ProductAI workflowsSavingsIntegrationsVoicePricing
Sign inStart free
FiscalOS/Privacy

Privacy

Privacy Policy

How FiscalOS collects, uses, protects, retains, and shares information across accounting, tax, payroll, banking, and Maya AI chat and voice — including tax return information, bank data, and your privacy rights.

Entity
Dexcon Capital LLC d/b/a FiscalOS, 3702 W Spruce St #1058, Tampa, FL 33607
Effective
July 29, 2026
Last updated
July 29, 2026
Contents
In plain terms1Who we are and what this policy covers2The two kinds of information in FiscalOS3Information we collect4How we use information, and our legal bases5Maya AI and automated processing6Tax return information and IRC §72167Bank and financial account data8Voice calls, recording, and consent9How we share information10Cookies and similar technologies11How we protect information12Retention and deletion13International data transfers14Your privacy rights15Children16Changes to this policy17Contact us

In plain terms

A short orientation before the full document.

FiscalOS holds two different kinds of information, and they are governed differently. Account Data is the information about you and your subscription — we decide how that is used. Company Records are your books: ledgers, invoices, bills, payroll, tax figures, bank activity, uploaded documents, and the people named in them. We process Company Records on your instructions, for you, and for no independent purpose of our own.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not train AI models on your Company Records or your tax return information.

Maya AI drafts work and cites its sources. A proposal is not a posted entry. Nothing enters your books until an authorized person at your company approves it, so there is no automated decision that produces legal or similarly significant effects on you without human review.

Two things in this policy are unusual and worth reading in full: Tax return information and IRC §7216, because tax data carries its own federal consent regime; and Voice calls, recording, and consent, because Maya can hold a live spoken conversation.

This summary is provided for convenience and is not part of the agreement. The numbered sections below govern.

1Who we are and what this policy covers

Dexcon Capital LLC, a Florida limited liability company doing business as FiscalOS ("FiscalOS," "we," "us," or "our"), operates the FiscalOS fiscal operating system for accounting, tax, invoicing, expenses, banking, payroll, planning, controls, and audit. FiscalOS is a registered fictitious name of Dexcon Capital LLC; the contracting party is always Dexcon Capital LLC.

This policy applies to the FiscalOS marketing site at fiscalos.ai, the authenticated FiscalOS application, the Maya AI chat and live voice capabilities, token-scoped customer and vendor portals, printable invoices and payslips, the user-acceptance-testing workspace, our background processing jobs, and our email and support channels (together, the "Service").

This policy does not apply to the independent practices of third parties you choose to connect — your bank, your card processor, your accounting-software provider, or your own accountant. Their handling of your information is governed by their own terms and privacy notices.

Our use of the Service is also governed by the Terms of Service. Where a definition appears in both documents, the Terms of Service controls.

2The two kinds of information in FiscalOS

FiscalOS is business software. Almost everything sensitive inside it belongs to a company, not to us. Understanding which of the two categories your information falls into tells you who is accountable for it and where to direct a request.

Account Data
Information about the customer relationship: your name and work email, authentication and two-factor credentials, company profile and role, organization membership, subscription and billing details, support correspondence, product-usage events, and security logs. For Account Data we act as a controller under the GDPR and as a business under the CCPA. This policy describes those practices.
Company Records
The financial substance of a workspace: chart of accounts, journal entries, invoices, quotes, bills, purchase orders, expenses and receipts, bank and card activity, reconciliations, payroll and time records, tax figures and workpapers, fixed assets, inventory, projects, budgets and forecasts, close and audit evidence, uploaded source documents, and the personal information of your customers, vendors, employees, and contractors contained in them. For Company Records we act as a processor under the GDPR and a service provider under the CCPA, acting on the documented instructions of the customer that controls the workspace.
If you are an employee, customer, or vendor of a FiscalOS customer

Your information is in FiscalOS because a business you deal with put it there. That business, not FiscalOS, decides what is collected, how long it is kept, and whether it is corrected or deleted. Please direct access, correction, and deletion requests to that business. If you contact us, we will refer you to them and assist them in responding, as our customer agreement requires.

