Privacy policy
Draft: reviewed by a lawyer before launch. Marked parts are still to be filled in by CompanyOS's founder and a lawyer.
Takes effect on 10 October 2026.
This page says what CompanyOS collects, what it does with it, who else handles it, how long it's kept and how it's deleted. It covers what people type into CompanyOS and what CompanyOS reads from the systems a company connects, such as QuickBooks Online.
Who we are
CompanyOS is provided by Dillingham Capital (“we”). It's a service for businesses: a company signs up, its owner invites the people who work there, and the company may connect its own systems.
For the founder and a lawyer
Our role in law for each kind of data: for the business records a company connects or uploads, the company decides what's collected and why, and we process them for it (service provider or processor); for QuickBooks data, Intuit's developer terms (§12.4) treat Intuit and us as independent controllers. Whether we offer a data processing agreement, and the laws this policy is written for (Intuit's publishing requirements name GDPR, CCPA, LGPD and PIPEDA).
What we collect
- Your account: your name and email address; your company's name, time zone, currency and kind of business; and your role and the areas of the company you work in.
- Signing in: we sign you in with a one-time code sent to your email address. We don't use passwords. To limit guessing, we count code requests and tries under a keyed code made from your address, never the address itself. Counts 24 hours old are deleted the next time anyone asks for a sign-in code, so they can stay longer while nobody does.
- What you do in CompanyOS: the tasks you're given, the decisions and approvals you make with any changes you make before approving, the settings you choose, the flows you turn on, and an audit record of who did what (ids and outcomes, not business content).
- Records from systems you connect. From QuickBooks Online we read customers (the names and details QuickBooks holds for them), invoices, payments, bills, estimates, the chart of accounts and the profit and loss report, every hour while it's connected. We keep a copy of these records as QuickBooks returns them, which only our servers can read, and work out our own standard records from them: invoice numbers, customers' names, amounts, dates and statuses.
- Company documents you add, such as a payment policy or a price list, and the passages and facts drawn from them. PDFs, Word documents and spreadsheets are read by our own servers in an isolated worker, with limits on memory and time. A file built to exhaust the server and an encrypted PDF are refused, and a scanned PDF with no text in it isn't read.
- Field-service files you upload (not available yet). When file import is available, we keep only the columns a person in your company confirms, and never customers' addresses, email addresses or phone numbers, notes, pay, or identity numbers.
- Cookies: only the ones CompanyOS needs to work: your sign-in session (which scripts on the page can't read), the sign-in in progress, the company you last chose and your light or dark setting. We use no advertising or analytics cookies.
Why we use it
We use what we collect to provide CompanyOS to your company. Every field of the standard records we work out from your books has a recorded reason in our software, for example:
- Customers' names, so a person acting on a list can find the customer in their own books.
- Invoice numbers, amounts, due dates and balances, to show what's overdue and to build follow-up lists and their results.
- Payments, to count collections and to hold back reminders when a customer's payment hasn't been applied yet.
- Bills, for bills due this week and to catch a bill entered twice.
- The profit and loss by account and month, for revenue, margin and profit by period.
We also use account and usage records to keep CompanyOS secure and working: limiting sign-in tries, keeping the audit record, and finding faults from logs that carry ids rather than your content.
We don't use your data to train AI models, ours or anyone else's.
One company's data is never shown to or shared with another company.
For the founder and a lawyer
Proposed, for the founder to confirm as a commitment: “We don't sell your data or your customers' data, and we don't use it for advertising.” Nothing in CompanyOS does either today, and Intuit's developer terms (§12.2) forbid selling or making available QuickBooks data for anything that doesn't support the customer's own use of the app.
What CompanyOS changes in QuickBooks
CompanyOS reads your books. It changes something in QuickBooks only to send invoices that QuickBooks shows as never sent, and only after your company's owner has turned sending on and a named person in your company has approved the exact list. QuickBooks then emails each invoice to the addresses already on it in QuickBooks. Intuit's permission screen asks for access to your accounting data as a whole, because QuickBooks has no read-only permission for apps.
AI, and what it sees
- We send data only to AI providers whose terms prohibit training on it, and never to a provider that trains by default unless we've confirmed an opt-out. Our software enforces this: a request to any other provider is refused before anything is sent.
- Records read from your books may be sent to your company's allowed AI provider when an assistant works on a task, for example to write a finding that names a customer. Anthropic is our default unless your company's settings choose another provider we support (today, OpenAI); a provider your company's settings don't allow never receives anything.
- When you type a question in Ask, the question goes to your company's allowed AI provider only to work out which question it is, with our list of what can be asked and the words of the questions your company saved that you can see. Never your records or figures: code works out every answer from your books, as you. Questions you pick from the list, and saved ones, use no AI.
