— Annex · Mercurius —

Privacy Policy

A short, honest accounting of what data Mercurius touches, where it lives, and who else sees it.

This is a private accounting tool, not a product for sale. It is operated by WvH Hospitality LLC, through its Managing Member JM Woody van Horn, on behalf of a small roster of fractional-CFO and bookkeeping clients who have authorized such access in writing. It runs in two places, both of them the operator’s: his own Mac, and one small private server he rents and controls.

1. Who We Are

WvH Hospitality LLC, a California limited liability company (Est. 2017), acting through its Managing Member, JM Woody van Horn (full legal name: John Morsell Woody van Horn). Mailing address: 1947 Garnet St, Mentone, CA 92359. Contact: admin@thehighseven.com (the council’s correspondence desk) or me@wvhhospitality.com.

2. Scope

Mercurius, a WvH Hospitality LLC AI Agent ("the bot"), is a Model Context Protocol server that allows Claude (Anthropic's AI assistant) to perform accounting work against QuickBooks Online realms that have explicitly authorized the operator via Intuit's OAuth 2.0 consent flow.

The bot runs in two modes. Both are operated solely by WvH Hospitality, run the same code, and answer only to the same set of client authorizations:

The hosted machine is single-tenant: it serves this one operator, and opening a session on it requires credentials only he holds. There is no shared instance, no SaaS layer, no version offered to anyone else, no marketing site capturing visitor data, and no analytics.

3. What Data Is Accessed

Only data within QuickBooks Online realms for which the realm-owner has granted access via Intuit's standard OAuth flow. This includes:

Access is scoped exactly as Intuit defines it. The bot cannot see realms it has not been authorized for.

4. Where Data Lives

On the operator's Mac

On the hosted machine

Nowhere else

Apart from that one machine, WvH Hospitality operates no server, database, cloud bucket, analytics platform, marketing automation, or telemetry endpoint that receives data from the bot. The bot does not "phone home," and it reports nothing to its operator's other systems.

5. Third Parties Involved

Intuit (QuickBooks Online)

The source of the data. Their privacy statement governs how QBO stores it. The bot communicates with Intuit's QuickBooks Online API over TLS using the OAuth 2.0 access token issued by the realm-owner.

Anthropic (Claude)

When the operator asks Claude a question that requires QBO data, the relevant data — the rows of a report, the body of an invoice, the names of a few vendors — is included in the conversation context that Claude needs in order to reason. That conversation context is processed by Anthropic's API. Anthropic's privacy policy and Data Processing Addendum apply to that traffic. Per Anthropic's standard commercial terms for API usage, your data is not used to train their models.

Fly.io (hosting)

The hosted instance runs on a virtual machine rented from Fly.io, Inc., a United States cloud hosting provider, in their Los Angeles region. Fly.io supplies the machine, its storage volume, and the TLS certificate that encrypts traffic to it; they are a hosting provider, not a recipient of your data, and they have no account, dashboard, or reason to read what passes through. As with any host, they hold the physical and administrative control that hosting entails. Their privacy policy applies to that infrastructure.

Apple (macOS)

Apple's macOS Keychain holds the encrypted OAuth refresh tokens. Apple's privacy policy applies.

That's it.

No advertising networks, no analytics vendors, no CRMs, no email-marketing tools, no offshore processors. The list above is exhaustive.

6. What We Do Not Do

7. Your Rights

If you are a realm-owner (a WvH Hospitality client whose QBO realm is connected to the bot), you may at any time:

8. Children

The bot is an accounting tool used in a professional services context. It is not directed to anyone under 18 and does not knowingly process children's data.

9. Security

On the operator's Mac: refresh tokens live encrypted in macOS Keychain, the machine is protected by FileVault full-disk encryption, automatic lock, and standard macOS security updates, and there is no network listener — that instance cannot be reached from the internet at all.

On the hosted machine: the one public address it answers on is HTTPS-only, and every request for accounting data must present a credential the operator holds. Registering a new client application against it additionally requires a separate passphrase typed by the operator by hand. Tokens are encrypted at rest as described in §4, with the key supplied at runtime and never written to storage. Credentials are rotated on a quarterly schedule. Traffic to Intuit and to Anthropic travels over TLS in both modes.

Honest caveat: a machine reachable from the internet is a larger target than a laptop that isn't, which is why its authentication is narrow and its stored data is limited to encrypted tokens rather than your books. No system is free of security vulnerabilities, and we don't claim otherwise.

10. International Transfers

The operator is in California, and the hosted machine sits in Fly.io's Los Angeles region. Intuit and Anthropic operate primarily in the United States. If you are accessing this from outside the U.S. and engage WvH for accounting services, your data will be processed in the U.S.

11. Changes to This Policy

If we change anything material about how the bot handles data, we'll update this page and revise the effective date below. Material changes (new third-party processors, new data flows) will additionally be communicated to active clients by email before taking effect.

12. Contact

Privacy questions, requests, or concerns: admin@thehighseven.com — the council’s correspondence desk, watched by a human — or me@wvhhospitality.com. Please put "Mercurius — Privacy" in the subject line so it routes correctly.

Effective 28 April 2026 · Southern California · Version 1.2 · Published 24 Sep 2026, in effect 1 Oct 2026 — hosted instance disclosed; Fly.io added as a processor (§§2, 4, 5, 9, 10)