3Information we collect

3.1Information you provide directly

  • Account and identity: name, work email address, password (stored only as a salted hash, never in readable form), two-factor authentication enrollment and recovery data, profile photo if you upload one, and your language, theme, and notification preferences.
  • Company profile: legal and trading name, business address, entity type, fiscal-year and accounting-method settings, base currency, chart-of-accounts configuration, and approval-policy choices.
  • Tax identifiers: employer identification numbers, taxpayer identification numbers, and state registration numbers you enter for filing preparation and 1099 or payroll workpapers. These fields are encrypted at rest with authenticated encryption and are never written to application logs.
  • Organization and invitations: the email addresses you invite, the role you assign, and the acceptance record.
  • Billing: the plan you select, billing contact and address, and tax-exemption status. Card and bank-account numbers are entered directly with our payment processor and are never transmitted through or stored on FiscalOS servers.
  • Support, feedback, and testing: the content of messages you send us, and — in the user-acceptance-testing workspace — the test runs, evidence, and tickets you submit.

3.2Company Records you or your connections supply

Company Records reach FiscalOS in four ways, all of them initiated by you:

  1. You enter them. Invoices, bills, journal entries, employees, pay rates, hours, mileage, assets, budgets, and every other document you create in the product.
  2. You upload files. Bank and card statements, receipts and invoices as images or PDFs, CSV, OFX/QFX, and CAMT.053 files, and supporting evidence attached to close and audit workpapers. Uploads are size-capped, validated by declared type and file signature, checksum-addressed, scoped to your company, and stored on encrypted volumes outside the application release.
  3. You connect a bank or card feed. With your authorization, our aggregation provider returns account balances, transactions, and account metadata. See Bank and financial account data.
  4. You import from another accounting system. With your authorization, we read a trial balance and related records from QuickBooks Online or Xero for a review-first migration. Imported data is staged for your review; it is not posted to your ledger automatically.

We may also derive information from Company Records in the ordinary course of providing the Service — for example, optical character recognition on a receipt image, a proposed expense category, a variance explanation, a reconciliation match, a depreciation schedule, an anomaly finding, or a hash-chain verification result.

3.3Maya AI conversations, voice audio, and transcripts

  • Chat: the messages you send Maya, the conversation title and history you choose to keep, the tool results returned during a turn, and any proposal created as a result.
  • Live voice: your microphone audio while a call is active, the model's spoken response, and the machine transcription used to display captions. Voice is described separately in Voice calls, recording, and consent.
  • Personalization: the preferences and memories you explicitly save so Maya can work the way your company works. Saved memories are treated as data, never as instructions capable of overriding our security, tenancy, citation, or approval rules.
  • Quota and telemetry: call duration, token and minute consumption, model and voice identifiers, and error codes, used to meter usage, enforce limits, and diagnose failures. Ephemeral voice credentials and session-resumption handles are treated as secrets and are never logged.

3.4Information collected automatically

  • Log and security data: IP address, request time, method and path, response status, user agent, and referrer, together with authentication events, failed sign-in attempts, rate-limit trips, role-gate denials, and administrative actions.
  • Device and session data: browser and operating-system family, viewport and locale, and the session identifier held in an essential cookie.
  • Product events: a fixed, closed list of interface events — for example, a call to action clicked, a plan selected, an onboarding step completed, or a Maya call started — with a fixed, closed list of allowed properties. These events are collected first-party by FiscalOS. They contain no financial amounts, no account numbers, and no free-text content. Collection is suppressed entirely when your browser sends a Global Privacy Control or Do Not Track signal.
  • Access-gate data: our production hostname sits behind an identity-aware network gate, which records the identity that passed the policy and the request metadata associated with it.

3.5What we do not collect

Stating the absence of a practice is as informative as describing one. We do not:

  • place advertising, retargeting, or cross-site tracking cookies, or embed third-party analytics, session-replay, heatmap, or advertising pixels on any FiscalOS surface;
  • buy, rent, or append personal information from data brokers or list vendors;
  • create, extract, or store a voiceprint, faceprint, or any other biometric identifier — Maya's live voice produces audio and text, never a biometric template;
  • collect precise geolocation;
  • ask for or use special-category data (health, race, religion, sexual orientation, union membership, genetic or biometric data) as part of the Service. Where such information appears incidentally inside a document you upload, we process it only as part of that document;
  • knowingly collect information from anyone under 18; or
  • store payment-card numbers, bank login credentials, or bank account and routing numbers you use to pay us.

