QuickCA for Chrome
Effective 17 September 2026 · Last updated 17 September 2026 · Version 1.0
The short version. QuickCA is a working tool for chartered accountants. It shows you your own clients' case details and portal logins beside the Income Tax e-Filing portal, so you are not copying them out of a spreadsheet.
It shows you data you already have access to in your QuickCA account. It collects nothing for us, contains no analytics or advertising of any kind, and never sells or shares your data.
The QuickCA browser extension for Chrome is published by AI Methods, operating from Rajasthan, India ("QuickCA", "we", "us").
| Entity | AI Methods |
| Registered office | AI Methods, Rajasthan, India |
| General contact | hello@aimethods.co |
| Product support | support@aimethods.in · Mon–Sat, 10am–7pm IST |
| Grievance Officer | See section 17 |
This policy covers the QuickCA browser extension for Chrome and nothing else. It is written for the chartered accountants and firm staff who install it.
The extension is a view onto your existing QuickCA account. The wider QuickCA service - the dashboard at quickca.aimethods.co, the WhatsApp intake bot, and the case records behind them - is covered by the AI Methods Privacy Policy. Where the two differ on a point specific to the extension, this document governs; on everything else the AI Methods policy applies.
This document also serves as notice under Section 5 of the Digital Personal Data Protection Act, 2023 in respect of personal data processed through the extension.
This distinction matters legally, so we state it plainly.
In practice this means requests from your clients about their data come to you first. We will support you in answering them; see section 16.
The extension has no password of its own and no login form. When you sign in, it opens the ordinary QuickCA login page in a Chrome-managed window; you complete the same phone-OTP login you already use. QuickCA hands back a single-use code, which the extension exchanges for a session token.
That means the extension never sees your phone number, your OTP, or any credential you type during login. Those are entered on QuickCA's own website, not in the panel. If you are already signed in to QuickCA in that browser, the extension adopts that session silently and no window is shown.
The resulting session is stored by the Firebase Authentication SDK in the extension's own IndexedDB storage, so you stay signed in between browser restarts. Signing out clears it.
The panel reads the cases in your own QuickCA book directly from Google Firestore, using your signed-in session. Firestore's security rules decide what you may read - a firm owner sees their firm's cases, an employee sees only cases assigned to them. The extension cannot widen that.
Depending on what your client submitted and what was extracted from their documents, a case can include: name, PAN, Aadhaar number, email address, bank name and the last four digits of an account, employer name and TAN, gross salary and TDS figures, GSTIN and GST turnover figures, income bracket and tax regime, filing status and acknowledgement number, and the documents themselves.
Sensitive identifiers are masked by default. A PAN, an Aadhaar number and a bank account are displayed masked, with an explicit reveal control. Nothing is unmasked until you ask for it.
Portal passwords are stored encrypted (AES-256-GCM) in QuickCA and cannot be decrypted by the extension - the encryption key exists only on QuickCA's servers and is deliberately not shipped in the extension. When you reveal a password, the panel asks the server, which re-checks that the case is yours and records the reveal against it.
Every reveal is logged with a timestamp, a running count, and which user performed it. A password revealed through the extension is indistinguishable, in that record, from one revealed on the dashboard.
A revealed password is held in the panel's memory only. It is never written to disk, never placed in extension storage, and never logged. It is cleared when you switch client, when you sign out, when the panel closes, and automatically after a period of inactivity (15 minutes by default).
On incometax.gov.in only, a content script watches the page to answer two questions: are you signed in, and whose PAN is the portal showing? It does this by looking at a small set of specific elements - the profile area and the page header - and at the portal's own cached profile entry in that site's browser storage, matching only against a PAN-shaped pattern.
This reading is deliberately narrow. It never scans the whole page, because the authenticated portal displays other people's PANs in search results and tax statements, and matching one of those would show you the wrong client. When it cannot tell, it reports that it cannot tell.
The result - whether the tab is on the portal, whether it looks signed in, and the detected PAN - is passed to the extension's own background worker and held in Chrome's session storage, which is erased when you close the browser. None of it is transmitted to QuickCA or anywhere else. It is used solely to pick which of your clients to show.
The extension runs on no other website. It does not read your browsing history, your tabs, or any other page.
Purposes are limited to the following, and personal data is not processed for any other purpose:
| Purpose | Data used |
|---|---|
| Authenticate you to your QuickCA account | Your QuickCA identity and session token |
| Show your case list and client details | Case records you are already entitled to read |
| Match the open portal tab to the right client | PAN detected on the portal page (local only) |
| Supply a portal login on request | The case's stored credentials, decrypted server-side |
| Maintain an audit trail of credential access | Timestamp, count and identity of the revealing user |
| Remember your preferences | Auto-lock delay, clipboard setting, consent timestamp |
Processing of your own account data rests on the consent you give when you create a QuickCA account and when you accept the notice shown in the extension before any credential is displayed. Processing of your clients' data rests on your engagement with them, as described in section 3. You may withdraw consent at any time by signing out and uninstalling the extension; see section 16.
