Privacy and data handling
Xero data is accessed only with the connected organisation owner's consent for internal accounting analysis and reconciliation.
- No Xero API data is used to train or fine-tune an AI model.
- OAuth credentials and raw captures are restricted to a root-only connector area.
- Penny receives only validated, privacy-controlled, read-only snapshots.
- No invoices, payments, journals, contacts, payroll records, settings or permissions are created, edited or deleted.
- Access can be revoked from Xero and the connector can be stopped independently.