What we can see
When you connect QuickBooks, Recoup reads your invoices, customers, and payment status. We use that to build your AR audit and draft follow-up messages. To be precise about the permission itself: QuickBooks grants apps one accounting permission that technically covers both reading and writing — Intuit doesn't offer a read-only version of it. Recoup's code only ever reads. There is no code path in this app that creates, edits, or deletes anything in your QuickBooks company file.
What we can't do
Recoup can't move money, issue refunds, change invoice amounts, or take any write action in QuickBooks. The only things that happen on your customers' side are: a message gets drafted, and — if you've approved it — sent. Nothing else.
Every message needs your OK
By default, Recoup drafts a message and puts it in your review queue. Nothing goes to a customer until you approve or edit it. Autopilot — where Recoup sends the routine reminders without stopping for your OK — is something the agent has to earn by matching your voice over many approvals, and even then it only starts once you choose to turn it on. If you never touch a setting, you're in approve-every-message mode, permanently.
We double-check right before every send
Right before any message actually goes out — even one you already approved — the system re-reads your ledger one more time. If the invoice was paid, the customer replied, or the balance changed since the message was drafted, the send is automatically cancelled instead of going out on stale information. This is the single failure mode we designed hardest against: a customer getting chased for money they already paid.
How payments work
When payments are enabled, your customers pay through Stripe. Recoup never sees or stores a card number or bank account number — that information goes directly to Stripe, not through our servers.
Data & access
Data is encrypted in transit (TLS) between your browser, Recoup, and QuickBooks, and at rest in our database provider's infrastructure. We don't sell your data or your customers' data to anyone, and we don't use it to train models for other companies. Today, Recoup is built for a single owner-operator per business — there's no multi-user team access yet.
Revoking access
You can disconnect Recoup at any time from your Intuit account's connected-apps settings — that revokes our access immediately on QuickBooks' side, independent of anything we do. If you'd like your data deleted from Recoup after disconnecting, email us and we'll take care of it.
Where we're headed
We're not SOC 2 certified yet — that's a real, larger investment we're planning for as the company grows, not something we're claiming today. If you have security questions before connecting your books, ask us before you connect anything — we'd rather answer directly than have you take it on faith.