not request it.
Operational and security logs
IP address, timestamps, user agent, and request metadata needed to secure, debug, and support the service.
Website analytics
zenofirm.com uses Google Analytics to measure aggregate traffic. The marketing site does not require an account.
What we deliberately do not collect
Zeno does not collect payment card numbers, protected health information, government-issued identification numbers such as Social Security, tax identification or employer identification numbers, or the credentials you use with third-party services other than the authorisation tokens described below. Zeno's tools refuse a tax id, Social Security number or birth date rather than accept one, in the cloud workspace and in Zeno for QuickBooks Desktop from version 1.14.0; you enter those in QuickBooks directly. In the cloud, if QuickBooks Online returns a tax id when Zeno reads your lists, Zeno keeps only its last four digits; the Desktop edition reports only whether a vendor has one on file. Do not send these to support or into the document inbox. Zeno collects only what a tool needs to do its job; it does not gather conversation content beyond the tool calls themselves.
Why we process it
To provide and secure the service; to connect to the accounting platforms you authorise; to prepare, check, approve, apply, and reverse bookkeeping work you request; to keep the durable audit trail that is a core feature; to bill you; to answer support requests; to detect abuse; and to meet legal obligations.
Zeno is offered to customers in the United States and Canada. If you are in Canada, we rely on your express consent where we ask for it and implied consent where the purpose is obvious from how you use the service, together with the exceptions PIPEDA provides for business contact information and records we are required to keep. You may withdraw consent, subject to legal and contractual limits, by emailing us.
AI models and training
Zeno does not operate a foundation model and does not train one. We do not use your data, your clients' data, or your firm memory to train any AI model, and we do not permit our providers to do so on our behalf.
Zeno is designed so that you bring your own AI client. When you connect one, that client and its provider process your requests and Zeno's responses under the provider's terms and privacy policy, not ours. You decide which provider to trust with that traffic. We list the common providers below to help you make an informed choice.
Who we share it with
We share information with the following categories of recipient, only as needed to operate the service. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- Accounting platforms you authorise. Intuit, for QuickBooks Online and QuickBooks Desktop connections. See the Intuit privacy statement.
- The AI provider you choose to connect. Common providers are Anthropic (see its privacy policy) and OpenAI (see its privacy policy). Zeno does not send data to an AI provider on its own initiative; data reaches a provider because you connected that client and made a request through it.
- Plaid, to connect your bank and card accounts. Zeno uses Plaid Inc. ("Plaid") to gather your data from financial institutions. By connecting an account, you grant Zeno and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution, and you agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy.
- Infrastructure and hosting providers that run the application, database, and website.
- Email delivery and inbound document processing providers.
- Our payment processor, Helcim, for subscriptions and Desktop licence purchases. See the Helcim privacy policy. Card details are entered directly with Helcim and are never received or stored by Zeno.
- Analytics for the marketing website. See the Google privacy policy. You can opt out with the Google Analytics opt-out add-on.
- Legal and safety recipients, where we are required by law or must protect our rights, users, or the public.
- A successor, if Zeno is involved in a merger, acquisition, or sale of assets, subject to this policy.
How long we keep it
- Account records: for the life of the account, then up to 12 months after closure, unless a longer period is required for tax, accounting, or legal purposes.
- Connected bookkeeping data and firm memory: until you remove the company or delete the workspace. Disconnecting stops the sync and revokes our access, and keeps Zeno's working copies so that reconnecting resumes where it left off; Remove, offered once a company is disconnected, deletes those copies. Neither alters anything in QuickBooks.
- Work log, plans, verdicts, and runs: retained for the life of the workspace because they must remain available for later review. Deleting the workspace deletes them.
- Bank and card data: kept with the company's books while you serve that company, because the lines are the evidence behind what was posted. Disconnecting a bank removes the connection at Plaid and deletes Zeno's stored authorisation; the lines already received stay. Removing a company deletes its bank lines, accounts and connection records 90 days later, unless the company is added back before then. In Zeno for QuickBooks Desktop, transactions pass through Zeno's servers only until your workstation confirms it has them, and are then deleted. A Desktop bank connection is removed at Plaid and its data deleted when its Zeno account is closed, or when none of its workstations has been seen for 180 days.
- Inbox documents: until you resolve or delete them, or the workspace is deleted.
- Operational and security logs: no longer than 12 months.
- Backups: deleted data can persist in encrypted backups for a limited period before being overwritten on the normal rotation.
Zeno for QuickBooks Desktop
The Desktop product runs on your workstation and stores its operating history locally, beside the company file. Bookkeeping data and the local journal are not uploaded to Zeno by using the product. If you turn on its live bank connection, bank data reaches your workstation through Zeno's servers and Plaid, as described under Bank and card data above. The software checks a public release endpoint for updates and validates licence keys against our licensing service; those requests carry the licence and machine identifiers, not your ledger.
Security
Each firm's data is held in its own database schema. QuickBooks and Plaid authorisation tokens are held under envelope encryption and are never exposed to a connected AI client. Access to the MCP server uses OAuth 2.1 over HTTPS. Report a suspected vulnerability at zenofirm.com/security. No system is perfectly secure, and we do not claim otherwise.
Your choices
You can access and export your workspace data, correct account information, disconnect any connected company, revoke an AI client's authorisation at any time, and request deletion of your account and its data. Firm administrators control connected client data, subject to their own professional and legal recordkeeping duties; where Zeno processes data on a firm's behalf, we act on that firm's instructions and will refer an end client's request to them.
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to appeal a refusal. Exercise any of these by emailing support@zenofirm.com. We will not discriminate against you for doing so.
International transfers
Zeno is operated from the United States, and all information is processed and stored there. The service is offered to customers in the United States and Canada; if you are in Canada, using Zeno transfers your information to the United States, where it is subject to United States law, including lawful access requests by United States authorities. We do not currently offer the service in the European Economic Area, the United Kingdom, or Switzerland.
Children
Zeno is a business product, is not directed to children, and we do not knowingly collect information from anyone under 18.
Changes
We will update the effective date above when this policy changes, and will give notice in the product for material changes.
Contact
Privacy questions: support@zenofirm.com. Security reports: security@zenofirm.com.
By mail: Zeno Services, LLC, 1040 E 13th St., Brooklyn, NY 11230, United States.
We answer privacy requests within 45 days, and will tell you if we need longer. If you are in Canada and are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada. In the United States, residents of some states may appeal a refusal and may contact their state attorney general.