QuickCA for Chrome

Privacy Policy

Effective 17 September 2026 · Last updated 17 September 2026 · Version 1.0

The short version. QuickCA is a working tool for chartered accountants. It shows you your own clients' case details and portal logins beside the Income Tax e-Filing portal, so you are not copying them out of a spreadsheet.

It shows you data you already have access to in your QuickCA account. It collects nothing for us, contains no analytics or advertising of any kind, and never sells or shares your data.

1. Who we are

The QuickCA browser extension for Chrome is published by AI Methods, operating from Rajasthan, India ("QuickCA", "we", "us").

EntityAI Methods
Registered officeAI Methods, Rajasthan, India
General contacthello@aimethods.co
Product supportsupport@aimethods.in · Mon–Sat, 10am–7pm IST
Grievance OfficerSee section 17

2. Scope of this policy

This policy covers the QuickCA browser extension for Chrome and nothing else. It is written for the chartered accountants and firm staff who install it.

The extension is a view onto your existing QuickCA account. The wider QuickCA service - the dashboard at quickca.aimethods.co, the WhatsApp intake bot, and the case records behind them - is covered by the AI Methods Privacy Policy. Where the two differ on a point specific to the extension, this document governs; on everything else the AI Methods policy applies.

This document also serves as notice under Section 5 of the Digital Personal Data Protection Act, 2023 in respect of personal data processed through the extension.

3. Who is responsible for what

This distinction matters legally, so we state it plainly.

In practice this means requests from your clients about their data come to you first. We will support you in answering them; see section 16.

4. Signing in

The extension has no password of its own and no login form. When you sign in, it opens the ordinary QuickCA login page in a Chrome-managed window; you complete the same phone-OTP login you already use. QuickCA hands back a single-use code, which the extension exchanges for a session token.

That means the extension never sees your phone number, your OTP, or any credential you type during login. Those are entered on QuickCA's own website, not in the panel. If you are already signed in to QuickCA in that browser, the extension adopts that session silently and no window is shown.

The resulting session is stored by the Firebase Authentication SDK in the extension's own IndexedDB storage, so you stay signed in between browser restarts. Signing out clears it.

5. What the extension reads

Your clients' case data

The panel reads the cases in your own QuickCA book directly from Google Firestore, using your signed-in session. Firestore's security rules decide what you may read - a firm owner sees their firm's cases, an employee sees only cases assigned to them. The extension cannot widen that.

Depending on what your client submitted and what was extracted from their documents, a case can include: name, PAN, Aadhaar number, email address, bank name and the last four digits of an account, employer name and TAN, gross salary and TDS figures, GSTIN and GST turnover figures, income bracket and tax regime, filing status and acknowledgement number, and the documents themselves.

Sensitive identifiers are masked by default. A PAN, an Aadhaar number and a bank account are displayed masked, with an explicit reveal control. Nothing is unmasked until you ask for it.

Client portal credentials

Portal passwords are stored encrypted (AES-256-GCM) in QuickCA and cannot be decrypted by the extension - the encryption key exists only on QuickCA's servers and is deliberately not shipped in the extension. When you reveal a password, the panel asks the server, which re-checks that the case is yours and records the reveal against it.

Every reveal is logged with a timestamp, a running count, and which user performed it. A password revealed through the extension is indistinguishable, in that record, from one revealed on the dashboard.

A revealed password is held in the panel's memory only. It is never written to disk, never placed in extension storage, and never logged. It is cleared when you switch client, when you sign out, when the panel closes, and automatically after a period of inactivity (15 minutes by default).

What it reads from the Income Tax portal page

On incometax.gov.in only, a content script watches the page to answer two questions: are you signed in, and whose PAN is the portal showing? It does this by looking at a small set of specific elements - the profile area and the page header - and at the portal's own cached profile entry in that site's browser storage, matching only against a PAN-shaped pattern.

This reading is deliberately narrow. It never scans the whole page, because the authenticated portal displays other people's PANs in search results and tax statements, and matching one of those would show you the wrong client. When it cannot tell, it reports that it cannot tell.

The result - whether the tab is on the portal, whether it looks signed in, and the detected PAN - is passed to the extension's own background worker and held in Chrome's session storage, which is erased when you close the browser. None of it is transmitted to QuickCA or anywhere else. It is used solely to pick which of your clients to show.

The extension runs on no other website. It does not read your browsing history, your tabs, or any other page.

6. Why we process this data

Purposes are limited to the following, and personal data is not processed for any other purpose:

PurposeData used
Authenticate you to your QuickCA accountYour QuickCA identity and session token
Show your case list and client detailsCase records you are already entitled to read
Match the open portal tab to the right clientPAN detected on the portal page (local only)
Supply a portal login on requestThe case's stored credentials, decrypted server-side
Maintain an audit trail of credential accessTimestamp, count and identity of the revealing user
Remember your preferencesAuto-lock delay, clipboard setting, consent timestamp

Processing of your own account data rests on the consent you give when you create a QuickCA account and when you accept the notice shown in the extension before any credential is displayed. Processing of your clients' data rests on your engagement with them, as described in section 3. You may withdraw consent at any time by signing out and uninstalling the extension; see section 16.

