OneManOS Privacy Policy
Version 1.0 · Effective August 14, 2026 · Last reviewed August 14, 2026
OneManOS (“we”, “us”) is a bookkeeping and job-management service for small construction and trades businesses, operated as a sole proprietorship in Ontario, Canada. This policy explains what personal information we collect, why, where it lives, who processes it, how long we keep it, and the rights you have over it. It is written to be read, not skimmed past — it is short because the truth is short.
Who is responsible
The person accountable for personal information at OneManOS (our Privacy Officer) is Anderson dos Santos Ferreira, Owner. For any privacy question, request, or complaint: adsf.anderson@gmail.com.
What we collect, and why
- Your account: email address and password (password handled by our authentication provider; we never see it in plain text).
- Your business records: the bookkeeping data you enter — invoices, quotes, expenses, income, receipts (including photos you upload), jobs, schedules, and the contact details of your clients, vendors, and subcontractors. This exists solely so the app can do its job for you.
- Payroll and tax identifiers: if you use payroll features, your employees’ details including Social Insurance Numbers (required for T4 slips) and identity documents they upload, and your subcontractors’ SIN or business numbers (required for T5018 reporting). SINs are stored encrypted (AES-256-GCM) and are never shown in bulk lists or logs.
- Bank account data via Plaid: if you connect a bank account, we receive your transactions (date, description, amount) and balances from Plaid Inc. See the Plaid section below.
- Early-access form: if you fill in the form on our landing page, we keep the name, company, trade, and email you provide, only to contact you about the product.
We collect nothing beyond what the features you use require, and we never sell personal information — yours, your clients’, or your employees’ — to anyone, for any purpose.
Bank connections (Plaid)
Bank connections are powered by Plaid Inc. You sign in on your bank’s own page; we never see or store your banking credentials. Through Plaid we receive your account transactions and balances, used only to keep your books reconciled against your bank. Plaid’s handling of your data is described in Plaid’s End User Privacy Policy, and you can view and manage what Plaid holds about you at my.plaid.com. You can disconnect a bank at any time in Settings → Bank Accounts; disconnecting revokes our access with Plaid and removes pulled transactions that you never booked into your records. If you revoke access at your bank or through Plaid directly, we detect that and do the same.
AI features — what leaves the app
Some features use an AI model (provided by Anthropic) to save you typing. In plain terms, here is exactly what gets sent, per feature, only when you use that feature:
- Receipt scanning: the receipt photo you scan is sent to the AI to read the vendor, amounts, and items.
- Bank statement import (text): the statement text is scrubbed first — SINs, card numbers, account numbers, and address blocks are removed before anything is sent.
- Bank statement import (photo/vision): because a page image cannot be scrubbed, this mode is off until you explicitly agree in the app the first time you use it.
- Budget advisor: summarized spending by category, vendor names, and your city/province, to produce advice and local price comparisons.
This data is processed to provide the feature and is not used by us for advertising or sold to anyone. If you don’t use these features, nothing is sent.
Where your data lives, and who processes it
Each customer’s bookkeeping data lives in its own fully isolated database — there are no shared tables between customers. Our service providers (“processors”), each used only for the purpose stated:
- Turso — hosts your isolated bookkeeping database (encrypted at rest, AES-256).
- Supabase — login/authentication, and storage of uploaded files (receipt photos, employee documents) in private, per-customer folders.
- Vercel — hosts and serves the application.
- Plaid — bank connections, as described above.
- Anthropic — AI features, as described above.
- Google — sending email you compose in the app through your connected Gmail account, and address autocomplete on address fields.
- ClickUp — only if you connect it, receives job names and numbers for task syncing.
Storage outside Canada: your bookkeeping database (Turso), the application host (Vercel), and the Plaid, Anthropic, and Google services process data on infrastructure in the United States; login and uploaded files (Supabase) are hosted in Canada. While information is in the United States it is subject to the laws of that jurisdiction, including access by its courts, law enforcement, and national security authorities under its lawful process. We protect it in transit and at rest with encryption regardless of where it sits.
How we protect it
- One isolated database per customer — no cross-customer access paths exist.
- All traffic encrypted in transit (TLS 1.2+); databases encrypted at rest.
- SINs and bank-connection credentials additionally encrypted at the application level (AES-256-GCM).
- Access to production infrastructure is limited to the owner and protected by multi-factor authentication.
- No analytics, advertising, or tracking scripts — the only cookies are the ones that keep you signed in.
How long we keep it
- While your account is active: your records are kept because that is the product — your books.
- If you delete your account (Settings → Security → Danger Zone): your entire database, uploaded files, bank connections, and login are permanently destroyed, immediately. This is real deletion, not archiving. Note that Canada Revenue Agency rules require you to keep business records for six years from the end of the last tax year they relate to — that duty is yours and survives deleting the account, so export what you need first.
- Working data: expired statement-import review batches are purged automatically; internal change logs are kept for up to 24 months; records of any security incident are kept at least five years, as regulators require.
Your rights
You can access, correct, export, and delete your information. Most of this is self-serve in the app; for anything else, email the Privacy Officer above and you will get a written response within 30 days. You may withdraw consent at any time (which may mean some features, like bank connections, stop working). If you believe we have handled your information improperly and we have not resolved it, you may complain to the Office of the Privacy Commissioner of Canada (or, for Quebec residents, the Commission d’accès à l’information).
People whose data you enter
As a customer, you enter information about your own clients, employees, and subcontractors. You are responsible for having the right to do so. Where the app collects information directly from your employees (the emailed onboarding form), that form links to this policy so they know how their information is handled: it is stored only in your business’s isolated database, used only for payroll and government filings you prepare, and protected as described above.
If something goes wrong
If a security incident creates a real risk of significant harm, we will notify the affected people and the required regulators (the OPC, Quebec’s CAI where applicable) and our bank-data partner Plaid, promptly and honestly, and keep the records of the incident the law requires.
Changes to this policy
We review this policy at least annually (the “last reviewed” date above) and update it whenever how we handle data actually changes. Material changes are versioned, and continuing to use the service after a change requires accepting the new version.
See also our Terms of Service.