Privacy Policy
Last updated: July 28, 2026
Information We Collect
AskWingo collects and processes information from your connected business systems to provide our data operationalization service. This includes:
QuickBooks Online data: Customer records, vendor records, invoices, items, and transaction data accessed via the QuickBooks Online API using the com.intuit.quickbooks.accounting OAuth scope. We access this data in read-only mode for analysis and knowledge graph construction.
Google Drive documents: Files you authorize us to access via the Google Drive API, read-only (drive.readonly scope). We crawl, classify, and cite your documents; we never create, modify, or delete files in your Drive. See the Google User Data section below.
Gmail data: Messages and attachments you authorize us to access via the Gmail API, read-only (gmail.readonly scope). We ingest business correspondence and cite source messages; we never send, modify, label, or delete mail. See the Google User Data section below.
Account information: Email address, name, and organization name provided during registration.
Usage data: Query logs, feature usage patterns, and performance metrics to improve the service.
How We Store Your Data
All data is stored in a Google Cloud Platform (GCP) environment in the us-central1 region.
Data at rest is encrypted using GCP's default encryption (AES-256).
OAuth credentials (access tokens, refresh tokens) are encrypted using Fernet symmetric encryption before storage in our database.
API keys and secrets are stored in GCP Secret Manager, never in code or environment variables in production.
How We Use Your Data
Knowledge graph construction: We connect entities (vendors, customers, documents, transactions) across your data sources to build a unified knowledge graph.
Natural language query answering: When you ask a question, we query relevant data and generate answers with source citations.
Business rule evaluation: We evaluate your data against rules you define to surface violations and recommendations.
We do not use your data to train machine learning models. We do not sell or share your data with third parties.
Data Retention and Deletion
Your data is retained for as long as your account is active and connected.
When you disconnect a data source (e.g., QuickBooks), we immediately revoke and delete the stored OAuth tokens. Extracted data from that source is marked for deletion and purged within 30 days.
When you close your account, all data associated with your organization is deleted within 30 days.
You may request immediate data deletion by contacting us.
Google User Data
Gmail. With your authorization, AskWingo accesses your Gmail messages and attachments via the Gmail API using the gmail.readonly scope. Access is strictly read-only: we ingest business correspondence to link it to the vendors, customers, and transactions it concerns, and answers cite the source message. We never send, modify, label, or delete mail.
Google Drive. With your authorization, AskWingo accesses your Drive files via the Google Drive API using the drive.readonly scope. Access is strictly read-only: our crawler discovers, classifies, and links your business documents to the entities they concern, and answers cite the source file. We never create, modify, or delete files in your Drive.
AskWingo’s use of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Google user data is used only to provide the features described above for your organization. It is not used for advertising, is not sold, is not shared with third parties, and is not used to train generalized AI or machine-learning models.
Storage. Google user data is stored in our Google Cloud Platform environment (us-central1), encrypted at rest (AES-256). OAuth tokens are encrypted with Fernet symmetric encryption before storage.
Retention and deletion. When you disconnect Google from the AskWingo Setup page, we immediately revoke and delete the stored OAuth tokens, and ingested Google data is marked for deletion and purged within 30 days. You may also revoke AskWingo’s access at any time from your Google Account security settings (myaccount.google.com/permissions), or request immediate deletion by contacting support@askwingo.com.
QuickBooks-Specific Disclosures
We access QuickBooks Online data via Intuit's OAuth 2.0 API with the com.intuit.quickbooks.accounting scope.
We store only the data necessary for knowledge graph construction and query answering.
Access tokens are refreshed automatically and stored encrypted. Refresh tokens are rotated per Intuit's token policy.
Users can disconnect QuickBooks at any time from the AskWingo Setup page or from the QuickBooks Apps management page. Both paths result in immediate token revocation and credential deletion.
Security
All data transmission uses TLS 1.2+.
Access to customer data is restricted to authenticated, authorized users within the customer's organization.
We implement tenant isolation at the database level — each organization's data is logically separated using tenant-scoped queries.
We conduct regular security reviews of our codebase and infrastructure.
Your Rights
Access: You can view all data we hold about your organization through the AskWingo application.
Deletion: You can delete your data by disconnecting sources or closing your account.
Portability: Contact us to request an export of your data.
Contact
For privacy-related questions, contact: support@askwingo.com