7. Filling in the login form

When you press Auto-fill, the extension types the client's User ID and password into the portal's login fields. It never submits the form. You click Continue and handle the OTP yourself. Nothing is filled unless you press the button, and nothing is filled on a page that is not the portal login.

8. Clipboard

Copy buttons write the copied value to your clipboard. When the clipboard-wipe setting is on (the default), the extension tries to blank the clipboard 60 seconds after you copy a password - first reading it to confirm it still holds that password, so it never destroys something else you copied in the meantime.

The clipboard is read only for that comparison, only after you copied a secret, and the value is never transmitted anywhere. Because a panel's timers stop when the panel closes, this is best-effort rather than a guarantee, and the setting says so.

9. What is stored on your computer

WhereWhatLifetime
IndexedDBYour QuickCA sign-in session (Firebase)Until you sign out
storage.localPreferences only: auto-lock delay, clipboard-wipe on/off, and the date you accepted the in-product noticeUntil you uninstall
storage.sessionPortal state per tab, including a detected PANErased when Chrome closes
Panel memoryRevealed passwords, case details on screenUntil auto-lock, sign-out, or the panel closes

No client data and no credential is ever written to storage.local. Uninstalling the extension removes all of the above from your computer.

10. Who else sees it

The extension communicates with exactly two destinations:

That is the complete list. There are no analytics services, no advertising networks, no error-reporting services, no third-party scripts, and no remotely-loaded code of any kind. The extension ships as a self-contained bundle, as Chrome's Manifest V3 requires.

We disclose personal data to no one else, except where compelled by law, a court, or a competent authority, or to establish or defend a legal claim.

Cross-border processing. QuickCA's services are provisioned on Google Cloud infrastructure in India (asia-south1, Mumbai). Google may process limited operational data outside India in the course of running those services, in accordance with its own terms and any restrictions notified by the Central Government under Section 16 of the DPDP Act.

11. Retention

The extension retains nothing of its own on our servers. Everything it displays is read live from your QuickCA account, and the local copies described in section 9 are transient or are preferences.

When personal data is no longer necessary for the purpose it was collected for, and no legal obligation requires us to keep it, it is erased.

12. Security

Measures applied to data handled by the extension include:

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal as required by the DPDP Act and the rules under it.

13. What we do not do

14. Chrome Web Store Limited Use disclosure

QuickCA's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  1. Allowed use. We use data obtained through the extension only to provide and improve the user-facing features described in the extension's store listing.
  2. Allowed transfer. We do not transfer that data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets, in which case we will obtain consent.
  3. Prohibited advertising. We do not use or transfer that data for serving advertising of any kind, including personalised, retargeted or interest-based advertising.
  4. Prohibited human interaction. We do not allow humans to read that data, unless we have your affirmative consent for specific messages, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymised for internal operations.

15. Permissions, and why each one exists

PermissionWhy
sidePanelThe extension is a side panel.
storageYour preferences, and per-tab portal state.
identityTo open the QuickCA login page and receive the sign-in code, without the extension ever handling your credentials.
activeTabTo know whether the tab you are looking at is the portal.
clipboardWriteCopy buttons.
clipboardReadSolely to check the clipboard still holds the password before wiping it, so nothing else you copied is destroyed.
incometax.gov.inTo detect portal sign-in state and fill the login form.
quickca.aimethods.coTo reach your QuickCA account.

16. Your rights

As a Data Principal under the DPDP Act, 2023, in respect of personal data for which AI Methods is the Data Fiduciary, you have the right to:

To exercise any of these, write to support@aimethods.in from the email or phone number registered on your account. We will respond within the period prescribed by the applicable rules.

If you are a client of a chartered accountant using QuickCA and want to exercise rights over your own tax data, please contact your CA first - they are the Data Fiduciary for that data. If you are unable to reach them, contact us and we will assist.

17. Grievance redressal

If you are dissatisfied with how your personal data has been handled, you may raise a grievance with our Grievance Officer:

Grievance OfficerThe Grievance Officer, AI Methods
Emailsupport@aimethods.in
AddressAI Methods, Rajasthan, India
Response timeAcknowledged within 72 hours; resolved within 30 days

If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023 and the rules made under it.

18. Your clients' data, and your obligations

The personal data shown in the panel belongs to your clients. You are the professional holding it, and you are responsible for having their authorisation to hold and use their portal credentials, and for the confidentiality of anything the panel displays. The extension shows this to you on the assumption that authorisation exists; it cannot verify it.

You are also bound by the confidentiality obligations of your profession, including the ICAI Code of Ethics. The extension displays a notice to this effect before it will show any credential, and you can review it again from the settings menu.

19. Children

QuickCA is a professional tool for practising chartered accountants and their staff. It is not directed at children, we do not knowingly process the personal data of a child through the extension, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

20. Changes to this policy

If this policy changes materially, we will update the date and version at the top and, where the change affects how the extension handles data, note it in the extension's release notes and give notice through the product. Continuing to use the extension after a change takes effect means you accept it.

21. Contact and governing law

Questions about this policy, or about data the extension has shown you, go to support@aimethods.in.

This policy is governed by the laws of India. Any dispute arising out of it is subject to the exclusive jurisdiction of the courts at Rajasthan, India.