Privacy Policy
DT Corp Pty Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose personal information when you use Report Craft ("the Service"). We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information We Collect
We collect the following types of information:
- Account information — name, email address, and password (stored as a one-way hash) when you register.
- Firm information — your accounting firm name and any branding assets (e.g. logo) you upload.
- OAuth tokens — access and refresh tokens issued by QuickBooks Online or Xero when you connect a client. We never receive or store your clients' accounting package passwords.
- Financial data — account names, account codes, and period balances fetched from connected accounting packages and cached locally to generate reports.
- Usage data — log data such as IP addresses, browser type, pages visited, and actions taken within the Service, used for security and performance monitoring.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service.
- Generate financial reports on your behalf.
- Authenticate users and maintain account security, including two-factor authentication.
- Send transactional emails (e.g. password resets, account notifications).
- Respond to support requests.
- Comply with legal obligations.
We do not use your clients' financial data for any purpose other than generating reports for you.
3. Disclosure of Information
We do not sell, rent, or trade your personal information. We may disclose information to:
- Service providers — third parties who assist us in operating the Service (e.g. hosting, email delivery), bound by confidentiality obligations.
- Third-party accounting platforms — QuickBooks Online and Xero, to the extent necessary to fetch data on your behalf via OAuth.
- AI providers you have chosen and licensed — where you have switched on AI Analysis by entering your own OpenAI or Anthropic API key, report figures are sent to that provider under your own account. See section 13.
- Law enforcement or regulators — where required by law or to protect the rights, property, or safety of DT Corp Pty Ltd, our users, or others.
4. Data Storage and Security
Your data is stored on servers located in Australia. We use industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews to protect your information from unauthorised access, disclosure, alteration, or destruction.
Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security.
5. Data Retention
We retain your account and financial data for as long as your account is active or as needed to provide the Service. If you close your account, we permanently delete your firm, its client ledgers, its reports and its user logins from the Service at midnight (Melbourne time) on the day you close it. Copies held in our encrypted backups age out within 90 days. We retain information beyond this only where we are required to for legal or compliance purposes.
6. Your Rights
Under the Australian Privacy Principles you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or out-of-date information.
- Request deletion of your personal information, subject to legal obligations.
- Complain about a breach of the APPs.
To exercise any of these rights, contact us at support@reportcraft.com.au.
7. Cookies
The Service uses session cookies necessary for authentication and secure operation. We do not use third-party tracking or advertising cookies.
8. Third-Party Links
The Service may contain links to third-party websites (e.g. QuickBooks, Xero). We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
9. Children's Privacy
The Service is intended for use by accounting professionals and is not directed at children under 18. We do not knowingly collect personal information from children.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via the Service. The effective date at the top of this page will be updated accordingly.
11. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us first at support@reportcraft.com.au. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
12. Connected Accounting Platforms (QuickBooks Online & Xero)
When you connect a client's accounting package, Report Craft acts on your behalf to read financial data needed to generate reports. This section explains how we handle data accessed through Intuit QuickBooks Online and Xero.
- What we access — via OAuth 2.0 we read the chart of accounts (account names, codes, types and classifications) and period balances (including debits, credits and totals) for the connected entity. We request only the read scopes required to build reports.
- What we never receive — we never receive or store your or your clients' QuickBooks Online or Xero login credentials. Authorisation is handled entirely by the platform through OAuth, and we hold only the access and refresh tokens issued to us.
- How it is stored — fetched financial data and OAuth tokens are cached on our servers in Australia, encrypted in transit (TLS) and at rest, and are accessible only to your authorised firm users and to the operations required to run the Service.
- How we use it — connected-platform data is used solely to generate the financial reports you request. We do not use it for advertising, we do not sell or rent it, and we do not share it with third parties except the service providers strictly necessary to operate the Service and, if you have switched on AI Analysis, the AI provider you have chosen and licensed (see section 13).
- Refresh and revocation — you may disconnect a client at any time, and you or your client may revoke Report Craft's access from within QuickBooks Online or Xero. Once access is revoked we can no longer fetch new data for that entity.
- Deletion — when you disconnect a client, its cached financial data is deleted and its OAuth grant is revoked straight away. When you close your account, the same happens for every connected client at midnight (Melbourne time) that day. Copies held in our encrypted backups age out within 90 days, and we retain records beyond this only where we are required to for legal or compliance purposes.
Our use of information received from Intuit APIs adheres to the Intuit Developer platform requirements, and our use of information received from Xero APIs adheres to the Xero Developer platform requirements.
13. AI Analysis (OpenAI & Anthropic)
Report Craft offers an optional AI Analysis feature that produces a written commentary on a client's figures. It is off unless you turn it on, and it runs on your own AI account, not ours — the request goes to your OpenAI or Anthropic account, and the commentary it returns is generated in that account, over a secure (encrypted, HTTPS) connection. Report Craft holds no AI provider account of its own, and nothing in this feature passes through one.
- You bring your own key — AI Analysis does nothing until an administrator of your firm enters an API key for their own licensed OpenAI or Anthropic account in Firm Settings. We do not provide, resell, or subsidise access to either provider, and firms that never enter a key never send anything to them.
- Your agreement, your controls — because the request is made with your key, it is governed by your own agreement with OpenAI or Anthropic. Whatever data-handling, retention and training terms you have negotiated or accepted with that provider are the terms that apply, which keeps the decision — and the privacy posture — in your hands rather than ours.
- What is sent, and how — when you generate an AI Analysis for a client, the account balances and totals for that client's reporting period are sent — over a secure, encrypted (HTTPS) connection, to your own provider account — so it can write the commentary. We send only what the commentary needs. We do not send your login credentials, your OAuth tokens, or any other client's data.
- Which providers and models — OpenAI (GPT models) and Anthropic (Claude models). You choose which provider to use, and may set a preferred one; if both keys are present and your preferred provider is unavailable, the request falls back to the other.
- Your key — API keys you enter are encrypted at rest and are used only to make AI Analysis requests on your instruction. They are never shown back to other firms and are never used for any other purpose.
- Switching it off — remove the API key from Firm Settings and the feature stops immediately. No further data is sent to any AI provider.
Generated commentary is a drafting aid, not financial advice, and should be reviewed by a qualified accountant before it is relied on or given to a client.
14. Contact
Privacy enquiries can be directed to:
DT Corp Pty Ltd
support@reportcraft.com.au