Last updated August 1, 2026 · Applies to the Amplify website and the Amplify review service.
Who we are
Amplify is operated by OneSource Consulting ("we," "us"). This policy describes what
we collect when you visit this site or use the Amplify review service, what we do with it, and
the commitments we make about your clients' information. Questions or requests:
info@onesourcesbc.com.
Three kinds of information, three different rules
Everything below is easier to follow with one distinction up front:
- Website data: what we collect when you visit this site.
- Client content: the drafts, documents, and source material your AI tools route
through Amplify for review. Your firm's work product, often containing your clients' information.
- Review metadata: the record of the review itself: who looked, what they were shown,
what they changed, what they decided, and when.
Website data
Contact details you give us: your email address, firm name, and what you tell us about
your firm if you request beta access, join the waitlist, create an account, or ask to talk to us.
We collect these only when you type them into a form
yourself; we never infer them, buy them, or obtain them from third parties.
How the site is used: we run our own first-party analytics to understand what visitors
read and where the site falls short: pages viewed, how far down a page you scroll, how long you
actively read, and what you click. Everything is collected and stored by us alone; there are no
third-party analytics services, no advertising trackers, and no fingerprinting. Specifics we think
you'd want to know:
- We never store your IP address. It is one-way hashed with a key that changes daily,
and even those hashes are deleted after 30 days.
- Analytics sets no cookies. A random identifier in your own browser's storage lets us
tell a returning visitor from a new one; it means nothing outside this site. The only cookie we
set is the session cookie that keeps you signed in to an account.
- We honor Do Not Track and Global Privacy Control. If your browser sends either
signal, our analytics does not record your visit at all.
- Detailed visit data is kept for at most 400 days; after that only daily aggregates
remain, which identify no one.
Client content, our core commitments
This is the part most firms are rightly cautious about, so it comes first and in plain terms:
- We never use client content to train AI models. Not ours, not anyone's. Content under
review is processed transiently to display it to your reviewer and produce the evidence record.
- We never sell client content or make it available to other customers in any form,
aggregated or otherwise.
- Your firm remains the owner and controller. We act as your service provider under a
written agreement, accessing content only to operate the service, support you at your request,
or meet a legal obligation we'll tell you about below.
- The AI drafting happens under your own agreements. Amplify does not send your content
to AI models. Drafts are produced by the Claude subscription your firm already holds (Copilot support upcoming),
under the data terms your firm already accepted with that provider, Amplify receives the draft
after, for human review.
- Confidentiality rules that bind you, bind us. We structure the service so your use of
it is consistent with professional confidentiality obligations, including AICPA rules and, for
tax-return information, the written-consent framework of IRC §7216, our agreement with your
firm includes the service-provider commitments those rules expect.
Review metadata and the evidence record
Your evidence records belong to your firm. They live in your firm's storage environment,
are content-fingerprinted at creation so later alteration is detectable, and we touch them only to
operate the service. They're your compliance documents: your firm sets their retention, and on
termination you can export them in full before we delete our copies.
Reviewer timing data is designed against surveillance. Amplify records when a review
started, how long each judgment took, and what changed, because that timing is part of what makes
the record credible. Three rules govern it: it is captured only inside the review screen (no
keystroke logging, no screen recording, no tracking outside the task); each reviewer can see their
own data in full; and firm leadership sees aggregates and deviations, not per-person leaderboards.
Aggregated statistics
Separately from any client's records, we maintain aggregated, de-identified review
statistics: for example, typical review times by task type, or how often AI drafts of a given
kind need correction. These power the product's quality signals ("this review took a typical amount
of care"). They are built only from activity of clients whose contracts consent to it, they contain
no client content, and they cannot be traced back to a person, a firm, or a document. If we ever
publish or license benchmark statistics, they come only from this de-identified aggregate.
How we use information
To provide and secure the service; to produce evidence records; to calibrate quality signals;
to respond when you contact us; to bill; and to meet legal obligations.
We do not sell or share personal information as those terms are defined under the California
Consumer Privacy Act, and we do not use it for cross-context behavioral advertising.
Subprocessors and where data lives
We use a small number of infrastructure providers (hosting, storage, payments) to run the
service, each bound by written data-protection terms. A current list is available on request and
will be published with the live version of this policy; we give notice before adding one.
Service data is stored in the United States. We do not transfer it internationally except
as needed to serve a firm located elsewhere.
Security
Data is encrypted in transit and at rest; evidence records are content-fingerprinted at
creation; access is role-limited to personnel who need it and is logged. Our safeguards program
is designed to align with the FTC Safeguards Rule that already governs many of our clients.
If a breach affects your data, we notify your firm without undue delay and in any case
within the timelines your agreement and applicable law require, with what we know and what we're
doing about it.
Legal requests
If a court, regulator, or government agency demands data, we notify your firm before producing
anything unless the law forbids it, we challenge overbroad requests, and we produce the narrowest
set the demand legally requires.
How long we keep it
Website contact details: until you ask us to delete them. Website analytics: detailed visit
data at most 400 days, IP hashes at most 30 days, daily aggregates indefinitely (they identify
no one). Account data: for the life of the account plus what tax and accounting law requires of
us. Client content: transiently, for the review itself. Evidence records: per your firm's
retention settings. De-identified aggregates: indefinitely, as they identify no one.
Your rights
Anyone may request a copy of the personal information we hold about them, ask us to correct
it, or ask us to delete it (where the law doesn't require us to keep it) by emailing
info@onesourcesbc.com. Residents of California and of other states with comprehensive
privacy laws (Virginia, Colorado, Connecticut, Utah, and others as they take effect) may exercise
their statutory rights the same way. We do not discriminate against anyone for exercising them,
and we respond within the time the applicable law sets.
If the business changes hands
If OneSource is acquired or merges, this policy's commitments travel with the data: client
content and evidence records transfer only under the same ownership and confidentiality terms,
and your firm is notified before any transfer takes effect.
Children
This site and service are for business use and not directed to anyone under 16.
Changes
If this policy changes, we'll update the date above; material changes will be flagged on this
page and, for service clients, sent to your account contact before they take effect.