WolfStrata

Privacy Policy

Effective 2026.07.20

WolfStrata (“WolfStrata,” “we,” “us”) provides an automated financial-analysis service that reads your accounting data, computes deterministic signals, and generates plain-language narratives. This policy explains what data we handle and how. It applies to the WolfLedger application provided by WolfStrata.

Our principles: we do not sell your data, we do not serve advertising, we do not use your data to train AI models, and we collect the minimum needed to run the service.

Eligibility. The Service is available only to businesses located in Canada (excluding the Province of Quebec) and the United States. It is not available in, or directed to, the Province of Quebec; persons located in or resident in Quebec must not create an account or use the Service. See the Terms (EULA) for full eligibility and territory terms.

1. Information we collect

  • Account information. Your email address and a securely hashed password used to sign in, plus your business name.
  • QuickBooks Online (QBO) data.With your explicit authorization, we retrieve financial data from your connected QuickBooks company — statements (Profit & Loss, Balance Sheet, Cash Flow), invoices, bills, payments, customer and vendor records, and receivables/payables aging — for the periods you analyze. We store the OAuth access and refresh tokens needed to maintain that connection, in encrypted form.
  • Payment information. Payments are processed by Stripe. We store your Stripe customer ID and subscription status; we never store credit card numbers, bank account details, or other payment instrument data on our servers.
  • Documents you upload. Files you upload (such as budget spreadsheets) are stored privately and encrypted.
  • Your own AI keys (optional).If you supply your own API key for an AI provider (“bring your own key”), we store it in encrypted form to make requests on your behalf.
  • Usage and operational data. We collect information about feature usage and application performance (including IP address and browser type in server logs) to keep the service secure and reliable. Operational traces sent to our monitoring provider have sensitive values (such as auth tokens) redacted before they leave the application.

2. How we use your data

We use your data solely to operate the service: to authenticate you, to retrieve and analyze your QuickBooks financials, to generate narratives and signal results, to process payments, to send transactional email (password resets, account and billing notices), and to keep the platform secure and reliable. We do not sell or rent your data, we do not share it with data brokers or advertisers, and we do not use it for advertising or profiling.

3. AI processing — and what we never do with your data

To generate the written narrative that accompanies your analysis, we send a prompt to an AI provider. That prompt contains period-level aggregate figures (such as revenue, gross profit, net income, ending cash, total assets, total liabilities, and equity) and short signal summaries. It does not include individual transactions, customer names, vendor names, or line-item ledger detail.

By default we use Anthropic (Claude). If you configure your own key, your requests go to your chosen provider (Anthropic, OpenAI, or Google) under your account with that provider.

We do not use your data or content to train, fine-tune, or improve any AI or machine-learning models — ours, our AI providers’, or any third party’s. Your data is processed through AI services solely to generate outputs for your use, under provider terms that do not permit training on API inputs. Your data is yours.

4. Service providers (subprocessors)

We share data with third parties only as necessary to provide the service:

  • Intuit / QuickBooks Online — source of the financial data you connect.
  • Anthropic, OpenAI, or Google — AI narrative generation (per the section above).
  • Stripe — payment processing.
  • Vercel — application hosting and encrypted document storage.
  • Neon — managed PostgreSQL database hosting (United States region).
  • Resend — transactional email (password resets, invites, billing notices).
  • Honeycomb — operational telemetry and monitoring (redacted traces).

We do not share, sell, or provide your personal information or financial data to any third party not listed above except as required by law.

5. How we store and protect your data

Data is stored in a PostgreSQL database hosted by Neon in the United States and transmitted over HTTPS/TLS. Sensitive credentials — QuickBooks access and refresh tokens, AI keys you provide, and multi-factor authentication secrets — are application-encrypted at rest using AES-256-GCM envelope encryption: a per-tenant data key is itself wrapped by a master key held only in our hosting environment’s protected configuration. Uploaded documents are stored privately and envelope-encrypted with the same scheme.

Customer financial data (your QuickBooks snapshots and the derived analyses) is not additionally encrypted at the application layer; it sits on encrypted storage with access protected by the controls below. We chose this trade-off deliberately so the signal-analysis pipeline remains debuggable; we do not claim “end-to-end encrypted” or that the operator cannot read your data.

The access controls in place:

  • Multi-tenant isolation enforced by the database.Postgres row-level security restricts every query to the authenticated tenant — even an application bug that omits a tenant filter cannot return another tenant’s rows.
  • Two-factor authentication for every account, and sensitive actions (connecting/disconnecting accounting systems, changing keys or passwords) require password re-verification within a short window.
  • Tamper-evident audit log. Security-significant events are recorded in an append-only, hash-chained audit log. Modification or deletion of audit entries is rejected at the database level.
  • Backups.Database backups use our database provider’s encrypted point-in-time snapshots, pruned on a fixed retention schedule; exported backups are additionally encrypted before storage.

No method of transmission or storage is completely secure; we cannot guarantee absolute security, and our responsibility for security incidents is limited as described in the Terms of Service.

6. Data retention and deletion

We retain your account data and connected financial data for as long as your account is active. If you ask us to delete your account, we delete your data — including QuickBooks snapshots, derived analyses, uploaded documents, encrypted tokens and keys, and account information — within thirty (30) days, except where retention is required by law (for example, billing records). Backups age out on their fixed retention schedule. Anonymized, aggregated statistics that cannot be linked back to you may be retained.

7. Disconnecting QuickBooks

You can disconnect your QuickBooks company at any time, either from within the application or from your Intuit account’s connected-apps settings. When you disconnect, we stop syncing and delete the stored QuickBooks tokens. Previously computed analyses may be retained unless you also request their deletion.

8. Your choices and rights

You may request access to, correction of, export of, or deletion of your personal data, and you may withdraw your QuickBooks authorization at any time. To make a request, contact us at support@wolfstrata.com. We respond to data-rights requests within 30 days. If you are located in a jurisdiction with data protection laws (such as PIPEDA, the GDPR, or the UK GDPR), you may have additional rights under those laws, and nothing in this policy limits them.

9. Cookies

We use essential cookies for authentication and session management (including your active workspace). We do not use third-party advertising cookies or cross-site tracking.

10. Children's privacy

WolfLedger is a business tool intended for use by adults. It is not directed to children and we do not knowingly collect data from anyone under 18. If we learn we have collected personal information from a child, we will delete it promptly.

11. Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected by an updated effective date at the top of this page, and where reasonably practicable we will notify you by email or in-app notice.

12. Contact

Questions about this policy or your data? Contact us at support@wolfstrata.com. This policy is governed by the laws of Manitoba, Canada.