Privacy Policy
What we collect, why we have it, who else touches it, where it physically sits, how long it stays, and how to get it removed. Where the honest answer is unflattering, it is written that way on purpose.
Version 1.0 · Last updated: [TO BE COMPLETED ON APPROVAL — publication date] · Applies to Sovun Assistant, operated by Sovun Technologies. If we change anything meaningful we will update this page and tell current customers — see Changes to this policy.
The short version
Sovun Assistant is business software. You put your company's operational information into it — jobs, estimates, inventory, appointments, the emails your customers send you — and it prepares work that a person at your business reviews and approves.
Here is the honest summary, and the rest of this page is the detail behind it:
- Your business data is yours. We do not sell it, rent it, or hand it to anyone for advertising. We do not use one client's business records to serve another client.
- Our QuickBooks connections read, and they write records you approved. Nothing is written to your books that a person at your business did not approve first. The QuickBooks section below sets out exactly what can be read, what can be written, and what is switched off today.
- We run on our own hardware, not in a cloud data centre. Sovun Technologies is a very small company. We have no security certifications and no security team.
- People at Sovun Technologies can see your data. That is how we support you. We have not built a technical restriction that limits our support access to reading only.
- We do not have an automatic deletion schedule. We keep your data for as long as your account exists. If you ask us to delete something, a person does it by hand, and copies already taken in backups are not reached by that.
Who we are, and who this covers
Sovun Assistant is built and operated by Sovun Technologies, a company in Maine, United States.
Registered entity: [TO BE COMPLETED BEFORE PUBLICATION — exact registered legal entity name and form]
Registered address: [TO BE COMPLETED BEFORE PUBLICATION — registered mailing address]
This policy covers three different groups of people, and it is worth being clear which one you are:
- The business that subscribes to Sovun Assistant. Most of this page is about you.
- People who work at that business and sign in — owners, office staff, technicians. We hold an account for each of you.
- Your business's own customers, who never signed up for anything with us. Their name, phone number, email address and the message they sent you can end up in our system because you use Sovun Assistant to handle enquiries. There is a section specifically about them.
This policy also covers people who fill in the enquiry form on this website.
What we collect, and why
Your account
Your email address, your name, which company you belong to, your role, and a protected version of your password. We need these to let you in and to show you your own company's information and nobody else's.
Passwords are never stored as you typed them. We store a one-way scrambled version, and we do the same for sign-in session tokens and password-reset codes — so if our database were ever exposed, none of those could be read back out and used.
Your business's operational data
Whatever you put into the platform, and whatever it generates for you. Depending on which parts of Sovun Assistant your company uses, that can include: companies and contacts, leads and enquiries, estimates, invoices and invoice tasks, inventory and bills of materials, production builds and cost rollups, appointments and bookings, delivery manifests, product batches, wholesale orders, follow-up drafts, review items, and documents you upload. We hold it in order to run the parts of the product your company uses.
Your customers' contact details
When an enquiry comes in — from your website form, a forwarded email, or a lead service such as Angi or Thumbtack — we store the sender's name, email address, phone number and the full text of their message, so that your business can respond to them. For automotive work we also pull vehicle details out of that message where they appear.
Sovun Assistant can also take enquiries by text message and by phone, through a telephony provider. That channel is not switched on for any company today — the credential it needs is not configured on our server, so no text message or call has reached us through it. If it is ever switched on for your company, that provider handles your customers' phone numbers and the contents of their messages, and it will be added to the list of companies further down this page at that time.
These are people who have a relationship with you, not with us. We hold their details so your business can respond to them.
Email you forward to us
If your company forwards customer email into Sovun Assistant, we store the whole message — sender, recipient, subject, and both the plain-text and the formatted body — in a review queue so a person at your business can read it and approve a reply.
We hold no access to your mailbox. Sovun Assistant cannot sign in to your email account and cannot read your inbox. Mail reaches us only because your company chooses to forward specific addresses to us. The permissions that would let software read a Gmail mailbox were deliberately removed from this product and are not requested.