4How we use information, and our legal bases

We use information for the purposes below and for no undisclosed purpose. Where the GDPR or UK GDPR applies, the legal basis for each purpose is stated in brackets.

  • Provide the Service — maintain your workspace, run the accounting, tax, payroll, banking, planning, close, and reporting features you use, execute Maya read tools, and create proposals for your review. [Performance of a contract; for Company Records, processing on the controller's instructions.]
  • Authenticate and authorize — verify who you are, apply your role, enforce approval policies, and keep company boundaries separate. [Contract; legitimate interests in securing the Service.]
  • Protect the Service — detect and investigate abuse, fraud, credential stuffing, and unauthorized access; enforce rate limits; verify the integrity of the accounting hash chain. [Legitimate interests; legal obligation.]
  • Communicate — send transactional messages such as invitations, approval requests, reminders, close and collections notices, security alerts, and billing notices. [Contract; legitimate interests.]
  • Support and diagnose — answer your questions, reproduce and fix defects, and improve reliability. [Contract; legitimate interests.]
  • Bill and account — apply your plan, meter usage-based capabilities, collect fees, and keep the tax and accounting records we are required to keep. [Contract; legal obligation.]
  • Improve the product — analyze aggregated and de-identified usage patterns, error rates, and performance to decide what to build and fix. We do not use the content of your Company Records or tax return information for this purpose. [Legitimate interests.]
  • Market responsibly — send product news to a business contact who asked for it, and measure whether public pages are useful using first-party events only. You can unsubscribe from every marketing message; transactional messages are part of the Service. [Consent where required; otherwise legitimate interests.]
  • Comply and defend — meet legal, tax, and recordkeeping obligations, respond to lawful requests, and establish or defend legal claims. [Legal obligation; legitimate interests.]

Where we rely on legitimate interests, we have balanced that interest against your rights and concluded the processing is necessary, proportionate, and consistent with what a business user of accounting software would reasonably expect. You may object at any time; see Your privacy rights.

5Maya AI and automated processing

5.1Which models process your information

Maya is built on third-party foundation models operated under contract. Text conversations are processed by an open-weight model served through Fireworks AI, with provider-side retention explicitly disabled on every request. Live voice calls are processed by Google's Gemini Live native-audio model, which your browser reaches directly using a short-lived ephemeral token that is constrained to Maya's model, tools, instructions, and voice and expires within thirty minutes. Retrieval of accounting and tax reference material, transcription of recorded audio, one-shot speech playback, and document optical character recognition run on infrastructure we operate ourselves.

Only the information needed for the turn in progress is sent to a model: your message, the relevant conversation history, and the results of the tools that ran. A model receives data scoped to your company and never data belonging to another customer.

5.2We do not train models on your data

We do not use your Company Records, your tax return information, your uploaded documents, your Maya conversations, or your voice audio to train, fine-tune, or otherwise improve any AI model, whether ours or a provider's. Our provider agreements are configured for zero retention and no training on inference data, and we do not rely on a provider's default setting to achieve that.

5.3Proposals, approval, and automated decisions

Maya may read your records and prepare work. When Maya prepares something that would change your books — a journal entry, a categorization, an invoice or bill draft, a reconciliation match, a depreciation run, or a payroll run — it is stored as a pending proposal. An authorized person must approve it. On approval, the server re-validates the stored payload under your company's access controls and applies it as that person's action, with the proposal and the approver both recorded.

Consequently, FiscalOS does not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects on you. A human decision always stands between an AI draft and a financial outcome. We do not use automated processing to profile you, to price your subscription, or to evaluate your creditworthiness.

5.4Accuracy, citation, and limits

Maya cites the source behind guidance on accounting treatment and tax rules, and surfaces uncertainty rather than concealing it. Even so, model output can be incomplete or wrong. Maya prepares work for review; it is not a licensed accountant, tax preparer, or attorney, and its output is not professional advice. See the Terms of Service.

You are interacting with an artificial-intelligence system whenever you use Maya chat or a Maya call. We disclose this in the interface and confirm it whenever you ask.

6Tax return information and IRC §7216

Read this section if you use the tax features

Federal law places a separate, criminal-backed restriction on the disclosure and use of tax return information by anyone who provides software or auxiliary services used in preparing returns. We apply that restriction to FiscalOS by default, in your favor.

