◆ Holly OS
Terms Privacy

Privacy Policy

Last updated: July 4, 2026

Holly OS is a private executive operating system operated by Holly Oh Diamond ("Holly OS", "we", "us", or "our"). This policy explains what information we collect, how we use and protect it, and the choices you have. Questions: info@workonward.com.

Holly OS is a private, invitation-only tool. It is not a consumer product and is not offered to the general public. Access is limited to a small number of authorized users (the operator and specifically invited team members) who use it to run their own business operations.

1. Information we collect

Account information

To sign in, we use a username/email and password for each authorized user. We do not create public accounts or accept sign-ups from the general public.

Financial account information (via Plaid)

When an authorized user connects a bank or financial account, we use Plaid Inc. ("Plaid") to establish that connection. You enter your financial credentials directly with Plaid — Holly OS never sees, receives, or stores your bank login credentials. Through Plaid we access financial information such as account names, balances, and transactions to display them in the dashboard.

What we actually store is limited to: (a) an encrypted Plaid access token that lets us re-request data for the accounts you connected, and (b) the institution name and account identifiers needed to organize the display. Balances and transactions themselves are fetched live from Plaid when the dashboard loads and are not stored in our database — they exist only briefly in memory to render the page.

Google account information (optional, via OAuth)

If an authorized user connects a Google account, we access email and calendar data through Google's authorized OAuth flow to power inbox and calendar features. Access tokens are stored encrypted. We do not sell this data or use it for advertising.

Technical information

Our servers keep standard operational logs (e.g., timestamps and request paths) to operate and secure the service. We do not use third-party advertising or cross-site tracking.

2. Our use of Plaid

We use Plaid to connect financial accounts and retrieve financial data on your behalf. By connecting an account, you grant Holly OS and Plaid the right to access and transmit your information as described here and in Plaid's policies. You can review how Plaid handles your data in the Plaid End User Privacy Policy.

3. How we use information

  • To display your financial position, email, calendar, and tasks in one executive dashboard.
  • To operate, maintain, secure, and improve the service.
  • To communicate with you about the service.
  • To comply with legal obligations.

We do not sell your personal or financial information, and we do not share it for third-party advertising.

4. How we share information

We share information only as needed to run the service:

  • Service providers that power the product — including Plaid (financial connectivity), Google (email/calendar, at your election), and our hosting and infrastructure providers — under agreements that limit their use of the data to providing their services.
  • Legal and safety — if required by law, regulation, legal process, or to protect rights, property, or safety.

5. How we protect information

  • In transit: all traffic is encrypted using TLS 1.2 or higher.
  • At rest: sensitive credentials (Plaid access tokens and Google OAuth tokens) are encrypted using AES-256-GCM. Raw consumer financial data (balances/transactions) is not persisted — it is retrieved live and held only transiently in memory.
  • Access controls: the dashboard is private and every route requires authentication; access is limited to allow-listed users. Administrative and server access is restricted, firewalled, and uses key-based authentication.

6. Data retention and deletion

We keep information only as long as needed to provide the service:

  • Plaid access tokens are retained until you disconnect the associated institution or request deletion, at which point the token is deleted and we can no longer access those accounts.
  • Financial transaction/balance data is not retained (it is fetched live).
  • Account and log data is retained for as long as your access is active and for a reasonable period afterward for security and legal purposes.

This policy and our retention practices are reviewed periodically and are maintained in accordance with applicable data-privacy laws. To request deletion of your data or to disconnect an account, email info@workonward.com.

7. Your choices and rights

  • Consent: connecting a financial or Google account is voluntary and requires your authorization through the provider's own flow.
  • Withdraw consent / disconnect: you may disconnect a connected account at any time, which stops further access.
  • Access and deletion: you may request access to, correction of, or deletion of your information by contacting us.

8. Children's privacy

Holly OS is a business tool and is not directed to children under 16, and we do not knowingly collect information from them.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice.

10. Contact us

Holly OS — operated by Holly Oh Diamond
Email: info@workonward.com

© Holly OS · Operated by Holly Oh Diamond · Terms of Service · Privacy Policy