One Purpose Tools · Product information
Privacy
Your catalog, cheque, Jane report, bank, and email source files can contain confidential business data. One Purpose Tools processes their contents locally in your browser.
Last updated: August 24, 2026
Catalog processing
CSV checks, import-change previews, automatic repairs, and CSV export run in this browser. The product does not upload your CSV, filename, products, SKUs, prices, vendors, URLs, or other catalog values to a One Purpose Tools server.
The browser temporarily holds the data needed for the active task. Resetting, replacing a file, switching away from a tool, closing the tab, or completing a bounded operation releases the related application session data according to the flow. Downloads are files you choose to save on your device.
Positive Pay files and bank settings
Positive Pay CSV and Excel files, cheque rows, payees, cheque numbers, amounts, reconciliation accounts, filenames, validation details containing source values, and generated bank-file bytes are processed locally and are not sent to One Purpose Tools, Stripe, analytics, or logging services.
Immediately before Stripe Checkout, the browser may keep normalized cheque records and the selected bank profile temporarily in session storage under an opaque flow identifier so the local review can resume after payment. That pending state is cleared after generation or reset. If you explicitly choose “Remember this bank setting on this device,” only allowlisted bank configuration values are stored in local storage; you can forget them from the product.
Jane month-end close files
Jane Sales, Billing Summary, Daily Transactions, Jane Payments Transactions, Jane Payments Payouts, and bank exports are read locally. The parser immediately projects the supported accounting totals; patient, customer, card, bank-description, and report-row details are not retained in the close model, sent to One Purpose Tools, or added to generated artifacts.
The browser can temporarily keep a privacy-minimized, flow-specific close package in session storage so the same tab can recover after Stripe Checkout. It contains normalized totals, approved mapping evidence, and the minimum data needed to reconstruct the package—not raw report rows, filenames, patient/customer/card identity, bank descriptions, or analytics attribution. It expires and is cleared after download or reset.
If you choose to remember a QuickBooks posting profile, the browser stores only the allowlisted account names, debit/credit sides, approval state, and safe preferences on this device. It does not store the clinic name, close period, report files, balances, bank entries, journal amounts, or generated package.
Open Month-End Close for Jane + QuickBooks to review the exact supported file set and local-processing boundary.
Shopify payout-close files
One Shopify Payments balance-transactions CSV and one Shopify Orders CSV are read locally in your browser. Activity totals, payout details, bank evidence, store references, dates, amounts, transaction references, account mappings, review notes, and generated close-package bytes that you enter or create are also kept local. They are not sent to One Purpose Tools, Stripe, browser analytics, or logging services.
Checkout receives only fixed product, price, currency, version, environment, and terms identifiers plus a randomly salted, one-way scope reference for the eligible store-month. The scope reference does not disclose the store reference, month, filenames, account names, transaction references, or financial values.
A short-lived signed access authority may be kept in session storage and shared with another same-origin tab. It can restore eligible paid access for the same opaque scope for 30 days, subject to re-verification. It cannot restore source files, controls, allocations, mappings, review notes, or a generated package. The Checkout Session identifier returns in the URL fragment so it is not part of an HTTP request or analytics path.
Bank Statement Converter files
Bank Statement Converter reads the PDF bytes, filename, transaction text, dates, balances, page geometry, corrections, and generated package only in browser memory. It does not upload them to One Purpose Tools, Stripe, analytics, error monitoring, logs, or another hosted service. The original PDF is not embedded in the output package.
Checkout receives fixed product and price identifiers plus random flow and batch identifiers. Those identifiers are not hashes of a statement and do not contain an account number, institution, period, filename, transaction, balance, correction, page image, or row count.
Purchase verification can be shared with another same-origin tab and recovered from a Stripe Checkout Session for 30 days. It restores paid access only. It cannot restore PDFs, extracted rows, corrections, source views, or downloads; you must reselect and requalify the local files.
EmailReady campaign source
EmailReady reads HTML source, filenames, destinations, tracking values, image attributes, campaign expectations, findings, and corrections locally in your browser. None of that campaign content is sent to One Purpose Tools, Stripe, Resend, browser analytics, or logging services.
The active review remains in memory. A local project file or QA package exists only when you choose to download it, and you remain responsible for where that file is stored. A short-lived signed access receipt may be kept in session storage and shared with another same-origin tab; it contains subscription authority, not campaign source.
