Automation App · Private internal business tools
Privacy policy
Effective September 10, 2026
Automation App is a private internal application operated by Mark Huetsch for businesses he administers and their authorized collaborators. This policy describes the app’s handling of connected-account information and visits to these public policy pages. The app has no public registration.
Information handled
Information accessed depends on the features enabled and permissions granted by an authorized account holder. It may include:
- Google sign-in information: a stable Google account identifier, verified Kessho email address, and Workspace domain, used to authenticate approved users. Google credentials are verified on the server; Google access and ID tokens are not retained after sign-in. This login does not request access to Gmail, Drive, or other Google business records.
- Company and accounting information: company identity and contact details, accounts, vendors, customers, transactions, payment records, and reports available through the authorized QuickBooks connection.
- Intuit profile information: user identifiers and profile details such as name, email, phone, and address when those permissions are granted and the profile feature is used.
- Connection information: company identifiers, granted permissions, OAuth access and refresh tokens, and token expiration times.
- Operational information: request times, error and diagnostic information, and information you provide when asking for support.
Intuit handles sign-in to Intuit accounts. The app does not collect or store your Intuit password. Sandbox testing uses test-company records; connecting a live company requires separate production setup and authorization.
How information is used
The operator uses information to authenticate approved users, maintain authorized account connections, retrieve and review business records, support internal bookkeeping, tax and compliance preparation, respond to questions, and diagnose or secure the service. Records are not published on these policy pages, sold, or used for advertising.
Access and sharing
Access is limited to the operator, collaborators authorized for the relevant business, and service providers needed to perform the authorized work or operate the service. Google processes sign-in requests and Intuit processes account authorization and API requests under their respective policies. Hosting providers may process technical information needed to deliver and secure the service.
The operator may disclose information when required by law or as necessary to investigate unauthorized access or protect the relevant business and its records. Publishing this policy does not make connected-account data public.
Storage and protection
The app uses encrypted storage for OAuth connection tokens, restricted access to local storage, and HTTPS for communication with Intuit. Tokens are excluded from ordinary application error messages and logs. Authorized users must also protect their devices and accounts. No storage or transmission method can guarantee absolute security.
Retention, disconnecting, and requests
Connection credentials are retained to support the authorized connection. Business records and operational information may be retained while needed for the internal workflow, recordkeeping, security, or applicable legal requirements. There is no automatic deletion solely because a connection token expires.
You may use the app’s authenticated disconnect page, revoke authorization through Intuit, or contact the operator for help disconnecting. The app pauses local access before asking Intuit to revoke the connection and removes saved connection credentials after Intuit confirms. If revocation cannot be confirmed, access stays paused and credentials are retained to support a retry. Revocation does not automatically remove previously retained records or copies in business files.
To request access, correction, or deletion of information, or removal of stored connection credentials, email mark@kessho.com. The operator may verify your identity and authority for the relevant business before acting. Requests are handled subject to applicable rights and any business or legal recordkeeping requirements; if information must be retained, the operator will explain the reason.
Public pages and cookies
These policy pages contain no advertising, analytics scripts, or data-entry forms, and do not set cookies. The web server processes technical request information, including IP address, browser information, requested path, and time, for delivery and security. The authenticated app uses secure cookies for sign-in sessions and request protection.
Updates and contact
Changes will appear on this page with a revised effective date. The operator will notify authorized users before material changes to these data practices take effect.
For privacy questions or requests, contact Mark Huetsch at mark@kessho.com. See also the end-user license agreement.