Calendars
If you connect a Google calendar, we ask only for permission to read it, plus your email address and display name so we can show you which account is connected. Calendar entries are fetched to display on screen; we do not copy them into our database.
If you connect an Apple iCloud calendar so that appointments do not double-book, we read busy time blocks only — the start and end of each block. We do not read event titles, notes, locations or attendees.
How you use the product
We record which pages and tabs of your portal are opened, when, and by which user account. We use this to work out which parts of the product are actually earning their keep, what to build next, and what to show prospective customers.
We are telling you this plainly because it is a commercial motive as well as a product one, and because these records are tied to your company and user account — they are not anonymous. Sovun Assistant does not run advertising trackers, and we do not sell this information.
Support conversations
Messages you send us through the platform, feedback you submit, and support cases. Support case text is automatically scrubbed of anything that looks like a password, key or token, and of email addresses and phone numbers, before it is stored.
Your agreement, and the record of it
When you accept our agreement in the app, we store which version you accepted, when, and the internet address (IP address) your browser was using at that moment. That record is how we can show, if asked, that consent was actually given.
Notifications on your devices
If you turn on browser notifications we store the notification address your browser gives us, the keys needed to deliver to it, and your browser's identification string, for each device you enable.
If you filled in the enquiry form on this website
You are not a customer and you have no account. What that form collects is your name, your email address, your business type, and up to 3,000 characters describing the workflow you want looked at. It is not stored in the Sovun Assistant platform at all. It is turned into an email and sent to our own company mailbox, with your address set as the reply-to so we can answer you. The form also carries a hidden field that real visitors never fill in; if it is filled in, the submission is discarded as automated.
Two companies handle it: Cloudflare, which runs this website and sends the message, and Google, which hosts the mailbox that receives it. It then sits in that mailbox like any other email, for as long as we keep it — there is no schedule that removes it. If you would like it deleted, write to [email protected] and we will do it, and reply within 14 days.
QuickBooks
This section is the most detailed on the page, because it is the one an accountant — and Intuit — will read most carefully. There are two different QuickBooks connections and they behave differently. Please read the one that applies to you.
QuickBooks Online — what we are allowed to touch, and why
When your company connects QuickBooks Online, Sovun Assistant asks Intuit for the standard accounting permission and nothing else. That permission is granted on Intuit's own screen, by you.
Inside our software there is a second, narrower list: the record types our code is permitted to ask QuickBooks Online for at all. There are ten, and we would rather set out all ten than the shorter list of what happens to be switched on this week:
- your company information;
- customers;
- items (your products and services);
- payment terms;
- tax codes;
- accounts — your chart of accounts;
- vendors;
- purchases — your expense transactions;
- time activities — billable time entries;
- invoices.
Anything outside that list is refused by our own code before a request is made. Bills, deposits, journal entries, payments and employee records are all deliberately excluded.
What is switched on today is narrower than what is permitted. One route is wired, and it fetches the first five: company information, customers, items, payment terms and tax codes. The readers for accounts, vendors, purchases, time activities and invoices are written and tested but are not reachable from any screen yet. We describe the permitted list rather than the wired list because connecting a route is a small change, and we do not want this page to become untrue quietly.
What each is for. The first five are reference information, read so that what you see inside Sovun Assistant matches your books — the same customer names, the same product and service list, the same payment terms and tax codes, rather than a second set typed in by hand. Accounts, vendors and purchases are read to assemble a review queue of expense transactions that have not been categorised, so that a bookkeeper can categorise them. Time activities and invoices are read to work out which billable time has not yet been invoiced and when each customer was last invoiced — so that an invoice can be proposed for a person to check and approve.
Not all of it is reference data. Two of those record types carry free text written by a person rather than a tidy list: an expense transaction can carry a private note, and we keep up to the first 2,000 characters of it; and a time entry carries a description, which in a professional practice can contain notes about a client matter. Calling all ten "reference data" would be comfortable and wrong, so we are not calling them that.
QuickBooks Online — writing to your books
Sovun Assistant is designed to write to QuickBooks as well as read from it, and that is how we declare the connection to Intuit. We would rather describe that plainly than let you discover it later.
