1. Overview

Effective date: August 20, 2026

Sealed Ledger is a service offering of Ubiquitous LLC ("we", "our", or "us"). We capture accounting records from platforms such as QuickBooks Online and QuickBooks Desktop into cryptographically sealed, independently verifiable archives, and we run migrations between accounting platforms.

This policy describes how we handle information. The short version, because it is unusual enough to state up front: we are a non-custodial service. We capture your records, deliver them to you, and delete our copy. We do not keep an archive of past engagements, we do not maintain a searchable index of client data, and we cannot produce a copy of something we delivered to you last year. That design is described in full on the Custody & Handoff page, and this policy is the binding statement of it.

2. Information we collect

Information you give us

  • Contact information. Your name, email address, company name, and whatever you write in the message when you use the contact form, together with your choice of whether to join our email list.
  • Account credentials. If we issue you an account to use our tools, we store a username, an email address, and a password hash. Passwords are hashed with scrypt and a per-user salt; we never store the password itself and cannot recover it.
  • Engagement correspondence. Email exchanged with us in the course of an engagement.

Information from connected platforms

  • Accounting data. When you authorize a connection, we access your accounting records through the platform's documented API using the scopes you approve. For QuickBooks Online this covers your chart of accounts, transactions, transaction lines, lists (customers, vendors, employees, items), preferences, report payloads, and attachments. This data will contain personal information about third parties — your customers, your vendors, and your employees.
  • OAuth tokens. Credentials issued by the connected platform to authorize access for the duration of a session or engagement. You can revoke our access at any time from within your Intuit account.
  • Attachment files. Where attachment capture is in scope, we retrieve the files themselves — scanned receipts, contracts, checks — and store them inside the sealed archive.

Information collected automatically

  • Analytics. Our public pages use Google Analytics (property G-MP07W97N7R) to measure traffic. Analytics is not loaded on our tool pages or in any authenticated session.
  • Session cookies. An HMAC-signed cookie identifying your logged-in session. It is not used for tracking and carries no advertising identifier.
  • Bot protection. Our contact form is protected by Google reCAPTCHA, which is governed by Google's own privacy policy and terms.
  • Server and application logs. Ordinary web-server logs, plus diagnostic logs written during capture and migration runs. See section 8 for what these can contain and how long we keep them.

3. How we use information

We use information solely to:

  • Perform the capture, sealing, analysis, or migration you have engaged us to perform.
  • Deliver the resulting archive or migration to you and confirm it verifies correctly.
  • Respond to your enquiries and administer your account.
  • Diagnose failures, maintain the reliability and security of the service, and correct defects.
  • Comply with legal obligations.

We do not use your accounting data to train machine-learning models, to build benchmarks or industry datasets, or for any purpose beyond the engagement you commissioned. We do not sell, rent, or trade your information, and we do not share it for anyone's marketing purposes.

4. Our role: processor, not controller

For the accounting data we capture, you are the controller and we act as a processor on your documented instructions. We connect to the platform because you told us to, we retrieve what you asked us to retrieve, and we deliver it where you told us to deliver it.

We perform no independent review of the contents. Our systems parse, structure, hash, and seal the data; no person at Sealed Ledger reads your records except where you have specifically engaged us to analyse them, or where a defect requires investigation and cannot be diagnosed any other way.

Where your accounting records contain tax return information and we are engaged by or on behalf of a tax return preparer, additional obligations may apply to both of us under U.S. federal law. If you are a CPA, enrolled agent, or other preparer engaging us on behalf of a client, tell us at the outset so the engagement terms can reflect it.

5. Sharing and service providers

We do not sell your data. We share it only with the following, and only as needed to operate the service:

  • Intuit Inc. — the source platform. We exchange data with Intuit on your behalf under the OAuth scopes you authorize.
  • A time stamp authority — by default FreeTSA. We send it a SHA-256 hash and nothing else. A hash is not reversible: the authority receives no accounting data, no company name, and no personal information. It returns a signed token attesting that the hash existed at that moment.
  • Our hosting and email providers — infrastructure on which the service runs and through which we correspond with you.
  • Google — analytics on public pages and reCAPTCHA on the contact form, as described in section 2.

We will disclose information where legally compelled to do so. Our retention practice means that for most past engagements there is nothing left to disclose — which is a deliberate consequence of the non-custodial design, not an accident of it.

6. Security

  • All communication with our servers uses HTTPS/TLS.
  • Passwords are hashed with scrypt and a per-user salt. We cannot read them.
  • Access to production systems is restricted to authorized personnel.
  • Short-lived credentials issued by QuickBooks Online inside attachment records — the pre-signed download URLs, which embed an API key and expire within hours — are stripped before sealing, so live credentials are never written into a permanent archive. The archive records which fields were removed.
  • We hold no signing keys. The cryptographic authority behind a seal comes from an external time stamp authority, not from us, so there is no Sealed Ledger key whose compromise would let anyone forge a seal.

