Privacy Policy
Effective August 14, 2026
JhaX (“JhaX”, “we”, “us”) is an AI operations assistant for restaurants and small businesses. This Privacy Policy explains what information we collect, how we use it, who we share it with, and how long we keep it. It applies to the JhaX web application and any data you connect to it, including your QuickBooks Online account.
By using JhaX or connecting a third-party service to it, you agree to the practices described here.
1. Information we collect
Account information
When you create an account we collect your name, email address, and/or phone number through our authentication provider (Google Firebase), and a hashed PIN if you set one. We never store your PIN or third-party passwords in plain text.
Business data you connect
JhaX reads business data from the services you choose to connect — for example a point-of-sale system (Square, Clover, Shift4 and others) and your accounting system (QuickBooks Online). This can include menu items, orders and sales, customers, employees and shifts, reviews, and — where you connect it — email that you explicitly authorize for task triage.
Documents you upload
If you use the finance document inbox, we store the bills, receipts and invoices you upload (including the original file or photo) so JhaX can extract their fields, check for duplicates, and — on your confirmation — record them in QuickBooks.
Usage information
We collect basic technical and usage information (such as log data and feature usage) to operate and secure the service.
2. QuickBooks Online (Intuit) data
When you connect QuickBooks, you authorize JhaX through Intuit’s official OAuth 2.0 flow. We request a single scope — com.intuit.quickbooks.accounting — and nothing more. We never receive your Intuit username or password; Intuit handles your sign-in and returns only an access token to JhaX.
What we read, and why
To show your finance dashboard and answer questions about your books, JhaX reads:
- Company information — your business name, address and currency, to label your workspace.
- Customers and Vendors — to populate reference lists and reporting.
- Chart of Accounts and Items — to categorize records and compute balances.
- Bills — to calculate accounts payable and what needs attention.
- Invoices — for receivables and revenue context.
- Financial reports — Profit & Loss, Balance Sheet and Cash Flow — to produce the KPI summary and AI explanations.
What we write, and only when you confirm
JhaX can create records in your QuickBooks company, but only when you explicitly confirm the action (for example, syncing an uploaded bill). Specifically, JhaX may create: Bills, Vendors, Customers, and Invoices. JhaX does not delete your QuickBooks records and does not make changes in the background without your action.
What we do not access
Because we request only the accounting scope, JhaX cannot access QuickBooks Payroll, employee Social Security numbers, bank login credentials, or any Intuit product outside QuickBooks Online accounting.
3. How we use your information
- To provide the service — dashboards, reports, finance summaries and assistant answers.
- To extract and classify documents you upload and, on your confirmation, sync them to QuickBooks.
- To operate, secure, debug and improve the product.
- To communicate with you about your account or the service.
We do not sell your data, and we do not use it for third-party advertising.
4. AI processing
JhaX uses AI models to summarize your data, answer questions, and read fields from documents you upload. To do this, relevant content (such as a receipt image or a computed data summary) is sent to our AI providers (including Google and Groq) solely to generate a response for you. We do not permit this content to be used to train their models. AI output is generated automatically and may contain errors — see our Terms of Service.
5. How we store and protect data
- Your QuickBooks OAuth tokens are stored securely in Google Firebase and are refreshed automatically; they are used only to make the accounting calls described above.
- Application data (such as connected business records and uploaded documents) is stored in our managed PostgreSQL database.
- All data is transmitted over encrypted connections (TLS/HTTPS).
- Access to production data is limited to what is required to operate the service.
6. Who we share data with
We share data only with the service providers that make JhaX work, and only as needed:
- Intuit — to read from and write to your QuickBooks company at your direction.
- Google Firebase — authentication and secure token storage.
- Our database host — managed PostgreSQL for application data.
- AI providers (Google, Groq) — to generate responses and read documents, as described above.
- The POS/other services you connect — to read the business data you authorize.
We may also disclose information if required by law or to protect the rights and safety of users.
7. Data retention and deletion
We keep your data for as long as your account is active or as needed to provide the service.
- Disconnecting QuickBooks: you can disconnect at any time from the JhaX Connectors page, or by removing JhaX from your Intuit account connections. Disconnecting stops all further access; we then delete the stored QuickBooks access and refresh tokens so JhaX can no longer reach your books.
- Deleting your data: you can request deletion of your account and associated data — including cached QuickBooks data and uploaded documents — by emailing jhapayapp@gmail.com. We will action verified requests within 30 days, except where we are required to retain certain records by law.
Note: records already written to your QuickBooks company at your direction live in QuickBooks and are managed there, not by JhaX.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to withdraw consent. To exercise any of these, contact us at jhapayapp@gmail.com.
9. Children
JhaX is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Effective” date above and, for material changes, provide additional notice.
11. Contact us
Questions about this policy or your data? Reach us at jhapayapp@gmail.com.