Everything we write is something a person approved. The pattern is always the same: the product assembles a proposed record from your own data — for example an invoice for billable time that has not been invoiced yet — and puts it in front of someone at your business. It reaches QuickBooks only if that person approves it. There is no path by which the software decides on its own to create, change or delete anything in your books.
Writing is not enabled in production today. The outbound connection our server is permitted to make to Intuit's accounting service currently accepts read requests only, and it stays that way until Intuit issues production credentials and we enable writing deliberately. Enabling it will not change the approval rule above.
What we read is not saved. The information comes back from Intuit, goes straight to the screen that asked for it, and is not written into our database. As the product is wired today, there is no stored copy of your QuickBooks Online books in our systems.
We do not calculate your tax, and we do not touch payments. Payment records are on the list of things our software refuses to request at all.
QuickBooks Online — what we do store about the connection
We keep one record of the connection itself. It contains:
- your Intuit company identifier — Intuit calls this the realm ID — which we store as ordinary readable text, not encrypted. It identifies which QuickBooks company is connected. It is not a password and it cannot be used to reach your books on its own, but we would rather tell you it is unencrypted than have you assume otherwise;
- the access keys Intuit issues us, which are encrypted before they are stored;
- the dates the connection was made, last renewed, and ended.
Your QuickBooks user name and password are entered on Intuit's own website, never on ours. We never see them and never store them.
QuickBooks Online — the current state of this connection
To be completely straight with you about where the product actually is: as of the date on this page, the live QuickBooks Online connection is switched off. Two separate settings have to be turned on before any real reading can happen — one for the whole platform and one for your company specifically — and the platform-wide one is off. Until it is on, the only QuickBooks Online path that runs is Intuit's test environment.
When that changes, one other thing changes with it: our software will not start the production connection at all unless the arrangement that holds the encryption key in Amazon Web Services' key-management service is turned on at the same time. So on the day the production connection is enabled, Amazon Web Services becomes one of the companies handling your data, and it will be added to the list below.
QuickBooks Desktop — this one is different
Some companies connect QuickBooks Desktop instead, using Intuit's QuickBooks Web Connector. That is a separate connection with different behaviour, and we will not paper over the difference:
- it writes to your QuickBooks company file today — specifically, recording completed production builds and updating assembly costs, and only where those were approved in Sovun Assistant first. Both are switched off unless your company has explicitly had them enabled, and nothing else can be written;
- it does save QuickBooks records into our database — your item and assembly records are copied into our inventory and bill-of-materials tables so the rest of the platform can use them. On a company's first full import, the earlier provisional inventory and bill-of-materials rows for that company are cleared and replaced.
Our relationship with Intuit
We do not process your data on Intuit's behalf. Sovun Technologies is an independent company. You are our customer. We decide, with you, what we do with the information you give us; Intuit does not direct us and we are not acting as Intuit's agent or as a joint decision-maker with Intuit.
We are not an Intuit partner and we do not claim any preferred or exclusive relationship with Intuit.
What we never do with your QuickBooks information
- We do not sell it, and we do not make it available to any third party for anything that is not directly part of running Sovun Assistant for you.
- We do not send it to an artificial-intelligence provider. See the next section — that is not a promise we are asking you to take on trust; it is a property of how the software is built.
- We do not show it to another Sovun Assistant client.
- We do not use it for advertising, and we do not use it to build a profile of you or of your customers.
Artificial intelligence
Sovun Assistant uses a large language model for one job: drafting a reply to an email a customer sent you, so that a person at your business has something to edit rather than a blank page. Drafts are placed in a review queue. Nothing the model writes goes to your customer until a person approves it.
When a draft is prepared, exactly five things are sent to the model provider: your business name, the sender's name, the subject line, the first 4,000 characters of the message body, and — if we have matched the sender to one of your customer records — that customer's name.
No QuickBooks information of any kind is ever sent to a model provider. That is guaranteed by the shape of the code, not by a rule we follow — the function that builds the model's input can only carry those five fields, so there is no route by which an inventory record, a customer list or anything read from QuickBooks could reach a provider even by mistake.