When you press Auto-fill, the extension types the client's User ID and password into the portal's login fields. It never submits the form. You click Continue and handle the OTP yourself. Nothing is filled unless you press the button, and nothing is filled on a page that is not the portal login.
Copy buttons write the copied value to your clipboard. When the clipboard-wipe setting is on (the default), the extension tries to blank the clipboard 60 seconds after you copy a password - first reading it to confirm it still holds that password, so it never destroys something else you copied in the meantime.
The clipboard is read only for that comparison, only after you copied a secret, and the value is never transmitted anywhere. Because a panel's timers stop when the panel closes, this is best-effort rather than a guarantee, and the setting says so.
| Where | What | Lifetime |
|---|---|---|
| IndexedDB | Your QuickCA sign-in session (Firebase) | Until you sign out |
storage.local | Preferences only: auto-lock delay, clipboard-wipe on/off, and the date you accepted the in-product notice | Until you uninstall |
storage.session | Portal state per tab, including a detected PAN | Erased when Chrome closes |
| Panel memory | Revealed passwords, case details on screen | Until auto-lock, sign-out, or the panel closes |
No client data and no credential is ever written to storage.local. Uninstalling the extension removes all of the above from your computer.
The extension communicates with exactly two destinations:
quickca.aimethods.co) - to complete sign-in, to decrypt a portal password you asked for, and to stream a document you opened.That is the complete list. There are no analytics services, no advertising networks, no error-reporting services, no third-party scripts, and no remotely-loaded code of any kind. The extension ships as a self-contained bundle, as Chrome's Manifest V3 requires.
We disclose personal data to no one else, except where compelled by law, a court, or a competent authority, or to establish or defend a legal claim.
Cross-border processing. QuickCA's services are provisioned on Google Cloud infrastructure in India (asia-south1, Mumbai). Google may process limited operational data outside India in the course of running those services, in accordance with its own terms and any restrictions notified by the Central Government under Section 16 of the DPDP Act.
The extension retains nothing of its own on our servers. Everything it displays is read live from your QuickCA account, and the local copies described in section 9 are transient or are preferences.
When personal data is no longer necessary for the purpose it was collected for, and no legal obligation requires us to keep it, it is erased.
Measures applied to data handled by the extension include:
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal as required by the DPDP Act and the rules under it.
QuickCA's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
| Permission | Why |
|---|---|
sidePanel | The extension is a side panel. |
storage | Your preferences, and per-tab portal state. |
identity | To open the QuickCA login page and receive the sign-in code, without the extension ever handling your credentials. |
activeTab | To know whether the tab you are looking at is the portal. |
clipboardWrite | Copy buttons. |
clipboardRead | Solely to check the clipboard still holds the password before wiping it, so nothing else you copied is destroyed. |
incometax.gov.in | To detect portal sign-in state and fill the login form. |
quickca.aimethods.co | To reach your QuickCA account. |
As a Data Principal under the DPDP Act, 2023, in respect of personal data for which AI Methods is the Data Fiduciary, you have the right to:
To exercise any of these, write to support@aimethods.in from the email or phone number registered on your account. We will respond within the period prescribed by the applicable rules.
If you are a client of a chartered accountant using QuickCA and want to exercise rights over your own tax data, please contact your CA first - they are the Data Fiduciary for that data. If you are unable to reach them, contact us and we will assist.
If you are dissatisfied with how your personal data has been handled, you may raise a grievance with our Grievance Officer:
| Grievance Officer | The Grievance Officer, AI Methods |
| support@aimethods.in | |
| Address | AI Methods, Rajasthan, India |
| Response time | Acknowledged within 72 hours; resolved within 30 days |
If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023 and the rules made under it.
The personal data shown in the panel belongs to your clients. You are the professional holding it, and you are responsible for having their authorisation to hold and use their portal credentials, and for the confidentiality of anything the panel displays. The extension shows this to you on the assumption that authorisation exists; it cannot verify it.
You are also bound by the confidentiality obligations of your profession, including the ICAI Code of Ethics. The extension displays a notice to this effect before it will show any credential, and you can review it again from the settings menu.
QuickCA is a professional tool for practising chartered accountants and their staff. It is not directed at children, we do not knowingly process the personal data of a child through the extension, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
If this policy changes materially, we will update the date and version at the top and, where the change affects how the extension handles data, note it in the extension's release notes and give notice through the product. Continuing to use the extension after a change takes effect means you accept it.
Questions about this policy, or about data the extension has shown you, go to support@aimethods.in.
This policy is governed by the laws of India. Any dispute arising out of it is subject to the exclusive jurisdiction of the courts at Rajasthan, India.