Security Overview

安全说明

Your books stay yours. Here is exactly what SnapBack does with your data — no vague promises.

你的账套始终属于你。下面如实、具体地说明 SnapBack 如何处理你的数据。

Version 2 — October 3, 2026第二版 — 2026 年 10 月 3 日

1.What SnapBack can and cannot access1.能访问什么、不能访问什么

Can readYour QuickBooks Online company data — only after you authorise it via Intuit's official sign-in.
How you authoriseIntuit's own OAuth flow. You sign in on Intuit's website. SnapBack never sees or stores your QuickBooks password.
Never asks forYour QuickBooks password · your bank credentials · your card details.
Where backups goOnly where you choose: a folder on your computer, a cloud drive you control, or both. SnapBack does not upload your company file to a server we operate.
能读取你的 QBO 账套数据 —— 且必须由你本人通过 Intuit 官方登录授权后。
如何授权走 Intuit 官方 OAuth 流程,你在 Intuit 网站登录。SnapBack 看不到、也不会保存你的 QBO 密码。
绝不索取QBO 密码 · 银行凭据 · 信用卡信息。
备份去向只存你自己选择的位置:本机文件夹、你自己的网盘,或两者。SnapBack 不会把账套上传到我们运营的服务器。

2.How your authorisation is stored2.授权令牌如何保存

  • The access token is stored encrypted on your own computer (~/.snapback/tokens.json) using AES-256-GCM.
  • The encryption key is generated randomly on your machine (256-bit) and kept in a separate file readable only by your user account (Unix permission 600).
  • 访问令牌以 AES-256-GCM 加密后保存在你自己的电脑上(~/.snapback/tokens.json)。
  • 加密密钥在你的机器上随机生成(256 位),单独存放,只有你的账户可读(Unix 权限 600)。
✅
Deliberate design choiceIf that key cannot be created for any reason, SnapBack uses a temporary key — meaning you would simply re-authorise next time. It will never fall back to writing your credentials in plain text.
一处刻意的设计选择如果密钥因故无法创建,SnapBack 会使用临时密钥 —— 结果是下次重新授权即可,而绝不会退化成把凭据明文写到磁盘上。
  • Revoke any time from your Intuit account settings (Settings → Apps).
  • Uninstalling SnapBack removes its local token storage.
  • 随时在 Intuit 账户设置里撤销授权。
  • 卸载 SnapBack 会清除本地令牌存储。

3.How your backups are encrypted3.备份文件如何加密

  • Every backup is encrypted with AES-256-GCM; the key is derived using PBKDF2-SHA512 with 600,000 iterations.
  • Each backup uses a fresh random salt and a fresh random IV, so the same data never produces the same ciphertext twice.
  • Your data is compressed before it is encrypted.
  • 每份备份使用 AES-256-GCM 加密,密钥通过 PBKDF2-SHA512、60 万次迭代 派生。
  • 每份备份都使用全新的随机 salt 和随机 IV —— 同样的数据两次加密结果完全不同。
  • 数据先压缩、再加密。

4.One honest limitation4.一处如实的局限

⚠️
The backup file stores its own encryption key inside the file.This is a deliberate trade-off: it is what allows backups to run fully automatically — no password to remember, and no risk of losing access to your own backups.
备份文件把自己的加密密钥写在文件里。这是为了"全自动运行、无需记密码、也绝不会因忘密码而读不出自己备份"而做的有意取舍。
  • What it protects: the backup while it sits on your disk, and against anyone who gets into the machine without access to your account.
  • What it does NOT protect: a copy of the backup file once it leaves your computer. Anyone who obtains the file can read it.
  • 👉 So do not email, upload to a third party, or share your .snap files. Treat them exactly like your books.
  • An upcoming update adds an optional password mode for those who want files that stay encrypted even when moved. It will be opt-in; automatic backups stay automatic.
  • 它保护什么:文件在你硬盘上的状态;以及防止他人绕过你的账户读取本机内容。
  • 它不保护什么:一旦文件离开你的电脑。任何拿到该文件的人都能读取它。
  • 👉 因此:不要把 .snap 备份文件通过邮件发送、上传或分享给第三方。请像对待账套本身一样对待它。
  • 后续版本会提供可选密码模式,供更在意文件外传风险的用户使用。该模式为可选项,自动备份仍保持全自动。

5.Your control5.你的控制权

  • Revoke access yourself, any time, in your Intuit account — no need to contact us.
  • Delete your data any time by deleting the backup files on your computer.
  • No lock-in: your backups are files on your disk, not our database.
  • 随时自行撤销授权,在 Intuit 账户设置里操作即可,无需联系我们。
  • 随时删除数据:删除本机备份文件即可。
  • 不锁定:备份是你硬盘上的文件,不是我们数据库里的资产。

6.Compliance & contact6.合规与联系方式

  • SnapBack is built on Intuit's official QuickBooks Online API under Intuit's developer terms.
  • Security questions: snapback1689@gmail.com
  • SnapBack 基于 Intuit 官方 QuickBooks Online API 构建,遵循 Intuit 开发者条款。
  • 安全问题请联系:snapback1689@gmail.com

Questions about your data?

对数据安全有疑问?

Email snapback1689@gmail.com — we answer security questions directly.

发邮件给 snapback1689@gmail.com —— 安全问题我们直接回复。