The provider we route these requests through is OpenRouter, which passes the request to Anthropic. Email content sent for drafting therefore leaves our servers and reaches both of those companies, and their own terms govern what they do with it. We have not negotiated any special data-handling terms with either of them, and we are not claiming any here.
Who else touches your data
Running this service means some other companies necessarily handle parts of your information. This is the complete list as of the date on this page. Every entry was verified against the running system, and nothing is listed that is not actually in use.
| Company | What they handle |
|---|---|
| Cloudflare | All web traffic to and from your portal passes through Cloudflare, which also provides the encrypted connection between your browser and us. Cloudflare also runs this public website and sends the enquiry-form email described above. |
| Resend | Email the platform sends on your behalf, and email your company forwards to us — including the message contents. |
| OpenRouter, which relays to Anthropic | The five fields described in the section above, when an email draft is prepared. No QuickBooks data. |
| Intuit | The QuickBooks connection itself. |
| Read-only calendar access, if your company connects a Google calendar. Google Workspace also hosts our own company mailbox, which receives enquiry-form submissions and mail forwarded to our company address. | |
| Apple | Read-only calendar busy-time access, if your company connects an iCloud calendar. Apple's iCloud Drive also holds our offsite backup copies — see Backups. |
| Apple, Google and Mozilla notification services | If you enable browser notifications, the notification title and text pass through whichever service your browser uses. |
Amazon Web Services is deliberately not on that list: it holds nothing for us today. It joins the list on the day the production QuickBooks Online connection is enabled, as described above.
Where your data lives, and how it is protected
We would rather you know exactly what you are trusting.
Sovun Assistant does not run in a cloud data centre. It runs on a single computer — a Mac mini — at Sovun Technologies' own location in the United States, along with the database that holds everything described on this page. That machine is reached from the internet through Cloudflare, which is why your connection to your portal is encrypted and why the machine itself is not directly exposed.
What that means in practice:
- The whole volume is encrypted with the operating system's built-in full-disk encryption. That protects the disk when the machine is off or locked. It is worth being precise about the limit: a server running under load is by definition unlocked, so full-disk encryption is not a defence against someone taking a machine while it is running.
- The database itself is not separately encrypted. Its protection is the encrypted disk and the operating system's file permissions.
- Your connection is encrypted between your browser and Cloudflare, and browsers are instructed to refuse an unencrypted connection to us.
- There is one machine. There is no second copy running elsewhere, no automatic failover, and no geographic redundancy. If that machine is down, the service is down.
- There is a second, smaller database on the same machine, belonging to the internal console we use to run the business. It holds message channels and messages between us. It is copied to the same nightly backup and the same offsite folder as the main database, and the automatic account-deletion process described below does not reach it — that process only runs against the main database. If you ask us to delete your data, we remove your company's records from it by hand as part of that request. We are naming it because "the database that holds everything" would otherwise be the wrong phrase.
Specific protections that do exist, stated exactly:
- Passwords are stored one-way scrambled with a random value unique to each account. Sign-in is deliberately written so that the same slow password check runs whether or not the email address exists, which is intended to stop the speed of a reply revealing whether someone has an account with us. We say "intended" rather than "cannot": the database lookup that happens first, and the per-address attempt limit, are not themselves written to take a fixed amount of time.
- Sign-in attempts are rate-limited, both per email address and per internet address, which slows password guessing to a crawl. These counters are held in the server's memory rather than in the database, so a restart of the server resets them.
- The keys Intuit issues for a QuickBooks connection are encrypted before they are stored. Today the encryption key sits in the server's own configuration file on the same machine as the database. An arrangement that holds the key separately, in Amazon Web Services' key-management service, is built and tested but is not the one in force; it becomes active only when the QuickBooks connection is switched to production.
- The QuickBooks integration's own audit records are filtered by a strict list of nine permitted fields before they are written, so no key, no authorisation header, no QuickBooks content and no raw error text from Intuit reaches those records. That much is enforced by the code rather than left to care. It is a filter on those records specifically — not on every log we keep. The server's general diagnostic output is a separate channel with no such filter, described two sections below.
