1.What SnapBack can and cannot access1.能访问什么、不能访问什么
| Can read | Your QuickBooks Online company data — only after you authorise it via Intuit's official sign-in. |
|---|---|
| How you authorise | Intuit's own OAuth flow. You sign in on Intuit's website. SnapBack never sees or stores your QuickBooks password. |
| Never asks for | Your QuickBooks password · your bank credentials · your card details. |
| Where backups go | Only where you choose: a folder on your computer, a cloud drive you control, or both. SnapBack does not upload your company file to a server we operate. |
| 能读取 | 你的 QBO 账套数据 —— 且必须由你本人通过 Intuit 官方登录授权后。 |
| 如何授权 | 走 Intuit 官方 OAuth 流程,你在 Intuit 网站登录。SnapBack 看不到、也不会保存你的 QBO 密码。 |
| 绝不索取 | QBO 密码 · 银行凭据 · 信用卡信息。 |
| 备份去向 | 只存你自己选择的位置:本机文件夹、你自己的网盘,或两者。SnapBack 不会把账套上传到我们运营的服务器。 |
2.How your authorisation is stored2.授权令牌如何保存
- The access token is stored encrypted on your own computer (
~/.snapback/tokens.json) using AES-256-GCM. - The encryption key is generated randomly on your machine (256-bit) and kept in a separate file readable only by your user account (Unix permission
600). - 访问令牌以 AES-256-GCM 加密后保存在你自己的电脑上(
~/.snapback/tokens.json)。 - 加密密钥在你的机器上随机生成(256 位),单独存放,只有你的账户可读(Unix 权限
600)。
✅
Deliberate design choiceIf that key cannot be created for any reason, SnapBack uses a temporary key — meaning you would simply re-authorise next time. It will never fall back to writing your credentials in plain text.
一处刻意的设计选择如果密钥因故无法创建,SnapBack 会使用临时密钥 —— 结果是下次重新授权即可,而绝不会退化成把凭据明文写到磁盘上。
- Revoke any time from your Intuit account settings (Settings → Apps).
- Uninstalling SnapBack removes its local token storage.
- 随时在 Intuit 账户设置里撤销授权。
- 卸载 SnapBack 会清除本地令牌存储。
3.How your backups are encrypted3.备份文件如何加密
- Every backup is encrypted with AES-256-GCM; the key is derived using PBKDF2-SHA512 with 600,000 iterations.
- Each backup uses a fresh random salt and a fresh random IV, so the same data never produces the same ciphertext twice.
- Your data is compressed before it is encrypted.
- 每份备份使用 AES-256-GCM 加密,密钥通过 PBKDF2-SHA512、60 万次迭代 派生。
- 每份备份都使用全新的随机 salt 和随机 IV —— 同样的数据两次加密结果完全不同。
- 数据先压缩、再加密。
4.One honest limitation4.一处如实的局限
⚠️
The backup file stores its own encryption key inside the file.This is a deliberate trade-off: it is what allows backups to run fully automatically — no password to remember, and no risk of losing access to your own backups.
备份文件把自己的加密密钥写在文件里。这是为了"全自动运行、无需记密码、也绝不会因忘密码而读不出自己备份"而做的有意取舍。
- What it protects: the backup while it sits on your disk, and against anyone who gets into the machine without access to your account.
- What it does NOT protect: a copy of the backup file once it leaves your computer. Anyone who obtains the file can read it.
- 👉 So do not email, upload to a third party, or share your
.snapfiles. Treat them exactly like your books. - An upcoming update adds an optional password mode for those who want files that stay encrypted even when moved. It will be opt-in; automatic backups stay automatic.
- 它保护什么:文件在你硬盘上的状态;以及防止他人绕过你的账户读取本机内容。
- 它不保护什么:一旦文件离开你的电脑。任何拿到该文件的人都能读取它。
- 👉 因此:不要把
.snap备份文件通过邮件发送、上传或分享给第三方。请像对待账套本身一样对待它。 - 后续版本会提供可选密码模式,供更在意文件外传风险的用户使用。该模式为可选项,自动备份仍保持全自动。
5.Your control5.你的控制权
- Revoke access yourself, any time, in your Intuit account — no need to contact us.
- Delete your data any time by deleting the backup files on your computer.
- No lock-in: your backups are files on your disk, not our database.
- 随时自行撤销授权,在 Intuit 账户设置里操作即可,无需联系我们。
- 随时删除数据:删除本机备份文件即可。
- 不锁定:备份是你硬盘上的文件,不是我们数据库里的资产。
6.Compliance & contact6.合规与联系方式
- SnapBack is built on Intuit's official QuickBooks Online API under Intuit's developer terms.
- Security questions: snapback1689@gmail.com
- SnapBack 基于 Intuit 官方 QuickBooks Online API 构建,遵循 Intuit 开发者条款。
- 安全问题请联系:snapback1689@gmail.com
Questions about your data?
对数据安全有疑问?
Email snapback1689@gmail.com — we answer security questions directly.
发邮件给 snapback1689@gmail.com —— 安全问题我们直接回复。