◉ OmniQB

LEGAL REVIEW DRAFT

Privacy policy

Draft dated · Version review-2026-10-08

Not effective. For owner and legal review.

This draft describes the reviewed implementation and proposed terms. It is not a final policy or an agreement you are asked to accept. No effective date has been set. Contact, retention, rights-request procedures, and final contract provisions require review before publication.

Who operates OmniQB

Brotsky, LLC, a California limited liability company, owns OmniQB. OmniQB connects authorized organizations and selected AI clients to QuickBooks® Online accounting software provided by Intuit®.

This draft covers OmniQB’s handling of account, organization, connection, and requested accounting information. Your organization and the third-party services you select may separately control information under their own policies.

Information and purposes

  • Google sign-in: Google account identifier, name, email address, email-verification status, and profile image establish and display your account. Better Auth manages identity, provider-account records, and sessions. The reviewed sign-in integration does not request Gmail or Drive access.
  • Account and browser data: Session cookies, session identifiers, and authentication records maintain sign-in and protect access. Session records can include IP address and browser user agent. A browser-local preference remembers your light or dark theme.
  • Organizations and invitations: Organization names, membership identifiers, member email addresses, roles, invitation recipients and status, and grant settings support shared workspaces and access management. Authorized teammates can see workspace information according to their role.
  • QuickBooks connections: Company identifiers and names, environment, authorized scopes, access and refresh tokens, and connection status allow OmniQB to connect, refresh access, and disconnect. Optional Intuit profile access retrieves the profile information authorized at connection time.
  • Requested accounting data: Permitted reads retrieve company information, reports, transactions, and records that may contain customer, supplier, employee, contact, and financial details. OmniQB processes these results to answer the requested operation and returns them to the browser or authorized client. The reviewed service does not persist complete accounting report responses in its application state; this does not describe storage by recipients or hosting infrastructure.
  • Access and operational records: Assistant client registrations, consent and grant records, hashed access credentials, event times, actor and target identifiers, and rate-limit data support authorization, recent activity, and abuse protection. Hosting and database services also process requests and operational metadata to run the service.

Where information goes

The hosting architecture uses Vercel to run OmniQB and Neon Postgres to store application and identity data. Google provides sign-in; Intuit provides connected accounting APIs. These providers process the information needed for their respective services. Better Auth is the authentication software used by OmniQB; its use alone does not imply a separate hosted identity provider.

When you authorize an MCP connection and use it from an AI client, the permitted tool results are sent to that requesting client. Depending on your chosen integration, this may be ChatGPT, Claude, Cursor, or an xAI client. Company, personal, and financial information within those results can therefore leave OmniQB and be processed by that provider.

Review the selected provider’s terms, privacy policy, account plan, and data controls before granting access. Consumer, business, and API products may have different retention and training practices. OmniQB does not promise that all clients have the same policies or that revocation removes copies already delivered.

Permissions and stopping access

Organization roles control workspace actions. Assistant grants limit access by organization, company, environment, and allowed operation. Intuit’s connection-level accounting scope is broader than OmniQB’s individual read permissions; granting that scope does not enable unavailable accounting writes or payments in OmniQB.

An authorized owner or administrator can revoke an assistant grant or disconnect a company in the workspace. Disconnect removes local connection access and attempts provider revocation. If OmniQB reports that upstream revocation is unconfirmed, disconnect OmniQB through Intuit’s Connected Apps controls as well.

You can also review or remove Google access in your Google Account connections. Removing provider access is separate from deleting an OmniQB account or existing records. Signing out does not revoke an assistant grant authorized for offline access.

Storage, deletion, and requests

Connection credentials and application state are encrypted in storage by the application. Identity and assistant OAuth records are stored separately; they are not all covered by that same encrypted state envelope. Audit history is bounded in the reviewed implementation and is not a permanent record.

Revocation stops future authorized access through the affected grant or connection; it does not delete all membership, identity, audit, provider, or backup records. A verified contact channel, retention schedule, and procedure for access, correction, and deletion requests have not yet been approved for this draft. No deletion deadline or completed account-deletion service is promised here.

Before this policy becomes effective, Brotsky, LLC must publish a working request channel and explain identity verification, applicable rights, necessary record retention, backup handling, and limits on deleting information already shared with others.

Security and developing features

Reviewed controls include organization and environment checks, scoped assistant grants, encrypted connection state, and authorization checks before returning protected results. No system can guarantee complete security. OmniQB has not completed a SOC 2 audit; these implementation descriptions are not independent assurance.

File uploads are being developed separately and are not a live capability covered by this reviewed release. Storage, scanning, and cleanup decisions require review before uploads are enabled. Draft write proposals do not authorize changes to accounting records.

Policy versions

The date above identifies this review draft, not an effective date. A final publication must identify its effective date and explain how material changes are communicated, including any additional authorization needed for new data uses.

Independent product

OmniQB is an independent product and is not affiliated with, endorsed by, or sponsored by Intuit or QuickBooks.

Intuit and QuickBooks are registered trademarks of Intuit Inc. References identify compatible third-party services.