Read-only means read-only.
How FuseGrid handles your books, in plain English.
What we can — and cannot — do
FuseGrid connects to QuickBooks Online or Xero through the provider's own OAuth consent screen, with read-only access. That's not a policy we promise to follow; it's the shape of the key. FuseGrid can read your books to analyze them. It can never create, edit, or delete a transaction, an account, or anything else in your accounting system. There is no code path that writes to your books, because we never request the permission that would allow one.
What we access
- Your QuickBooks Online or Xero accounting data — the general ledger where provider access permits it, statements, invoices, bills, customers, and vendors — going back five years, so the analysis sees full seasonality.
- Your company profile (name, industry) to pick the right benchmarks.
We don't access your bank logins, payroll provider, or anything outside the accounting connection you approve.
What we store, and how
- A synced copy of your accounting data, so your Brief, forecasts, and reports are ready every morning without re-reading the provider from scratch.
- Everything is encrypted in transit (TLS) and at rest.
- Access is scoped by workspace membership — you control who's invited, and per-viewer permissions control what each person sees.
- Share links are view-only snapshots, served from a random token you can revoke at any time. Recipients never touch your live workspace.
Xero safeguards
Xero API data is excluded from shared model training, cross-company learning, and training corpora. Ledger drill-down is rebuilt deterministically from the organization's own source documents — invoices, bills, payments, and bank transactions — and every month is cross-checked to the penny against reports Xero itself renders before anything is presented. Generative commentary follows the same review gate as every provider: nothing AI-drafted reaches a client until a human reviews it. Deterministic reports, reconciliation, and source lineage are available according to the permissions the organization grants.
Disconnecting
You can disconnect from either side at any time — inside FuseGrid, or from Intuit's or Xero's connected-apps page. Disconnecting stops all syncing immediately. If you want your synced data deleted as well, email hello@fusegrid.io and we'll confirm deletion. Any Excel or PowerPoint files you exported are native files on your machine — they're yours forever. See how to disconnect.
Your accountant as auditor
Every plan includes unlimited seats, so your accountant can log in free and see exactly what you see — every number with its accounting source, plus ledger entries where the provider makes them available. We built FuseGrid to be audited, because you should audit it. We like it when someone checks our work.
Questions
Security question we didn't answer here? Email hello@fusegrid.io and a human will reply. See also our privacy policy.