QuickBooks Bulk Importer, published by Cody Labs. Effective 21 July 2026.
QuickBooks Bulk Importer (the "add-on") moves your QuickBooks invoice, bill, and customer data into your own Google Sheets. This policy explains what the add-on accesses and how that data is handled. The short version: your data flows directly between your QuickBooks company and your Google Sheet — Cody Labs operates no servers and never receives, stores, or transmits your financial data or your QuickBooks credentials.
spreadsheets.currentonly scope). The add-on cannot see your other files in Google Drive.All processing happens inside Google's Apps Script runtime, in your Google account. Financial data is fetched from your QuickBooks company and written into your spreadsheet. It is not sent to Cody Labs or any third party. We have no database and no server that could receive it.
Your QuickBooks OAuth authorization is handled via QuickBooks' official OAuth2 library. The token is stored using Google's PropertiesService (user properties), scoped to your Google account. It is never written into the spreadsheet and is not visible to other people you share the sheet with. It remains until you disconnect or uninstall the add-on, at which point it is removed.
If you enter a license key to unlock paid features, the add-on sends only that license key and the Cody Labs organization identifier to our payment processor, Polar, to confirm your subscription is active. No financial data or QuickBooks credentials are involved. See Polar's privacy policy. A disabled legacy Gumroad verifier remains in the release only as a rollback path and is not called during normal use.
The add-on keeps aggregate counts of six one-time milestones in Google Apps Script Properties: install, first connection, first successful run, free-limit reached, checkout opened, and license activation. The counters contain no account identifier, email, OAuth token, accounting data, spreadsheet content, or license key. Per-user markers in your Google account prevent duplicate counting and ensure a Marketplace review is requested only after the first successful import.
The only Google user data the add-on accesses is the content of the single Google Sheets spreadsheet you open it in, through the spreadsheets.currentonly scope. It uses that data for one purpose only: to generate import templates, to read the invoice, bill, and customer rows you enter so it can validate them against your QuickBooks company, and to write validation notes, results, QuickBooks record IDs, and an activity log back into that same spreadsheet. The add-on:
spreadsheets.currentonly scope makes this technically impossible);The add-on's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We protect your data — including any sensitive data — with the following mechanisms:
PropertiesService user-property store — encrypted at rest by Google and scoped to your own Google account. They are never written into the spreadsheet and are never exposed to other people you share the sheet with.spreadsheets.currentonly, script.container.ui, and script.external_request scopes, so it can only ever touch the active spreadsheet and the endpoints described above — never your wider Google Drive or account.Because we store nothing on our own systems, there is nothing for us to retain or delete. Credentials and settings live in your Google account's add-on storage and are removed when you disconnect or uninstall. Financial data lives in your spreadsheet, under your control.
We may update this policy; material changes will be reflected by the effective date above.
Questions about this policy: [email protected].
QuickBooks is a trademark of Intuit, Inc. Google Sheets is a trademark of Google LLC. This add-on is independent and not affiliated with or endorsed by either.