Internal Revenue Code §7216 and Treasury Regulation §301.7216-1 restrict how tax return information may be disclosed or used by tax return preparers, a definition that reaches persons who develop or provide software used in connection with preparing or filing a return. Where FiscalOS falls within that definition, we treat the following as binding:

  • Purpose limitation. We disclose and use tax return information only as needed to provide the Service you asked for, and as otherwise permitted without consent under Treasury Regulation §301.7216-2 — for example, disclosure to an auxiliary service provider located in the United States that processes information on our behalf under contractual confidentiality obligations.
  • No use for marketing, product development, or model training. We do not use tax return information to solicit other business from you, to build or improve products, or to train any AI model.
  • No disclosure to anyone else without your consent. Any disclosure or use beyond what the regulation permits requires your knowing, voluntary, written consent, obtained in a separate document that satisfies the form and mandatory-language requirements of Revenue Procedure 2013-14 and identifies the intended recipient. Agreeing to this policy or to the Terms of Service is not, and is never treated as, §7216 consent.
  • United States processing. The no-consent exception for auxiliary service providers applies only to a provider located in the United States; a disclosure to a provider outside the United States requires your consent under Treasury Regulation §301.7216-3. We therefore keep tax return information with providers that process it in the United States, and we will not send it outside the United States without that consent. One exception is stated plainly below.
  • Maya live voice is not a channel for tax return information. Live calls run on Google's Gemini Live endpoint, which Google processes globally and does not offer under a United States residency commitment. Do not supply return data, taxpayer identification numbers, or filing positions during a call. Use the workspace and Maya chat for tax work, where processing stays with United States providers.
  • Safeguards. We maintain a written information security program consistent with the Gramm-Leach-Bliley Act, the FTC Safeguards Rule at 16 C.F.R. Part 314, and IRS Publication 4557, including access controls, multi-factor authentication, encryption in transit and at rest, logging, and vendor oversight.

FiscalOS prepares tax estimates, workpapers, and supporting schedules with rule-pack provenance. It is not an electronic return originator, does not transmit returns to the IRS or any state, and does not sign returns. Preparing and filing a return remains yours or your tax professional's responsibility.

7Bank and financial account data

When you connect a bank or card account, you authenticate directly with your financial institution through our aggregation provider's interface. Your online-banking username and password are never shown to, transmitted through, or stored by FiscalOS. We receive an access token, which we hold encrypted with authenticated encryption, plus the account metadata, balances, and transactions you authorized.

  • Access is read-only. FiscalOS cannot move money, initiate a transfer, or make a payment from a connected account.
  • Feed data is staged for review. An incoming transaction becomes a candidate for matching and categorization. It never posts to your ledger without a human decision, and no external provider posts to your ledger.
  • You can disconnect a feed at any time in Banking, which revokes our access token. Records already imported into your books remain, because they have become part of your accounting history.
  • We treat this information as customer information under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule and secure it accordingly.

Your rights against your own financial institution regarding access to your account data are governed by that institution and by federal law, including the framework being developed under §1033 of the Dodd-Frank Act. Nothing in this policy limits those rights.

8Voice calls, recording, and consent

Maya can hold a live spoken conversation. A call starts only when you press Call Maya. While a call is active, your microphone audio is streamed from your browser to the voice model, the model's spoken reply is played back to you, and a machine transcription is produced so captions can be displayed.

  • We do not retain call audio. Audio is processed in transit to generate the response and is not stored by FiscalOS as a recording. The provider is contractually configured not to retain it.
  • Transcripts. Captions are generated for the call in progress. Where a conversation is saved to your history, the saved record is text, kept under the retention rules in Retention and deletion.
  • No voiceprint. We do not create, derive, or store a biometric voice template, and we do not use your voice to identify you.
  • Others in the room. Florida — where we are established — and a number of other states require the consent of every party to a recorded conversation. Do not start or continue a Maya call while a third party is audible unless everyone present has been told and agrees. You are responsible for obtaining that consent.
  • Declining. Voice is optional. You can use FiscalOS entirely through the interface and Maya chat. Ending a call stops capture, disconnects the microphone, and stops every media track.
  • Processed globally. Unlike the rest of FiscalOS, the live voice endpoint is processed by Google without a United States residency commitment. Keep tax return information out of calls, as Tax return information and IRC §7216 explains.
  • Metering. We record call duration and usage for quota enforcement and billing. An abandoned call is conservatively metered up to the session cap so that usage cannot be understated.