- When you describe a job in Describe a job, your words (up to 4,000 characters, and anything you paste in goes as you pasted it) and your answers to its questions go to your company's allowed AI provider, with our list of approved building blocks and library flows and the names of the areas you work in, so it can propose a flow made only of those blocks. Never your records or figures, or the documents you keep in CompanyOS.
- When you write a rule for a flow in your own words, your words go to your company's allowed AI provider with the flow's settings and the names of the customers on that flow's list (only when every one comes from your books), so it can choose one change to suggest. The people in the area its list goes to are sent only as stand-ins (P1, P2…), never by name, and code first replaces the names and email addresses it recognises of your people who use CompanyOS; anything else you type goes as you wrote it. Code checks the choice, and nothing changes until someone accepts it.
- When someone asks a question about your documents, only the passages that person is allowed to read are sent, each with its headings and its document named only “Doc A”, “Doc B” and so on, never by its title, file name or collection; code checks the answer against them.
- When you upload a document that can hold your company's policies, such as payment terms or a rate card, added as company policy to an official collection, its text is sent once to your company's allowed AI provider so it can point to the sentences that state those policies. Never its title or file name, your books or your other documents. Uploading it is your consent for that document. Code reads every number from your document itself, and nothing is used until a person in your company confirms it.
- When you tell CompanyOS about your company in your own words during setup, what you write goes to your company's allowed AI provider only when you press the button to have it read, with setup's questions and their possible answers, so it can propose answers to them. Code checks each one against your words, nothing is saved until you confirm it, and your words aren't kept. Up to 10 readings a person a day.
- The AI that writes the opening and closing of a payment reminder never receives anything from your books: code fills in every customer detail afterwards, and a person checks, approves and sends each reminder. A second AI checks each reminder against the relevant sections of your policy documents, never their titles or file names, before a person sees it; it never sees your books either.
- No AI sees your customers' email addresses or the list of invoices QuickBooks sends for you.
- Nothing from a row of a file you upload is ever sent to AI: at most counts and totals code works out, and a figure about employees only with at least 3 people behind it.
- AI providers may keep what we send for up to 30 days to monitor abuse. Under a zero-retention agreement they keep nothing, except content flagged for safety review. If your company requires zero retention, we use only providers with which we have such an agreement, and features it covers; requests to anyone else are refused.
- To make repeated requests cheaper, Anthropic keeps the fixed opening of a request we mark in memory for 5 minutes; today that's only our own instructions, with none of your data. OpenAI keeps parts of every request for up to 24 hours, so a company that requires zero retention, or any region but the US, gets no OpenAI at all.
- Our AI providers are US companies. Unless your company requires processing in the US, Anthropic may process a request in any of its regions; where you require the US, we ask Anthropic to keep processing in the US. Processing only in the EU isn't available yet.
| Kind of data | For example | What AI may see |
|---|---|---|
| Your customers' personal data | Customers' names, and keys that stand in for a customer or an address | From your books: only to the AI provider your company allows. From files you upload: never |
| Your employees' personal data | Technicians' names, their hours, and deadlines about a person | From your records and files: never, except counts and totals code works out with at least 3 people behind each. A name someone types themselves (in a question, a rule or a job they describe) goes as they typed it, except the names of people who use CompanyOS that code recognises in a rule, which it replaces |
| Business data | Invoice and job numbers, amounts, dates and statuses | From your books: only to the AI provider your company allows. From files you upload: only counts, totals and the kinds of job they cover, as code works them out |
| System data | Record ids, which system a record came from, and when it was read | Which company, which system and when: never. Ids from your books may travel with the records they belong to |
Who else handles your data
We use these service providers to run CompanyOS. Each handles only what its job needs. We give 30 days' notice before adding any AI provider.
| Provider | What it does | What it handles | Where |
|---|---|---|---|
| Supabase | Database, sign-in and file storage | Everything CompanyOS keeps | [To be filled in: the production database's region] |
| Vercel | Runs the application | Requests as they pass through; logs without your content | US |
| Inngest | Runs background jobs, such as the hourly read of your books | Each job's results, encrypted before they leave our servers so Inngest can't read them; the events that start jobs, which carry ids only; and errors, reduced to their kind | US |
| Anthropic (Claude) | AI: reading, drafting and checking | What a task needs, as described above | US, or any of its regions unless you require the US |
| OpenAI | AI, only if it's set up for your company and your rules allow it | What a task needs, as described above | US |
| Resend | Emails sign-in codes, and notices to your people (and the Monday email) that say only what kind of thing is waiting, with a link to CompanyOS: never what it is | Each email (the address, subject and text: a sign-in code, or our fixed words and a link to CompanyOS; never anything of yours), kept 30 days, and in its backups 7 days more | US |
| Amazon Bedrock | Not used yet: AI for companies that require the EU | Nothing until it's set up | Your region |
| A search provider | Not used yet: search quality for documents, once one has confirmed it won't train on them | Nothing until it's set up | To be chosen |
Intuit. When your company connects QuickBooks Online, we read from it, and send invoices through it if you allow that, on your company's behalf. We don't process your data on Intuit's behalf: Intuit and we each handle it separately, and Intuit's handling is covered by your company's agreement with Intuit.
