Last updated: September 23, 2026
Profit Duck (“Profit Duck,” “we,” “us”) provides a financial dashboard that helps restaurant owners understand their sales, fees, expenses, and taxes by bringing together data from their point-of-sale, bank, and delivery platforms. This policy explains what we collect, how we use it, and the choices you have.
Account information — the username/email and password you use to sign in. Passwords are stored only as salted hashes; we never store them in plain text.
Financial & business data you connect — when you connect an account, we retrieve and store the data needed to power your reports:
This integration is not available yet; it is pending Google API approval and release. Once available, if you authorize a connection, Profit Duck will access the Google business accounts and locations you manage so you can view reviews, publish owner replies, and update regular hours, special hours and temporary closures. Each reply or profile change will require your explicit confirmation before it is sent to Google for publication.
We will read profile and location details, hours, reviewer names and profile photos, review content, ratings, and owner replies on demand. We will store encrypted authorization tokens and the identifiers of your selected account and location to maintain the connection. We will not keep a persistent history of reviews, reviewer details, profile details or hours in our database.
The integration will use Google data only for these Business Profile features and will not send Google profile or review data to our AI provider. We will not sell this data or use it for advertising.
You will be able to disconnect Google in Profit Duck to remove the stored connection and request revocation of access. You can also revoke Profit Duck’s access through your Google account’s third-party connections. Encrypted credentials may remain in existing backups until their retention period expires. Disconnecting will not undo replies or profile changes already published to Google.
If you connect Meta, Profit Duck accesses the Facebook Pages and linked professional Instagram accounts you authorize. We read their account identifiers, names, posts, comments, available Instagram usernames, replies and engagement metrics to show them in Social. You can publish posts and comment replies only after reviewing and confirming each action. Meta receives the text and public image address you choose to publish; Meta downloads the image directly from its host. We do not receive your Facebook password.
We store encrypted authorization tokens, account identifiers, granted permissions, token expiration and a bounded set of action receipts to maintain access and prevent duplicate submissions. Receipts contain action identifiers, content hashes, publication status and resource identifiers, not copies of your post or reply text. We keep up to 500 recent receipts and prune older receipts when you next act. We read posts, comments and insights on demand. If you enable daily social history, we also save encrypted follower and engagement snapshots and available post/tag identifiers, dates, links and caption excerpts (up to 500 characters). We also save dated account metrics, aggregate audience breakdowns, and post, Reel and Story metric snapshots. Collection can request available historical insights and discover older posts, whose totals are labeled with the date retrieved. History is bounded to 90 days of snapshots for up to six accounts, 12,000 content snapshots and 120 tagged/feed excerpts per connection, and 1,000 content records per account, subject to a 16 MB history limit that may remove older captures sooner; dated metrics and snapshots older than 90 days are removed during collection; the bounded content inventory may include older posts. You choose which shared accounts appear in the workspace and which save daily history. Removing an account from the workspace stops access and collection locally but keeps its saved history and Meta authorization so it can be added back. Pausing collection also keeps existing records until you disconnect. We show reported metrics without calculating social-to-sales attribution. We do not send this Meta content to our AI provider. We do not sell Meta data or use it for advertising.
Delete Meta data: sign in, open Social and choose Disconnect. This removes this restaurant's stored Meta connection, pending authorization, saved social history and action receipts from our active database. To revoke Profit Duck's access across every restaurant you connected, also remove Profit Duck in Facebook's Business Integrations settings. Disconnecting does not delete posts or replies already published on Meta. Encrypted credentials can remain in existing infrastructure backups until those backups expire.
If you cannot sign in, or want us to confirm deletion, email support@profitduck.app with the subject “Meta data deletion” and identify your Profit Duck account and connected Page or Instagram username. Do not send passwords or access tokens. After verifying ownership, we will delete the associated Meta connection data and confirm completion within 30 days. This request does not delete your unrelated financial records unless you also request account deletion.
If you enable Cloud Sync for a delivery platform, we run a browser session on our servers that signs in to that platform’s merchant portal to pull your data on a schedule. You type your platform password into the platform’s own login page, streamed through our servers: your keystrokes pass through Profit Duck to reach that page, but we do not log them and never store your password in our own database.
Once you have signed in, that browser profile’s login session cookies are saved on our servers so later syncs can run without you. This happens whenever you connect Cloud Sync and is not optional, because those cookies are what keeps the session alive. We encrypt that snapshot, and the encryption key is not available to the browser process itself. If you additionally accept the browser’s own offer to save your password, that copy is held inside the browser profile under the browser’s standard protection, which is weaker than our own encryption of the session snapshot.
You can disconnect a platform at any time from your settings, which revokes the sync’s credentials and deletes the browser profile from our servers. Removal of the encrypted session snapshot is verified. If a sync happens to be running at that moment the disconnect can fail and report an error; retry it, and contact us if you want us to confirm removal.
Profit Duck includes an optional AI assistant (“Duckworth”) that answers questions about your own business data. When you use it, your question, any images you attach, your recent messages in the conversation, relevant context (such as the page you’re viewing), and the business figures needed to answer are sent to Anthropic, our AI provider, to generate the response. Under Anthropic’s commercial terms, this data is not used to train its models. The assistant is deliberately built without access to your customers’ names or your bank account numbers, and it sees bank transactions only as amounts, dates, vendor names, and categories — though for transactions you haven’t given a clean vendor name, the vendor may appear as the merchant descriptor from your bank statement.
We keep a log of assistant conversations, which we may review to improve answer quality and investigate problems or misuse. You can ask us to delete your conversation history at any time. And the assistant is entirely optional: if you’d rather not use AI at all, ask us and we’ll turn it off for your account — every number in the app is computed without AI either way, so nothing else changes.
We use Plaid Inc. to securely connect your bank account. When you link a bank, your login credentials are entered directly into Plaid and are never seen or stored by Profit Duck. Plaid provides us with the account and transaction data you authorize. Your use of Plaid is also governed by Plaid’s End User Privacy Policy. You can disconnect your bank at any time from your settings.
We use your data solely to provide the service to you — to calculate and display your sales, fees, expenses, tax estimates, forecasts, and reconciliation. We do not sell your data, and we do not use it for advertising.
If you choose to connect the upcoming Google Business Profile integration after release, we will also use the Google data you authorize to display reviews and profile details and publish only the replies and profile changes you confirm, as described above.
We share data only with the service providers that make Profit Duck work — our cloud hosting provider, Plaid (bank connectivity), Square (POS data), Anthropic (AI assistant responses, only when you use the assistant), and our email delivery provider, Resend (your email address and message content, only when we email you) — and only to the extent needed to operate the service. We may disclose data if required by law. Each customer’s data is stored in an isolated, per-account database.
We keep your data while your account is active. If you ask us to delete your account, we do so within 30 days, including removing it from our backups at the next backup cycle. We use reasonable technical and organizational measures to protect it, including encrypted transport, hashed passwords, encrypted storage for supported API tokens, and per-account data isolation. Stored data is also encrypted at rest at the storage layer by our cloud hosting provider. Account backups may contain readable transaction, order, customer, and platform data, so store downloaded backup files securely. No method of storage or transmission is 100% secure, but we work to protect your information.
You can disconnect any connected account at any time, download a full copy of your data from your settings, ask us to turn the AI assistant off for your account, ask us to delete your assistant conversation history, or ask us to delete your account and associated data by contacting us at support@profitduck.app.
Profit Duck is a business tool and is not directed to anyone under 18.
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and where appropriate we’ll notify you in the app.
Questions about privacy? Email us at support@profitduck.app.
© 2026 Profit Duck