9How we share information

We do not sell your personal information

We have not sold personal information, and we have not shared personal information for cross-context behavioral advertising, in the preceding twelve months or at any time. We do not sell or share the personal information of anyone under 16. There is no financial incentive program.

We disclose information only in the following circumstances:

  • Inside your workspace. Other members of your company see information according to their role. An administrator or owner can see workspace configuration, membership, billing, exports, and audit history.
  • To recipients you direct. Anyone you send an invoice, statement, portal link, payslip, or 1099 workpaper to receives the information in that document, through a token-scoped link.
  • To your accountant. If you invite an external accountant to your workspace, they see what their role permits.
  • To service providers and processors. The vendors listed below, each under a written contract limiting them to processing on our instructions, with confidentiality and security obligations, and — for a service provider under the CCPA — a prohibition on retaining, using, or disclosing the information for any other purpose.
  • For legal reasons. To comply with a law, subpoena, court order, or other lawful request; to enforce our terms; or to protect the rights, property, or safety of FiscalOS, our customers, or the public. We assess each request, disclose only what is required, and notify the affected customer unless legally prohibited.
  • In a corporate transaction. In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to this policy continuing to govern the information transferred and to notice being given before any material change.
  • With your consent. Anywhere else you ask us to.
Service providers and subprocessors
ProviderWhat it supportsInformation involvedLocation
Cloudflare, Inc.Network delivery, TLS, DDoS protection, and the identity-aware access gate in front of productionRequest metadata, IP address, and the identity that passed the access policyUnited States and global edge
Contabo GmbHHosting for the application, its database, stored documents, and background processingAll Company Records held in the Service, including ledger data, documents you upload, and account informationUnited States (processing and storage); provider incorporated in Germany
Fireworks AI, Inc.Maya text conversationsConversation content and tool results for the turn in progress; retention disabled on every requestUnited States
Google LLCMaya live voice calls (Gemini Live native audio)Call audio in transit, model audio output, and output transcription; not retainedGlobal — no United States residency commitment on this endpoint
Plaid Inc.Bank and card feed aggregation, when you connect an accountInstitution credentials entered directly with Plaid, account metadata, balances, and transactionsUnited States
Stripe, Inc.Invoice payment acceptance for your customers, and FiscalOS subscription billingPayment card and bank details entered directly with Stripe, payment amounts, and statusUnited States
Amazon Web Services, Inc. (Amazon SES)Transactional email deliveryRecipient address, subject, and message content of transactional emailUnited States
Intuit Inc. / Xero LimitedReview-first migration from QuickBooks Online or Xero, when you authorize itTrial balance and related accounting records you authorize us to readUnited States (Intuit); New Zealand and United States (Xero)

Credential-dependent providers are readiness-gated: where production configuration is incomplete, the feature is unavailable and no data flows to that provider. Retrieval of accounting and tax reference material, document optical character recognition, recorded-audio transcription, one-shot speech playback, and the FiscalOS database and file storage run on infrastructure we operate ourselves and are not disclosed to a third party.

We will post material changes to this list on this page before they take effect. To be notified of subprocessor changes, write to [email protected].

10Cookies and similar technologies

FiscalOS uses only cookies and local storage that are strictly necessary to operate. There is no advertising, retargeting, or third-party analytics technology on any FiscalOS surface, so there is no consent banner and nothing to opt out of for advertising purposes.

Cookies and local storage used by FiscalOS
PurposeWhat it holdsLifetime
Authenticated sessionA signed session identifier issued at sign-in, plus cross-site request forgery protectionSession or until sign-out and expiry
Access gateThe authorization token issued by the identity-aware gate in front of productionAs configured by the gate policy
Interface preferenceLight or dark theme, sidebar and navigation statePersistent until you clear it
Portal accessThe scoped token in the link you were sent, for a customer or vendor portal sessionLimited to the token's validity

We honor the Global Privacy Control and Do Not Track browser signals. When either is present, first-party product-event collection is suppressed entirely. Because we do not sell or share personal information for advertising, no other opt-out is required for those signals to be fully effective.

