Privacy Policy

SMG AI OS · Effective 2026-08-18 · Version 1.0

This policy describes how SMG Engineering, LLC ("SMG", "we") handles information in SMG AI OS, our internal business operations application. It covers the application's connection to Intuit QuickBooks Online ("QuickBooks").

1. Who this application serves

SMG AI OS is an internal tool. It is used only by SMG personnel, on SMG-controlled hardware, to view SMG's own business data. It is not offered to the public, we do not create accounts for third parties, and there are no external users. If you are not an SMG employee or contractor acting in that capacity, this application is not intended for you.

2. What we access from QuickBooks

The application connects to a single QuickBooks company: SMG's own. It requests the accounting scope (com.intuit.quickbooks.accounting) and reads:

3. Read-only access

The application does not write to QuickBooks. It cannot create, modify, void, delete, or send invoices, bills, payments, or any other record. This is enforced in the software itself, by a client that has no mutating capability, rather than by configuration or policy alone.

4. What we store, and where

5. Who we share it with

No one. We do not sell, rent, trade, or disclose QuickBooks-derived data to third parties. We do not use it for advertising. We do not use it to train machine learning models. There are no sub-processors handling this data.

6. Network transit

Requests to Intuit's Accounting API travel over TLS directly between SMG-controlled hardware and Intuit. Where SMG enables remote access to the application for its own personnel, that access is fronted by Cloudflare Access and Cloudflare Tunnel, and traffic transits Cloudflare's network in encrypted form. No other third party is in the data path.

7. Retention and deletion

Derived figures are written to local log files on SMG-controlled hardware and are retained until deleted. We do not retain a copy of your underlying QuickBooks records.

You may disconnect the application at any time from QuickBooks under Settings → Apps → Disconnect. On disconnection, or on request, we revoke the authorization tokens with Intuit, delete them from the Keychain, and delete the local files containing derived figures.

8. Security

Credentials are held in the operating system keychain rather than in files. Application access requires authentication. Where remote access is enabled it additionally requires Cloudflare Access authentication. Access to the underlying hardware is limited to SMG personnel.

9. Children

This application is a business tool and is not directed to children. We do not knowingly collect information from anyone under 13.

10. Changes

If this policy changes materially, we will update the version and effective date above.

11. Contact

SMG Engineering, LLC
Email: admin@smgeng.com