And, just as importantly, what does not exist. Sovun Technologies has:
- no SOC 2 report, no ISO certification, and no other security certification of any kind;
- no security team, and no third-party security audit or penetration test;
- no data protection officer;
- no bug-bounty or vulnerability-disclosure programme.
We are a one-person operation. Security work here is done as a deliberate review step before releases, not by a standing team. If a security programme is a requirement for your business, this is the section to weigh.
Who at Sovun Technologies can see your data
This is the section most likely to be softened elsewhere, so it is written plainly here.
Sovun Technologies personnel can access your data. An administrator account on our side can read any client's records, and can also make changes. That is how support, setup and troubleshooting get done. It is not limited to reading.
The software development tools we use to build and operate the platform run on that same machine, which means they can reach its files. We mention it because "personnel" would otherwise not be the whole answer.
There is also a separate, more visible route we use when we need to see what you see. It is called "view as", and:
- it requires its own short-lived credential, valid for 30 minutes, tied to the exact administrator session that started it;
- starting it and ending it are both recorded;
- while it is active, a banner is shown at the top of the portal saying who is viewing.
The honest caveat: that banner describes the session as a read-only support view, but that wording is a label in the interface, not a restriction the server enforces. There is no technical block that stops an administrator using that mode from changing something. The controls that are real are that the access is explicit, separately credentialed, time-limited and visible to you — not that it is technically confined to reading. We are correcting our own wording here rather than leaving you to discover it.
Within your own company, staff accounts are locked to your company's data — they cannot read or write another company's records — and accounts marked as view-only are blocked from making changes.
Do we mix one client's data with another's?
No. Your business records are not shown to another client, not combined with another client's records, and not used to produce anything for another client.
The one thing we do look at across all clients is the product-usage information described earlier — which screens get used, how often — to decide what to build next. Those records are tied to a company and a user account rather than anonymised, so we are describing this as internal analytics on identified accounts and not as anonymous statistics.
What we record about activity
We keep an activity log so that we can investigate problems and see who did what. It records email addresses and internet addresses in some places — notably failed sign-in attempts, password-reset requests, and single-sign-on events.
Two honest limitations: the log is an ordinary table in the same database as everything else, with no tamper-proofing and no copy kept off the machine; and our server's own diagnostic output, which is written to a file on that machine, includes the email address on a password-reset request and the internet address of each QuickBooks Desktop connection, and is not automatically rotated or trimmed.
Cookies and what your browser stores
Short section, because there is very little to say.
- A sign-in cookie. When you sign in, we set one cookie holding your session token. It is marked so that scripts on the page cannot read it, and so that it is not sent from other sites. Signing out clears it.
- A support-session cookie. When someone at Sovun Technologies opens a "view as" support session, a second, separate cookie carries that session. It expires after 30 minutes.
- Nothing else. Sovun Assistant runs no analytics tag, no advertising pixel, no session-replay tool and no third-party tracker — not Google Analytics, not Tag Manager, not Meta, not Hotjar, not Plausible. This website does not either. There is no cookie banner because there is nothing to ask you about beyond the two cookies above, which are needed to sign you in.
Where processing happens
The machine that runs Sovun Assistant, and both databases on it, are in the United States. So are we.
Some of the companies listed above process data outside our building and, in some cases, outside the country — traffic to your portal passes through Cloudflare's network; email is handled by Resend and by Google; email drafting requests go to OpenRouter and on to Anthropic; the QuickBooks connection reaches Intuit; offsite backup copies sit in Apple's iCloud Drive. Where each of those companies physically processes the data is determined by that company, not by us, and we have not negotiated a location restriction with any of them.
Backups
The entire database is copied every night — every row of every table, including everything described on this page. Those copies are:
- plain compressed files, not separately encrypted. Locally they are protected by the encrypted disk they sit on. A copy is also placed in Apple iCloud Drive, where the protection is whatever iCloud provides;
- kept until they age out, with older ones removed automatically as newer ones replace them — except for a monthly copy that is placed in an archive folder which nothing currently removes. We are not publishing a fixed retention period, because the honest answer is that these are operational settings rather than a policy we would be holding ourselves to.
