Privacy Policy
Last updated: August 24, 2026
1. Introduction
MultiplyOS LLC ("Company," "we," "us," or "our") operates the Multiply OS platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By using the Service, you consent to the practices described herein.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, password, company name, and profile picture when you register or update your profile.
- Business data: Scoreboard metrics, KPI entries, goals, team member information, meeting notes, and other business content you input into the Service.
- Communication data: Any messages or feedback you send to us directly.
- AI Coach content: The messages you send the AI Coach, together with any images, documents, or voice dictation you attach or record. Voice input is transcribed to text; attached images and documents are used only to answer that request and are not stored by the Service.
2.2 Information from Third-Party Services
When you connect an accounting service (such as Intuit QuickBooks Online), we collect financial data from that service on your behalf, including but not limited to:
- Chart of accounts and account balances
- Profit & Loss reports
- Balance Sheet reports
- Company financial metadata
When you connect a Google account in Marketing HQ, we collect read-only marketing performance data from Google Analytics, Google Ads, and Google Search Console. Section 5.2 sets out exactly which data we read and how it is used.
We access this data only after you explicitly authorize the connection through the third-party service's OAuth process. You can revoke this access at any time.
2.3 Automatically Collected Information
- Usage data: Login timestamps, pages visited, and features used within the Service.
- Device data: Browser type, operating system, and IP address for security and analytics purposes.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Display your business data, metrics, and financial information within the Service
- Generate AI-powered insights and recommendations based on your business data
- Communicate with you about the Service, including updates and support
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
4. How We Share Your Information
We do not sell your personal information. We may share your information only in the following circumstances:
- Service providers: With trusted third-party vendors who help us operate the Service (e.g., cloud hosting, database services), subject to confidentiality obligations.
- AI processing: Your business data may be sent to AI language model providers to generate insights, and AI Coach content — your messages and any attached images, documents, or dictated audio — is sent to third-party AI providers to generate responses: Anthropic (Claude) for chat and image/document understanding, and OpenAI for voice transcription (Whisper) and image generation. These providers process your data solely to fulfil your request under no-training terms and do not retain it to train their models. On-device voice dictation may alternatively be transcribed by your device’s operating-system speech service.
- Legal requirements: If required by law, regulation, or legal process, or to protect the rights, property, or safety of our company, users, or others.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Third-Party Integrations
The Service allows you to connect third-party accounts such as Intuit QuickBooks Online and Google. When you connect a third-party service:
- We access only the data necessary to provide the features you use.
- We store OAuth tokens securely (AES-256-GCM at rest) and use them only to fetch data on your behalf.
- You can disconnect the integration at any time from the Settings page, which stops further data access.
- You can permanently delete every record we hold for an integration via the “Delete all data” control on the Addons page; this revokes our token with the provider and erases synced reports, accounts, and metric mappings for your company.
5.1 Intuit QuickBooks Online — specific disclosures
For QuickBooks Online specifically:
- Data categories synced: Chart of Accounts (names, types, balances), Profit & Loss reports, and Balance Sheet reports — the most recent six months, at monthly granularity. We do not sync individual customer or transaction records.
- Retention: We keep the last six months of monthly reports plus a snapshot of your Chart of Accounts. Older reports are removed automatically on each sync. All QuickBooks data is deleted within 24 hours of disconnecting via “Delete all data,” or within 90 days of account closure.
- AI processor: When you use AI financial insights, the synced financial data is sent to Anthropic (model:
claude-sonnet-4-6) under a no-training agreement. Anthropic does not retain your data for model training and does not share it with third parties. - Independent controller: For data we collect from QuickBooks on your behalf, Multiply OS is an independent controller, not Intuit’s processor. We determine the purposes and means of processing in accordance with this Privacy Policy.
- Not a consumer report: We do not use QuickBooks data as a “consumer report,” and Multiply OS is not a “consumer reporting agency” or “furnisher” under the U.S. Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.).
Third-party services have their own privacy policies. We encourage you to review Intuit's privacy policy at intuit.com/privacy/statement.
5.2 Google user data: specific disclosures
Marketing HQ lets you connect your own Google account so that Multiply OS can show your marketing performance inside your dashboard. This access is read-only. Multiply OS never creates, edits, pauses, or deletes anything in the Google accounts you connect through Marketing HQ. Other Multiply OS features that can connect to Google (for example Google Calendar or Google Sheets reports) request their own, separately consented scopes; the disclosures in this section cover Marketing HQ only.
For the Marketing HQ connection we request the following scopes, and only these:
- Google Analytics (
analytics.readonly): we read report data for the single Google Analytics 4 property you select, covering sessions, users, key events and conversions, and traffic broken down by channel, source, medium, and campaign. This is the narrowest scope the Google Analytics Data API offers for reading reports. - Google Ads (
adwords): Google publishes a single Google Ads scope, whose user-facing description reads “See, edit, create, and delete your Google Ads accounts and data.” Multiply OS uses it exclusively for reading. Every Google Ads request we make is a reporting query. We read cost, impressions, clicks, and conversions at campaign and ad group level for the single Google Ads account you select. We do not create, modify, pause, or delete campaigns, ad groups, ads, budgets, or accounts. - Google Search Console (
webmasters.readonly): we read aggregate search performance for the single verified property you select, covering clicks, impressions, average position, and top queries and pages. - Account identification (
openid,userinfo.email): the email address of the Google account you connect, used only to label the connection so you can see which account is in use.
How we use it. Google data is shown only to authenticated members of your own company, inside your own Marketing HQ dashboard. We do not sell it, use it for advertising, or transfer it to third parties. We do not use it to develop, improve, or train generalized artificial intelligence or machine learning models.
Storage and retention. OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. Synced Google data is stored as daily aggregates scoped to your company and is retained for as long as the integration remains connected. When you disconnect, we ask Google to revoke our token, and we delete the Google Analytics, Google Ads, and Search Console data we synced. Any residual data is removed within 90 days of account closure.
Revoking access. You can disconnect at any time from Settings, Integrations, Marketing sources inside Multiply OS (shown when Marketing HQ is enabled for your company). Whether or not that page is available to you, you can always revoke Multiply OS's access directly from your Google Account at myaccount.google.com/permissions.
Limited Use. Multiply OS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google's own privacy policy is available at policies.google.com/privacy.
6. Data Security
We implement industry-standard security measures to protect your information, including encryption of data in transit (TLS/SSL), encrypted storage of sensitive credentials (OAuth tokens), secure password hashing, and access controls. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. If you close your account, we will delete or anonymize your personal data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Object to or restrict certain processing of your data
- Request a portable copy of your data
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at the email address below.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
MultiplyOS LLC
Email: support@multiplyos.com