Privacy Policy

Last updated: 24 July 2026

Who this covers

This policy describes the “Amy” application, a private, internal
integration operated by Xennix LLC. Amy is not offered to the public, is not listed
on the Intuit App Store, and connects only to accounting data belonging to Xennix LLC.

What data Amy accesses

Amy connects to Xennix LLC’s QuickBooks Online company through the Intuit API. It
may read accounting records including customers, vendors, invoices, bills, payments,
accounts, items, journal entries, and financial reports (profit and loss, balance
sheet, cash flow, aged receivables and payables). Amy may also create and update
records such as invoices, estimates, and customers. Amy is not permitted to delete
QuickBooks records.

Amy does not access QuickBooks payroll data, and does not store credit card or
bank account numbers.

Who can use Amy

Access is limited to authorized Xennix LLC personnel through a private,
authenticated internal chat channel. Amy is not accessible to the public.

Where data is stored

Amy runs on computing equipment owned and controlled by Xennix LLC. OAuth
credentials are stored locally on that equipment with restricted file permissions and
are never transmitted to third parties other than Intuit for the purpose of
authenticating API requests.

Third-party processing

Amy uses third-party large language model providers to interpret requests and
produce responses. Accounting information retrieved from QuickBooks may be
transmitted to these providers as part of processing a request. These providers
process the data to generate a response; Xennix LLC does not authorize them to use it
for any other purpose.

No QuickBooks data is sold, rented, or shared with advertisers, data brokers, or
any party other than the processors described above.

Retention and deletion

Conversation records are retained on Xennix LLC equipment and may be deleted at any
time at the company’s discretion. QuickBooks records themselves remain in QuickBooks
Online and are governed by Intuit’s own retention terms.

To disconnect the integration, an authorized user may revoke Amy’s access from
within QuickBooks Online (Settings → Apps → Disconnect), which immediately
invalidates its tokens. Xennix LLC may also delete the stored credentials directly
from its own systems.

Security

OAuth tokens are stored with restricted permissions on company-controlled systems
and are rotated automatically. Amy’s access is scoped to the minimum set of QuickBooks
operations required, and destructive operations (record deletion) are disabled at the
application level.

Changes

This policy may be updated as the integration changes. The revision date above
reflects the most recent update.

Contact

Questions about this policy: admin@xennix.com
Xennix LLC