For the founder and a lawyer
Whether traces go to an outside tracing service in production (only if OTEL_EXPORTER_OTLP_ENDPOINT is set there; they carry ids and outcomes, never prompts or your content): name it here, or remove this note. When we may disclose data to authorities, and what happens to it if the business is sold.
How long we keep it
| Data | How long |
|---|---|
| Your business records and documents | While you are a customer; deleted within 30 days of your deletion request |
| Records read from your books (invoices, payments, bills and the profit and loss) | Replaced each time we read your books; deleted when you disconnect them or switch to another company's books, and with your organization. If QuickBooks refuses our access, hidden at once, and deleted if it refuses again an hour or more later (after 7 days at the latest) |
| Documents you delete | Hidden from the product immediately; permanently removed within 30 days |
| Policy facts the AI proposed from a document, what it couldn't read, and a note of each read | With the document: retired when it's replaced, and removed when it's removed |
| Search indexes and embeddings | Deleted with the document they came from |
| Questions asked in Ask (the question, how it was read and what was asked for; never the answer's figures), seen only by whoever asked | 90 days, then deleted; sooner when they delete one or leave the company |
| How many questions each person typed in Ask today (a count, for the daily limit) | Deleted by a nightly sweep within 2 days after that day ends |
| Each person's document uploads (who, which company, and when; never the file), for the limit on uploads | 48 hours, then deleted the next time anyone uploads (longer while no one does) |
| What you write about your company in setup for the AI to read, and what it proposes from it | Never kept: shown once, and only the answers you confirm are saved, as your setup answers. A count of each person's readings a day, for the daily limit, is deleted by a nightly sweep within 3 days after that day ends |
| Questions your company saved in Ask (the words and what they count, never SQL), seen by whoever can see that area | Until whoever saved one, or the owner, removes it; deleted with your organization |
| Reminders prepared for your customers (with who wrote, checked and approved each) | Kept with the flow run that prepared them; deleted with your organization, and included in its export |
| Diagnostic traces | 30 days; AI prompts and answers are not included by default |
| Background job history at our job provider (Inngest) | As long as Inngest's plan keeps it: 24 hours on its free plan, 7 days on Pro (never more than 14 days); job results in it are encrypted so Inngest cannot read them |
| Backups | Expire within 35 days of deletion |
| Audit records: who did what and when (accepting the terms included), with no business content | Up to 6 years, and deleted with your organization |
| Deletion receipts | 6 years after the deletion; metadata only |
| Sign-in attempts (codes asked for and tries, to limit guessing) | 24 hours, then deleted the next time anyone asks for a sign-in code (longer while no one does); kept under a keyed code, never the email address |
| Things your people asked a flow to do that CompanyOS can't do yet (a short code for each, the area and how many times; never anyone's words or names) | 13 months after it was last asked for, deleted the next time your company records one (longer while no one does) |
| Jobs your people described to build a flow (the words, the AI's questions and their answers, and the trial run's examples, with their amounts, and the marks on them), seen by whoever described it while they can still see its area, and by whoever manages the area | Cleared by a nightly sweep once the draft hasn't changed for 90 days, whether it was turned on, set aside or left open; deleted sooner with the draft or your organization |
| Who covers for whom on a flow (the two people, the dates, and who added or ended it), seen by the two people and whoever can see the flow's area | Kept with the flow, ended cover included, until either person leaves your company; deleted with your organization |
| A record of each AI request (the kind of work, the provider and model, how many tokens, its estimated cost and whether it worked; never what was sent or answered), for your monthly AI budget, seen by the owner and admins | Kept with your organization, and deleted with it |
| Notices we email | Only which item (or which week, for the Monday email), to whom, when, and what Resend reported (delivered, bounced, marked as spam); never the text, which is our fixed words, written when it's sent. Kept with your organization |
| People we've stopped emailing (after a bounce or a spam report) | Who and why, never the address; until they turn notices back on, or their account is deleted |
| Email at our email provider (Resend) | 30 days, in the US; its backups 7 days. A notice holds only the person's own address, our fixed words and a link to our app; one that said what it's about would wait for Resend's written confirmation that it never uses email to train AI |
| Checks of what we read against QuickBooks' own reports | 90 days; a confirmed difference 13 months |
Field-service files, once file import is available
| What | How long |
|---|---|
