Principle 01
Data handling
Analytir reads your data through read-only access and stores only what it needs to produce your reports.
Connections use read-only OAuth scopes — Analytir cannot create, modify, or delete records in any connected platform. Data is fetched on the schedule the operator configures and used to produce the reports and answers the operator has requested. The connected platforms remain the system of record — Analytir can read, never write.
OAuth tokens are stored encrypted at rest. Connections can be revoked at any time from the Analytir dashboard or from the connected platform's own access controls.
Read-only access. Your data, used only to produce your reports.
Principle 02
What Analytir can and cannot do
Analytir connects to your Square and QuickBooks accounts using read-only OAuth. That means Analytir has permission to read your transactions, payouts, refunds, and account metadata — and nothing else.
What Analytir cannot do:
- Move money in or out of your accounts
- Issue refunds or process transactions
- Modify or delete any records inside Square or QuickBooks
- Change your bank account, payout schedule, or business settings
- Access other Square or QuickBooks apps you have connected
You can revoke Analytir's access anytime from your Square or QuickBooks dashboard, and access ends immediately.
Principle 03
Encryption
All data moving between Analytir, Square, QuickBooks, and your browser is encrypted in transit using TLS 1.2 or higher — the same standard your bank uses.
Your OAuth tokens (the credentials that let Analytir read your data) are encrypted at rest before they touch our database. Even if someone somehow gained access to the raw database files, the tokens are unreadable without the encryption keys, which are stored separately.
Your transaction data is stored in Supabase, which encrypts every row at rest by default. Backups are encrypted. Nothing touches disk in plaintext.
Principle 04
What Analytir stores
To deliver scheduled reports, Analytir stores:
- Account identifiers and configuration (which connections, which report types, which schedule)
- The text of generated reports, retained for the operator's history
- Transaction data from your connected accounts (sales, payouts, and the figures derived from them), used to produce your reports and answer your questions
- Standard authentication and billing records
Analytir does not store card numbers, payment credentials, or any data not required to produce the reports the operator has requested. Your data is never sold or shared, and you can delete it at any time.
Principle 05
AI usage
AI is used inside Analytir for one job: converting structured numerical output into the plain-language sentences that appear in reports.
AI is not used to make decisions about the business, generate recommendations the underlying engineering didn't already detect, or speculate about causes. The engineering layer determines what's worth saying. The language layer determines how to say it.
No customer data is used to train models. Model providers used by Analytir are bound by data processing agreements that prohibit training on customer inputs.
Principle 06
AI and your data
Analytir uses AI to help write your brief and to power the AI Analyst that answers questions about your data. Here's how that works — and doesn't work.
Your data is never used to train AI models. Not by Analytir, not by any AI provider Analytir uses. Your numbers stay yours.
When the AI Analyst answers a question, it queries a scoped view of your data through a validator that only allows safe, read-only queries. Every question and answer is logged so there's a record of exactly what was asked and what was seen.
The AI never sees your bank account numbers, customer contact information, or anything outside the scope of what Analytir needs to write your brief.
Principle 07
What happens when you disconnect
When you disconnect Analytir from Square or QuickBooks, we immediately stop syncing new data and mark the integration as disconnected.
The historical data Analytir already synced stays in your account so you can continue viewing past reports. If you want that data deleted too, email support@analytir.com and it's gone within 7 days.
If you delete your Analytir account entirely, everything — historical data, reports, alerts, past briefs — is deleted within 30 days, permanently.
Principle 08
Reliability
Analytir reports run on scheduled jobs. The scheduler is monitored. When a job fails, the operator is notified — Analytir does not silently skip a delivery and hope no one notices.
Real-time claims are reserved for features that operate in real time. Scheduled features are described as scheduled. The documentation reflects what the software does, not what it would be nice if it did.
Principle 09
Editorial standards
Every report Analytir ships is subject to one test: would an operator read it in the morning and act on it?
If a feature produces output that would be skipped, ignored, or saved-for-later by a working operator, the feature isn't shipped. Analytir does not pad reports with charts, vanity metrics, or AI-generated commentary for the sake of appearing thorough. Reports are short because operators are busy.
Principle 10
What Analytir is not
Analytir is not a dashboard product. Operators who want a dashboard get one — the email is the product, the dashboard is the reference.
Analytir is not an AI product. AI handles the last mile of language generation. The remainder is conventional software engineering, deliberately so.
Analytir is not a bookkeeping product, a tax product, an accounting platform, or a replacement for any of the platforms it reads from. Analytir produces operating reports for people who already have those systems in place.
Principle 11
In case of a security incident
Analytir is built by a small team, so honesty here is easier than at bigger companies: if something goes wrong, you'll hear about it directly.
In the event of a security incident that affects your data, we commit to notifying you within 72 hours of discovery, telling you what happened, what data was affected, what we're doing about it, and what you should do.
If you spot something that looks like a vulnerability, email security@analytir.com and we'll respond within one business day.
Principle 12
Contact
Security questions, vendor reviews, or data processing questions: security@analytir.com