AN Software LLC
Privacy Policy
Applies to Verrandi. Effective 6 September 2026.
The short version: your business records are held in a database instance dedicated to you. We do not sell them, we do not share them with advertisers, and we do not use them to train machine-learning models. We do hold operational access to that database, and processes we run read your connected systems on a schedule, including when nobody is signed in. This page is specific about that rather than reassuring about it.
Who we are
Verrandi is built and operated by AN Software LLC ("we", "us"), a California limited liability company. Contact us at alex@verrandi.com.
AN Software LLC2108 N St Ste N
Sacramento, CA 95816
United States
This policy covers Verrandi, including its connection to QuickBooks Online and to any other system a customer chooses to connect.
Where your data lives, and who holds the keys
Each customer's data is held in a database instance dedicated to that customer. We do not maintain a combined store of customer content across customers.
There are two arrangements, and which one applies to you is agreed when you start:
- Managed — the default. The database instance is dedicated to you and the records in it are yours, but we create and administer it, and we hold the administrative credentials. In practice this means we can reach your content. We do so to operate and repair the service, not to read your business.
- Sovereign — the database belongs to your own cloud account and you hold the administrative credentials. We reach it only through the access you grant.
Some connected systems are read live rather than copied. QuickBooks Online is one of these: accounting records are read from Intuit at the moment a question is asked and are not written into our storage.
When we read, and on whose authority
Verrandi reads your connected systems in two ways, and one of them is unattended.
In the background. Scheduled processes we operate collect content from connected sources — email, documents, calendar — using the authorization granted by the person who connected each source. These run on a schedule whether or not anyone is signed in. This is how the system stays current, and it means that connecting a source is a standing grant rather than a per-session one.
When you ask. Answering a question reads from what has already been collected, and may read a live system such as QuickBooks Online at that moment.
Who can see what
When a person signs in, what they can retrieve is limited to the sources they have been granted and to content about them personally. That limit is applied when content is retrieved, before it reaches the reasoning step.
Two things about this you should know rather than discover. First, the limit is enforced at the level of the source — a person granted a source can retrieve what was collected from it. It is not a per-item re-check against the permissions of the original system, so it will not by itself reproduce fine-grained sharing rules inside a mailbox or a document store. Second, an administrative role exists that can retrieve everything in your instance. Your own administrator holds it, and so do we under the managed arrangement above.
If a category of material must never be reachable through Verrandi, do not connect the source that holds it. That is the only boundary we can promise today.
Credentials
Access credentials — including OAuth tokens for QuickBooks Online — are held encrypted in your own database instance. They are not held in a shared store.
They do, however, pass through services we operate. When you first authorize a system, the authorization code is exchanged for a token by a service of ours, which then writes the token to your instance; when a token is renewed, the renewal passes through that same service. Your business records do not pass through it. We state this plainly because it is a real qualifier on the sentence "your data stays in your own database," and we would rather you read it here than infer it later.
Intuit and QuickBooks Online data
Specific to the QuickBooks Online connection:
- We request only the accounting scope, and only for companies you explicitly connect.
- Accounting data is read on demand to answer a question or prepare a proposed change. It is not copied into our storage, not indexed, and not retained after the request completes.
- We do not write to your books without you approving the specific change first.
- We do not disclose QuickBooks data to any third party except the infrastructure providers named below, and we do not use it for advertising or profiling.
- Disconnecting removes our authorization. See how to disconnect.
What we never do
- We do not sell customer data, and we do not share it with data brokers or advertisers.
- We do not use customer content to train machine-learning models, and we do not permit our providers to do so.
- We do not read customer content to build products or profiles.
Service providers
Verrandi runs on infrastructure operated by third parties, including database and cloud hosting providers and the provider of the language model that performs reasoning. Content is sent to the reasoning provider only as needed to answer a request. We select providers whose business terms bar training on the content sent to them and limit its retention, and we do not authorize any provider to use customer data for its own purposes. Their own terms govern what they do, and we cannot audit them beyond what those terms allow.
Retention and deletion
Collected content stays for as long as you keep the source connected. Disconnecting a source stops further collection but does not by itself delete what was already collected. Write to alex@verrandi.com to have it deleted and we will do so. Under the sovereign arrangement you may also delete the database directly. Operational logs that record that a request occurred, without its content, are kept for a limited period for security and reliability.
Security
Credentials are stored encrypted. Retrieval is denied by default and permitted only after the signed-in person's identity is resolved from their own session. We run automated checks that look for misconfiguration which could widen access, and we treat a finding as an incident. These checks run on a schedule, so they detect a problem rather than prevent one, and there is a window between a misconfiguration appearing and a check noticing it.
We have no third-party security certification — no SOC 2, no ISO 27001 — and we do not claim one.
Your rights
You may ask what is held about you, ask for a copy, ask for correction, or ask for deletion, by writing to alex@verrandi.com. We aim to respond within 30 days. Depending on where you live you may also have the right to complain to a data protection authority.
Children
Verrandi is a business product and is not directed to anyone under 18.
Changes
We may update this policy. The current version is always the one on this page, and the effective date above changes when it does. We do not operate a notification list, so check this page if it matters to you.