11How we protect information

We maintain a written information security program with administrative, technical, and physical safeguards proportionate to the sensitivity of financial and tax data. The controls that matter most in FiscalOS are:

  • Tenant isolation enforced in the database. Every tenant table carries the company boundary, with row-level security enabled and forced, and company work executing inside a transaction-scoped company context under a non-owner database role. Isolation is a database rule, not a filter in the interface.
  • Authorization separate from authentication. Signing in establishes who you are. What you may view, prepare, approve, post, export, or administer is decided separately by explicit role gates on the server. Hiding a control in the interface is never treated as a permission.
  • Encryption. TLS for all data in transit; encryption at rest for the database and file storage; AES-256-GCM with authenticated additional data for protected fields such as provider tokens and tax identifiers.
  • Credential hygiene. Passwords are stored only as salted hashes. Two-factor authentication is available and recommended. Long-lived provider keys stay on the server; live voice uses a short-lived, constrained ephemeral token so the underlying API key is never exposed to a browser. Secrets, tokens, raw personal information, and full provider payloads are excluded from logs.
  • Append-only accounting history. Posted journal entries and lines cannot be updated or deleted; corrections are reversal entries. Database revokes and triggers enforce this, and a hash chain is verified on a schedule so tampering is detectable.
  • Upload validation. Attachments are size-capped, validated by declared type and file signature, checksum-addressed, scoped to a company, and stored outside the immutable application release.
  • Webhook and callback integrity. Provider callbacks are signature-verified against the raw request body on their exact routes, with replay and idempotency protection.
  • Monitoring and audit. Authentication events, role-gate denials, administrative actions, approvals, exports, and erasures are recorded as append-only audit events.
What we do not claim

These are implemented controls, not a certification, and not a guarantee. No system is perfectly secure. FiscalOS has not completed a SOC 2 examination, and we do not represent that it has. Your own practices matter too: use a unique passphrase, enable two-factor authentication, keep roles tight, remove people who leave, and review what you approve.

If you believe you have found a vulnerability, write to [email protected] with "Security report" in the subject line. Please do not test against another customer's data. Where a security incident affecting your information occurs, we will notify affected customers and regulators as applicable law requires, without unreasonable delay.

12Retention and deletion

We keep information for as long as needed for the purpose it was collected, and then for the shorter of the period required by law and the period needed to resolve disputes or enforce agreements.

Retention by category
CategoryHow long we keep it
Account DataFor the life of your account, then up to 12 months after closure for dispute resolution and legal defense
Company RecordsFor as long as your workspace is active, and thereafter as you direct. Accounting and tax records commonly carry multi-year statutory retention; you decide what your business must keep
Posted journal entries and audit eventsRetained as an append-only record for the life of the workspace and any applicable retention period; corrected by reversal, never by deletion
Uploaded source documentsUntil you delete the document or close the workspace, subject to retention you configure
Maya conversations and saved memoriesUntil you delete the conversation or memory, or close your account
Live call audioNot retained. Usage and duration metering is kept for billing history
Security and access logsTypically 12 months, longer where an investigation or legal hold requires it
Billing and tax recordsAs long as tax and corporate recordkeeping law requires, generally at least 7 years
Marketing contact recordsUntil you unsubscribe, plus a suppression record so we honor it

You have two self-service paths in Settings → Privacy & data:

  • Export. An owner or administrator can download a complete, machine-readable export of the company's data at any time.
  • Delete my account. Removes your access and anonymizes your profile. A sole owner is blocked with guidance, so a workspace is never orphaned.
  • Erase and close the company. An owner can erase the workspace after typing the company name to confirm. This anonymizes personal information across customers, vendors, employees, and the company identity block in a single transaction and records an audit event.
Erasure preserves the accounting ledger

Company erasure anonymizes personal information but deliberately preserves the append-only, hash-chained journal entries. Deleting posted accounting history would break the integrity guarantee that makes the books auditable, and would conflict with the recordkeeping obligations that apply to financial and tax records. This is a lawful limitation on the right to erasure, not a refusal. Export your data before erasing if you need it.

Backups are retained on a rolling schedule and are overwritten in the ordinary course. Information already removed from the live system may persist in a backup until that backup is cycled out.

13International data transfers

FiscalOS is operated from the United States, and Company Records are stored in the United States. Our text AI, retrieval, document, and storage providers process in the United States. The single exception is Maya's live voice endpoint, which Google processes globally; see Tax return information and IRC §7216 and Voice calls, recording, and consent.

If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data-protection law differs from that of your jurisdiction. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary technical and organizational measures. A copy of the relevant clauses is available on request.