No system is perfectly secure, and we do not claim otherwise. What we can say is that the quantity of client data resident on our systems at any moment is small and short-lived by design.

7. The QuickBooks Desktop bundle key

There is one point in our workflow where the non-custodial model does not hold, and we would rather state it than let you discover it.

QuickBooks Desktop capture runs on your own machine. Our capture tool writes its bundle as an encrypted file using AES-256-GCM under a per-bundle key that we generate and hold in our bundle registry. We release that key to you, and on release the key is deleted from the registry and the deletion time is recorded.

Between capture and release, we hold a key that would decrypt a bundle sitting on your machine. We do not hold the bundle. After release we hold neither. If you lose the key after we have deleted it, we cannot recover it and neither can anyone else.

QuickBooks Online bundles involve no such key. They are delivered unencrypted over an authenticated, TLS-protected connection, and confidentiality after delivery is yours to manage.

8. Retention and deletion

This section is the operative one for this service.

During an engagement

We hold a working copy of your captured data on our secured server for as long as the engagement is active, and use it only for the work you commissioned. Diagnostic logs written during capture and migration runs may contain identifying details from your records — customer and vendor names, document numbers, amounts — because that is what makes a failed record traceable.

At engagement close

We delete immediately: the working copy of your archive, any plaintext or encrypted bundle held on our systems, the staged migration ledgers, and the diagnostic logs from your engagement. Deletion happens at close, not on a schedule that runs later.

What we keep

Engagement-record metadata only: an engagement identifier, its dates, a scope description, and a list of deliverables produced. No accounting data, no customer or vendor names, no financial figures. We keep this because we need a record that the work happened.

We keep your account credentials for as long as you have an account with us, and correspondence for as long as is reasonable for the business relationship.

What this means

  • We cannot re-deliver an archive we deleted. You must retain the copy we gave you.
  • We cannot answer a question about the contents of a past engagement without you sending the archive back to us.
  • We cannot restore data you lose. There is no backup on our side.

You may request deletion of your account and any associated information at any time by writing to admin@ubiquitous.llc. We will action it within 30 days, subject to any legal obligation to retain limited records.

9. After we deliver

Once a sealed archive is in your hands, it is yours and its handling is yours. This is worth being explicit about, because a sealed archive is a complete and unusually convenient copy of your books.

The archive contains identifiable personal information about your customers, your vendors, and your employees, and where attachment capture was in scope, the supporting documents themselves. It is not encrypted by the seal — the seal proves the contents have not changed, which is a different property from preventing someone reading them. Anyone holding the file can read it.

We would encourage you to store it on encrypted storage, control who can reach it, and keep a record of who has handled it. If you open the archive with an AI assistant, a cloud analytics tool, or any other third-party service, you are disclosing that data to that provider under their terms, and the decision and its consequences are yours. None of this is a limitation of the seal; it is the ordinary responsibility that comes with holding your own records.

10. What we capture, and what we cannot

We capture only what the source platform exposes through its documented API. Where the platform does not expose something, we do not have it and the seal does not attest to it.

The clearest example is the QuickBooks Online audit log. QuickBooks Online provides no audit-log API, so we cannot retrieve it. If you export it yourself and give us the file, it can be carried alongside the archive and cross-checked, but it sits outside the sealed perimeter and carries none of the API-captured provenance that every other record in the archive carries. We say so in the archive itself rather than leaving you to work it out.

Every archive ships with a LIMITATIONS.txt disclosing what that particular capture did and did not cover, including anything that failed. The general boundaries are set out in our threat model.

11. Your rights

Depending on where you live, you may have the right to access a copy of the personal information we hold about you, to have inaccurate information corrected, to request deletion, and to withdraw consent by revoking our access to a connected platform at any time.

Write to admin@ubiquitous.llc to exercise any of these. We do not charge for it and we will not treat you differently for asking.

One practical note: for personal information belonging to your customers, vendors, or employees that appears inside your accounting records, you are the controller. Requests from those individuals should be directed to you, and we will support you in responding to them.

12. Children's privacy

Sealed Ledger is a business service and is not directed at children. We do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it.

13. Changes and contact

We may update this policy. When we do, we will revise the effective date at the top. Where a change materially reduces the protections described here, we will say so rather than let it pass as a routine revision.

Questions about this policy or our data practices:

Ubiquitous LLC
Email: admin@ubiquitous.llc

See also our Terms of Service.