Privacy Policy
Last updated: July 8, 2026 · Teresa QC LLC. This is a plain-language description of how the Teresa QC software handles data. It is not a contract and not a Data Processing Agreement.
Who We Are
Teresa QC LLC (“Teresa QC,” “we”) makes workpaper-benchmarking software for licensed auditors. The software computes line-by-line variances against a benchmark in a GASB/GAGAS reference format. It does not audit, attest, review, or opine, and it is not a substitute for a licensed auditor's professional judgment. Teresa QC LLC is a software company and is not a licensed Florida CPA firm. See our Legal Disclosures.
What We Collect (Live Today)
- Engagement details you enter — entity name, fiscal year, auditor name, account series, and your independence confirmation. These label your work product and record what a session did.
- Files you upload — the chart of accounts, trial balance, general ledger, and vouching workbook you choose to process, plus any workpaper text you paste for comparison. This content is held only for the length of the request, sent to our AI subprocessor to compute the result, and is not saved to a Teresa QC database — we do not operate one.
- A session log (metadata, not your file contents). For each run we record non-content facts: row counts, ledger totals, date ranges, the materiality basis and any override you make with the reason you type, and pass/fail results of built-in checks. This lets us reconstruct what a session did.
- Sign-in identity. Access is gated by Google Cloud Identity-Aware Proxy; Google handles your sign-in. If our system detects an attempt to attack or extract the software's internal instructions, we log the signed-in email of that request so the account can be revoked.
- Basic error and security telemetry — browser type, error details, and the page path when the app crashes.
- Landing-page visit data — our public page at teresaqc.com is served by Cloudflare and loads Google Fonts, so those providers see your IP address for that request. The landing page runs no analytics or advertising trackers.
What We Collect (Planned — Not Live Yet)
These features are described so this policy is ready when they ship. Each is marked planned and none is active today:
- Planned Eligibility check. Before a user profile is created we intend to verify a Google (Gmail) account and ask you to confirm that you maintain a payment method on file with Google or Amazon. We intend to rely on your attestation and to never store card numbers ourselves.
- Planned User profile. Once eligibility is added, we would keep a minimal profile tied to your account.
- Planned On-device save. We intend to let the app save your in-progress session in your own browser (see “Browser-Local Storage” below).
- Planned Artifact pickup. A page for downloading our pre-made synthetic practice artifacts, which you may alter and run through the software. The synthetic-only rule below applies to everything you submit.
What We Deliberately Do NOT Collect
- We do not operate a Teresa QC database of your uploaded ledgers; uploaded file content is not retained by us after the request.
- We use no advertising trackers and no third-party analytics on the app or the landing page.
- We do not ask for or store payment card numbers ourselves (see the planned eligibility check).
- Your finished
.docx/.xlsxoutputs are generated in your browser and downloaded to your device; we do not keep a copy.
Subprocessors
- Google Cloud — hosts the app (Cloud Run), authenticates you (Identity-Aware Proxy), holds the API key (Secret Manager), and stores operational logs (Cloud Logging).
- Cloudflare — DNS and hosting for the public landing page.
- Anthropic, PBC — the AI service that computes the benchmark draft and the variance report from the data you submit. Under Anthropic's standard API terms, prompts and responses may be retained by Anthropic for up to 30 days in the ordinary course, and content flagged for trust-and-safety review may be retained for up to two years. We have not put a zero-retention agreement in place. If an engagement requires a zero-retention vendor, do not use Teresa QC for it until such an agreement exists.
- Planned Google and/or Amazon — for the eligibility check described above, if and when it ships.
Browser-Local Storage
Planned When the save-in-place feature ships, your in-progress session will be stored in your own browser (localStorage/IndexedDB) on your own device. That data is not transmitted to us, we cannot read it, and you can clear it from your browser at any time. Today, the app keeps no such state — closing the tab discards the session.
Uploads and the Synthetic-Only Rule
Teresa QC is a practice-and-benchmarking tool built to run on synthetic data. If you upload artifacts, they must be synthetic and must not contain real client records, real personal information, or other real confidential data. Do not submit anything you are not free to disclose to our AI subprocessor. If real personal information reaches us despite this rule, our posture is: on detection we will quarantine and delete the affected material, purge it from logs where feasible, and contact the submitting account. Report a suspected exposure to admin@teresaqc.com [FERNANDO-CONFIRM: admin@ vs fcisneros@].
Your Choices and Contact
You control what you upload and what you keep (your outputs live on your device). To ask what we hold about an engagement ID, or to request deletion of a session log, email admin@teresaqc.com [FERNANDO-CONFIRM: contact address]. Access is limited to authorized, signed-in users. See also our Data Retention Policy.
Legal-Framework Applicability
Whether GDPR, CCPA/CPRA, or other privacy laws apply to Teresa QC depends on facts we have not yet determined, and this policy does not claim compliance with any of them. [ATTORNEY QUESTION — do not assert compliance without counsel]
Changes to This Policy
We may update this policy; the “Last updated” date shows the current version. Material changes will be posted here.
← Back to Teresa QC · Legal Disclosures · Data Retention Policy