Starting Checkout sends Stripe the email address you provide and the minimum opaque product, price, mode, flow, terms, and authority-version identifiers required to create and verify the subscription. One Purpose Tools keeps the provider customer and subscription identifiers, status, keyed email lookup, and bounded recovery-use records needed to validate access. Resend receives an address and a one-time access-recovery message only when recovery is requested.
Purchase recovery restores eligible subscription access only. It cannot recover HTML files, corrections, a downloaded local project, or a QA package.
Payments
Stripe receives the email address and payment details entered in Stripe Checkout, together with the opaque payment flow, product, price, bank, service, format/version, and contract-version identifiers needed to process and verify payment. Stripe records whether its required Terms checkbox was accepted. Stripe may collect billing-location information needed to calculate applicable tax. One Purpose Tools does not use or retain that billing address in its payment-verification model.
After paid local generation or selection of the download button, One Purpose Tools may add generation confirmation and download selection timestamps to that Stripe Checkout Session. These payment-support records never include cheque contents, filenames, payees, amounts, account numbers, or generated file bytes. They also exclude record counts and bank settings.
A paid Stripe Checkout Session can be re-verified for 24 hours; the signed browser entitlement lasts 30 minutes. Stripe does not receive the source file or generated bank file.
Privacy-safe product analytics
When production analytics is enabled, One Purpose Tools uses Umami Cloud in its European Union region to measure visits to registered public pages. The tracker is disabled on local, test, preview, and branch deployments and respects your browser’s Do Not Track setting.
Page measurement is limited to the One Purpose Tools website identifier, canonical hostname, registered page path without query parameters or fragments, and a referring hostname when it can be reduced safely. The Shopify checker and Canadian Positive Pay generator may also send reviewed fixed lifecycle names, product/build/ruleset identifiers, real-or-sample mode, closed result/action/blocker labels, and coarse file-size, row-count, and processing-time buckets. Analytics for generated Positive Pay files may include only registry-owned bank and format identifiers; it never sends the bank or account values entered by a customer. Product analytics never sends exact file metrics, findings, rule identifiers, or finding text.
The Jane month-end close may send only fixed lifecycle names, the fixed Jane product/ruleset identifiers, real-or-sample mode, and closed result, action, and blocker categories. It never sends report or bank values, dates, amounts, account names, payment-method labels from a source report, report filenames, or generated package data.
EmailReady product and guide routes do not load browser analytics. EmailReady measurement is limited to aggregate subscription facts available in Stripe and manually categorized, redacted support themes; campaign files, URLs, findings, and report contents are excluded.
For a real Jane close, short-lived random attempt and revision identifiers connect those fixed events so aggregate funnel reports can distinguish a retry from a new attempt. They contain no customer or file information and reset when you switch to an example or begin again. If an eligible close proceeds to checkout, its attempt identifier is stored only as the opaque payment-flow reference in the minimized recovery package and is reused for Stripe Checkout; the revision identifier is not stored there or sent to Stripe.
The integration removes exact screen size, browser language, and page title before transmission. One Purpose Tools does not enable session replay, heatmaps, fingerprinting, or a product identity. Only validated lowercase campaign labels from the four documented UTM fields may be kept for the current browser session; the raw query string is never sent. Filenames, file contents, catalog, cheque, Jane, or bank values, customer details, Stripe identifiers, raw URLs or referrers, query strings, exception messages, and arbitrary event properties are prohibited.
A verified Stripe webhook may report a completed purchase or successful refund to Umami using only pre-tax aggregate product revenue, currency, fixed product and registry-owned bank/format labels, controlled campaign labels, and an irreversible per-event delivery key. Umami never receives a Stripe identifier or customer detail. To prevent duplicate webhook reporting, One Purpose Tools keeps a narrow Stripe-object identity, event type, processing state, and timestamps in an isolated idempotency ledger for up to 35 days; it stores no customer, billing, cheque, file, account, filename, or generated-file content.
Reports and spreadsheets
A cleaned Shopify CSV preserves catalog values, including values that begin with spreadsheet formula markers. The separate audit report applies a limited formula-neutralization policy for human review. No CSV defense works in every spreadsheet program, and the audit report must not be imported into Shopify.
Your browser and future changes
Your browser, device, extensions, download folder, spreadsheet software, and any service where you later upload a file have their own security and privacy behavior. Review them before handling a sensitive catalog.
Material changes to analytics, identity, storage, or other server features require another product and privacy review before they ship.