Privacy Policy

Effective 2 October 2026

1. Who we are

Folklabs, Inc. (“Folklabs”, “we”) provides the Folklabs service at folklabs.ai and in the Folklabs app. This policy explains what information we handle, why, and your choices. It applies together with our Terms of Service.

2. What we collect

  • Account information: names, email addresses and roles of the people in your business account, and your business’s details.
  • Content you provide: agent instructions, goals, documents you upload or forward (such as vendor bills), and messages to support.
  • Connected service data: data agents read from services you connect, such as QuickBooks (see §4), and the credentials needed to stay connected.
  • Agent outputs and run history: results, reports and transcripts of agent runs, which can include data from connected services.
  • Technical data: logs, device and browser information, and usage data used to run and secure the Service.

3. How we use it

We use information only to provide, secure, support and improve the Service, to communicate with you about it, and to meet legal obligations. We do not sell your information, use it for advertising, or use your business’s data to train AI models.

4. QuickBooks data

When you connect QuickBooks Online, you sign in with Intuit and approve access; we never see your Intuit password. We request Intuit’s accounting permission only, not payments, payroll or profile access.

What agents access. Agents read accounting records such as invoices, estimates, vendors, bills and expense accounts. Accounts-payable agents you set up can also create vendors, bills and bill attachments. We do not delete QuickBooks records.

What we store and where it goes:

WhereWhatWhy
Folklabs database (Supabase)Access credentials and your QuickBooks company ID, encrypted with a separate keyTo stay connected
Folklabs database (Supabase)Agent outputs and run transcripts, which can include figures and records from QuickBooksSo you can see results and history
Anthropic (AI model provider)QuickBooks data an agent reads during a run. Never your access credentialsSo the AI model can do the work
Vercel (hosting, US)Every request agents make to QuickBooks, using your access credentialsTo run the Service
Folklabs server logs (Vercel)The type and result of each QuickBooks request and Intuit’s request ID, not the request contentsTo troubleshoot with Intuit support

Anthropic’s commercial terms do not permit it to train AI models on this data. We do not share QuickBooks data with anyone else except as required by law.

5. Who we share information with

We share information only with service providers that help us run the Service, under agreements that limit their use to providing services to us: Supabase (database), Vercel (hosting, US), Anthropic (AI models), and Google (email). We may also disclose information if required by law, to protect rights and safety, or as part of a merger or acquisition, subject to this policy.

6. Security

We encrypt data in transit and at rest. Connected-service credentials are additionally encrypted with a separate key. They are never displayed in the Service, and only the engineers who operate the Service can access the key that decrypts them. Database access rules restrict each business’s data to its own members. If a breach affects your information, we will notify you as the law requires.

7. Who can see your data

  • Your business: members of your Folklabs business account can see its connections, agent outputs and history.
  • Folklabs staff: a limited number of staff can view business accounts and agent results, which may include QuickBooks figures, to set up agents and provide support. Credentials are never displayed to staff in the Service, and only the engineers who operate the Service can access the key that decrypts them.

8. Retention, disconnection and deletion

8.1 While your account is active we keep your account information, agent outputs and run history so you can use the Service.

8.2 Disconnecting QuickBooks. You can disconnect from the Connectors page in Folklabs or from within QuickBooks. If you disconnect in Folklabs, we delete the stored credentials and company ID immediately. If you disconnect from within QuickBooks, Intuit cuts off our access at once, and we delete the stored credentials and company ID as soon as we detect the disconnection: right away if QuickBooks returns you to Folklabs while you are signed in, and otherwise at our next scheduled check, normally within an hour.

8.3 Revoked access. If access is revoked from the QuickBooks side, or Intuit stops accepting our credentials, the credentials stop working at once. We mark the connection as needing reconnection, tell you, and delete the stored credentials as soon as we detect it, normally within an hour and in any case within 24 hours.

8.4 Agent outputs. Outputs and transcripts that contain QuickBooks figures stay in your history after you disconnect, so you keep your reports. We delete them on request, and when your account closes, within 30 days.

8.5 Closing your account. Email help@folklabs.ai to close your account and have your data deleted. We delete it within 30 days, except where the law requires us to keep something. Backups are overwritten on their normal cycle.

9. Your rights

You can ask to access, correct, export or delete your information by emailing help@folklabs.ai. Depending on where you are, you may have further rights under local law; we will honor them as that law requires.

10. Changes to this policy

This policy is effective as of 2 October 2026. We will post updates here with a new effective date and, for material changes, notify account owners in advance.

11. Contact

Folklabs, Inc., 3455 W 34th Ave, Denver, CO 80211. Privacy questions: help@folklabs.ai.