Privacy Policy

/CHARCOAL · Last updated: June 29, 2026

/CHARCOAL (the “Service”) is a private practice-management and billing application operated by Klaber Design Architecture PLLC (“K—DA,” “we,” “us”). This Privacy Policy explains what information the Service collects, how we use it, and how we protect it. The Service is an internal tool for K—DA’s authorized personnel and is not offered to the general public; access requires an authorized K—DA account.

1. Information we collect

2. How we use information

We use this information solely to operate the Service: to authenticate you, record and report time, expenses, and billing, generate invoices, and administer the firm’s projects. We do not sell personal information and do not use it for advertising.

3. Third-party services (sub-processors)

We rely on the following providers, each of which processes data only to provide its service to us:

4. QuickBooks Online (Intuit)

If an administrator connects the Service to QuickBooks Online, we access — through Intuit’s API — your QuickBooks company identifier, customer list, item and account lists, and invoice records. We use this only to (a) export invoices you create in the Service to your QuickBooks company and (b) read back invoice payment status to display a paid/open indicator. The integration is one-way: the only data we write to QuickBooks is invoices you explicitly export. We do not modify other QuickBooks data, and we do not sell, rent, or share QuickBooks data with any third party. OAuth access and refresh tokens are encrypted at rest (AES-256-GCM) and are never exposed to the browser. An administrator may disconnect QuickBooks at any time, which revokes our access.

5. Google user data

If you connect Google Calendar, the Service requests read-only access (the calendar.events.readonly scope) solely to display your events so you can convert them into time entries. We never create, edit, or delete Google Calendar data. /CHARCOAL’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google tokens are encrypted at rest, and you may disconnect at any time.

6. Data security

Access is restricted to authenticated, authorized K—DA personnel. Data is transmitted over HTTPS and stored in access-controlled, managed infrastructure. Sensitive third-party tokens are encrypted at rest, and receipt images are stored privately and served only through authenticated, short-lived links.

7. Data retention

We retain business records for as long as needed for the firm’s operational, accounting, and legal purposes. You may request deletion of specific data by contacting us.

8. Your choices

You may connect or disconnect optional integrations (Google Calendar, QuickBooks) at any time from the Service’s settings. For questions or requests regarding your data, contact us using the details below.

9. Changes to this Policy

We may update this Policy from time to time; material changes will be reflected by the “Last updated” date above.

10. Contact

Klaber Design Architecture PLLC
68 Jay Street, Studio 423, Brooklyn, NY 11201
hello@kda.nyc