14Your privacy rights

14.1United States state privacy rights

Depending on your state of residence, you may have the right to confirm whether we process your personal information and to access it; to obtain a portable copy; to correct inaccuracies; to delete it; to opt out of sale, of sharing or targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects; to limit the use of sensitive personal information; and to be free from discrimination for exercising a right.

Because we do not sell personal information, do not share it for cross-context behavioral advertising or targeted advertising, do not profile in that manner, and do not use sensitive personal information for inferring characteristics, the opt-out and limitation rights have nothing to operate on. We honor them regardless.

These rights are exercisable against a controller. For Company Records, the controller is the FiscalOS customer whose workspace holds the information, and we will route your request to them.

14.2GDPR and UK GDPR rights

If the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, the right to withdraw consent where processing is based on consent, and the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects. As explained in Maya AI and automated processing, FiscalOS makes no such solely automated decisions.

You may lodge a complaint with your supervisory authority. We would appreciate the chance to address your concern first at [email protected]. We have not appointed an EU or UK representative because we do not currently target the EU or UK market; if that changes, we will appoint one and name them here.

14.3How to exercise a right

Most requests are faster to satisfy yourself: export and deletion are available in Settings → Privacy & data. Otherwise, write to [email protected] with "Privacy request" in the subject line and tell us what you want and which workspace or email address it concerns.

  • Verification. We will verify your request against information already in our records — typically by confirming control of the account email. We will not ask for more information than needed, and we will not create an account to process a request. Where we cannot verify you, we will explain why.
  • Timing. We respond within 45 days, and may extend once by a further 45 days where reasonably necessary, with notice. Where the GDPR applies, we respond within one month, extendable by two further months for complex requests.
  • Authorized agents. An agent may submit a request with your written, signed permission. We may contact you to confirm the authorization and to verify your identity directly.
  • Appeals. If we decline a request in whole or in part, you may appeal by replying to our response with "Appeal" in the subject line. We will decide the appeal within 45 days and explain our reasoning. If we deny the appeal, we will tell you how to contact your state attorney general.
  • No charge, no penalty. Requests are free unless excessive or repetitive, and exercising a right never affects your price, plan, or service quality.

California residents may also request, once per year, a list of the categories of personal information we disclosed to third parties for their direct marketing purposes. We disclose none, because we do not engage in that practice.

15Children

FiscalOS is business software offered to businesses and to adults acting for a business. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we hold such information as Account Data, we will delete it. Where a child's information appears inside a Company Record — a dependent named in a payroll or tax workpaper, for example — it is under the control of our customer, who is responsible for the lawful basis for including it.

16Changes to this policy

We may update this policy to reflect changes in the Service, our providers, or the law. When we do, we will revise the "Last updated" date at the top of this page. If a change materially reduces your rights or materially expands how we use personal information, we will give notice — by email to account owners or by an in-product notice — at least 30 days before it takes effect, and we will describe what changed. Continuing to use the Service after a change takes effect means you accept the updated policy. Prior versions are available on request.

17Contact us

Privacy questions, requests, and complaints:

Entity
Dexcon Capital LLC d/b/a FiscalOS
Mail
3702 W Spruce St #1058, Tampa, FL 33607, United States
Email
[email protected]
Subject line
We run one mailbox rather than aliases that might not be monitored. Start the subject with "Privacy request" or "Security report" so your message is routed and tracked correctly.

The other half of the agreement

Terms of Service

The agreement governing your use of FiscalOS: accounts and roles, early access and billing, your data, Maya AI and the approval gate, disclaimers, liability limits, and dispute resolution.

Read the terms of service ↗See the security controls ↗Ask a legal question ↗

Maya AI prepares the work. You approve what posts.

FiscalOS is a registered trade name of Dexcon Capital LLC, a Florida limited liability company. 3702 W Spruce St #1058, Tampa, FL 33607. FiscalOS is software, not an accounting firm, and does not provide tax, legal, or accounting advice.

ProductOverviewWorkflowsIntegrationsPricing
MethodsEditorial methodAccounting methodTax readinessSecurity controls
LegalPrivacy policyTerms of serviceSubprocessorsYour privacy rightsCookies
AccountSign inStart freeContact
© 2026 Dexcon Capital LLC d/b/a FiscalOSPrivacyTermsTrustBuilt for careful decisions