This matters for deletion. Removing something from the live system does not remove it from backup copies that were already made. Please read the next section with that in mind.
How long we keep things
The truthful answer is: for as long as your account exists, and after that until the backups holding it age out.
We do not have a defined retention period, and there is no automatic process that deletes old records. Leads, email in the review queue, invoices, appointments, activity logs, product-usage records, support messages — none of these are removed on a schedule. We would rather tell you that than publish a deletion timetable that nothing in the software enforces.
If you want something removed sooner than that, ask us — the next section is how.
Deletion, and what we can actually promise
When a QuickBooks connection ends
When a QuickBooks Online connection is disconnected, we tell Intuit to revoke our access and we mark the connection record as ended. Nothing further is read from, or written to, your books.
But the record itself is marked as ended, not deleted. The encrypted keys stay in that row even though they no longer work. There is no step anywhere in our software that erases a QuickBooks connection record; it goes only when the whole account is deleted, or when you ask us to remove it. There is more detail on our QuickBooks disconnection page.
Asking us to delete your data
Write to [email protected]. A person at Sovun Technologies handles it, and we will respond within 14 days. Five things you should know before you rely on it:
- It is done by hand. A person runs it. There is no self-service delete button and no scheduled process.
- What it covers on the live system. It removes your users, their sessions, and rows from every table that is keyed to your company — those tables are found automatically, so newer parts of the product are covered too. It also removes your company's activity history, which means the record of what happened in your account goes with it.
- What it cannot currently tell us. If the removal from one of those tables fails — a lock, a constraint, a permissions problem — the process carries on and still reports success. It has no way to report a partial deletion. So we can tell you it ran; we cannot, today, hand you a signed statement that every last row went. We would rather you knew that than take "deleted" on trust. A person can check afterwards, and for a deletion that matters we will.
- The automatic part reaches one database, not both. It runs against the main platform database. The smaller internal console database described earlier is removed by hand as part of the same request.
- It does not reach backups. Copies taken before the deletion still contain the data, including the monthly archive copy that is not currently removed on any schedule.
There are also some older files on the machine — earlier uploads and leftovers from a previous version of the system — that sit outside the database and are not reached by either the deletion process or the nightly backup. We would rather name that than let it be assumed clean.
Your rights
These are things we will do on request, whoever and wherever you are, because they cost us nothing but time:
- Access — tell you exactly what we hold for your company;
- Export — give you a copy of it, in a form you can use elsewhere;
- Correction — fix anything that is wrong;
- Deletion — delete it, with the caveats in the section above stated honestly rather than buried.
Ask for any of them at [email protected] and we will respond within 14 days. All four are done by hand by a person, which is why we have not promised a faster turnaround than we can actually meet.
This policy is governed by the laws of the State of Maine, United States.
If you are a customer of one of our clients
If a business you contacted uses Sovun Assistant, your name, contact details and the message you sent may be stored in our system on that business's behalf.
That business decides what happens to your information, not us. The fastest route is to contact them directly. If you would rather come to us, write to us at the address below and we will pass your request to them and help them action it.
We do not sell your information, we do not use it for advertising, and we do not use it to build a profile of you.
How we record your agreement
Before your company starts using Sovun Assistant, someone with authority accepts our agreement inside the app. We keep a record of which version was accepted, by whom, when, and from which internet address — so that if we are ever asked to show that permission was actually given, we can.
If your company's permission is withdrawn, or your agreement with us ends, or a connection is disconnected, we stop processing the data that permission covered.
If something goes wrong
If we discover a security incident that affects your data, we will tell you within 24 hours of discovering it, by email to the addresses on your account, and we will tell you what we know at that point rather than waiting until we know everything.
Where the incident touches QuickBooks data, we are also required to notify Intuit within 24 hours of discovering it, and we will.
Changes to this policy
If we change this policy in a way that affects what we do with your data, we will update this page, change the date at the top, and tell current customers. Where a connection to another service is involved, we will also notify that service's provider in writing where their terms require it.
Contact
Questions about anything on this page, or a request about your data, go to a person — not a ticket queue.