| The file you upload | Kept encrypted in our database only while its import is open, and deleted as soon as the import is applied or discarded. An import not confirmed within 7 days is discarded, with its file, by the first daily sweep after that (so within 8 days), and so is one confirmed but not applied within 1 day (so within 2 days of its confirmation). Backups hold the encrypted file for up to 35 days, without the key |
| The file's name (it can name a person) | Cleared when its import ends; only the file's type, size and fingerprint stay |
| Example values shown while you check the columns (up to 5 per column, with contact details masked) | Deleted when the import ends, or by the first daily sweep after 7 days (so within 8 days) |
| Rows waiting to be applied | Deleted when the import is applied; anything left behind is swept away every day |
| Import reports (counts, and the numbers of rows left out; never a row's content) | 12 months |
| The column choices you confirmed | 12 months after a file last used them |
| Imported jobs, field-service invoices, memberships and estimates | 36 months after the record's own date (completed, issued, closed or ended) |
| Imported customers | While an imported record still names them |
| Timesheets | 13 months |
| Technicians | 90 days after they last appear in a full import |
| Records a newer full export no longer has | Deleted when that import is applied |
| Retired licence, certificate and filing deadlines | 90 days after they're retired |
| Matches between your field-service tool and your books | Worked out again on every run, and each run's results kept 90 days. Links between one customer's records in the two systems: from the latest run only |
| Your answers to matching questions | Until a record they name is gone, and at most 36 months |
When you disconnect QuickBooks
- Disconnecting in CompanyOS (Setup, Connect QuickBooks) asks Intuit to end our access, tells you whether Intuit confirmed it, deletes our copy of the sign-in keys QuickBooks gave us, and deletes the records we read from QuickBooks, all at once. Tasks already handed out and numbers already worked out stay as they are, as part of your company's history. So do the totals of QuickBooks' own reports kept with our checks of what we read, for as long as the table below says.
- If QuickBooks refuses CompanyOS's access (for example after you remove CompanyOS in QuickBooks), we stop at once: nothing more is read or sent, and the records we read are hidden. We ask QuickBooks again each hour. If it accepts, everything comes back. If it refuses again an hour or more later, we delete the records we read from QuickBooks and our copy of its sign-in keys, and after 7 days we delete them anyway. Your company's owner is told both times, and Getting started says what happened.
- Backups that hold them expire within 35 days.
Deleting your company, and getting a copy
- Your company's owner can have the company and everything in it deleted. All automation stops at once, the data is deleted within 30 days, and the owner receives a deletion receipt listing what was removed and when backups expire.
- The owner can have a copy of the company's records at any time.
- Until both are buttons in CompanyOS, the owner asks us at aaron@dillinghamcapital.com, and we confirm with the owner before deleting anything.
How we protect it
- Everything travels encrypted: the app is served only over https, and our servers reach the database and every provider over encrypted connections.
- QuickBooks' sign-in keys are encrypted by our software with a key only our servers hold, on top of the database's own encryption, and are never sent to a browser or to AI. Background jobs' results are encrypted before they reach Inngest, which sees only ids and the kind of an error in clear.
- Each company's data is kept apart by rules in the database itself. People see only their own areas of the company; only the owner sees every area. Only the owner and admins who can see Finance can connect or disconnect QuickBooks.
- Nothing leaves your company, such as an invoice or a reminder, without a named person's approval.
- Our logs and traces carry ids, not your content.
For the founder and a lawyer
How and when we tell a company about a security incident affecting its data. Our incident runbook (docs/runbooks/incident-response.md) tells Intuit within 24 hours as its terms require; the timeline for telling companies is a commitment the founder makes there.
Your choices
- Your company chooses which AI providers may receive its data, whether to require zero retention, and its region.
- The owner and admins can pause all automation at any time; only the owner turns it back on.
- Your company sets when people must approve actions. Only the owner can reduce review.
- To see, correct or delete your own account details, write to us (below). If you're a customer of a company that uses CompanyOS, ask that company first: it decides what's kept about you, and we'll help it.
For the founder and a lawyer
Rights under the laws that apply (for example California's), and how to exercise them; whether CompanyOS is offered outside the US.
Children
CompanyOS is for businesses and the people who work in them. It isn't meant for children.
Changes to this policy
We'll post any change here with its date, and tell each company's owner before a change that affects their data takes effect.
For the founder and a lawyer
How much notice, and how it's given.
Contact
Write to aaron@dillinghamcapital.com, or by post to Dillingham Capital, 581 Hutchinson Ln, Lewisville, TX 75077.