Last updated: February 14, 2026
Taxlytic ("we," "us," or "our") provides automated tax intake software for independent tax preparers. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
We collect the following categories of personal information:
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Name, email, phone, SSN (last 4 via chat, full via voice with consent) | Tax intake, account creation |
| Financial information | Income sources, deductions, W-2/1099 data | Tax preparation |
| Employment information | Employer name, wages, withholdings | Tax preparation |
| Family information | Dependents, filing status, relationships | Tax preparation |
| Document images | W-2 photos, 1099 scans, receipts | AI extraction |
| Voice call data | Call audio, transcripts, AI-generated responses | AI Receptionist service |
| Chat/messaging data | Intake messages, tawk.to live chat | Service operation |
| Usage data | Session activity, timestamps, feature usage | Analytics, improvement |
| Device/technical data | IP address, user agent, browser | Analytics, security |
| Payment data | Handled by Stripe; we store only subscription status | Billing |
When you use our platform, we automatically collect certain technical information including analytics events, authentication session data, and rate limit counters (ephemeral). This data is used for service operation, security, and improvement.
| Purpose | Legal Basis |
|---|---|
| Facilitating tax intake between clients and preparers | Contract performance |
| AI-powered data extraction from documents and chat | Contract performance |
| Voice call handling and transcription | Contract performance + consent |
| Transactional emails (invitations, notifications) | Contract performance |
| Analytics and service improvement | Legitimate interest |
| Fraud prevention and platform security | Legitimate interest + legal obligation |
| Marketing communications (if opted in) | Consent |
| Compliance with legal obligations | Legal obligation |
Your data is NOT used to train AI models. Not by us, and not by our AI providers.
AI outputs may contain errors, omissions, or inaccuracies. All AI-processed data must be independently verified by a qualified tax professional before use in tax return preparation.
No automated decisions with legal or significant effects are made without human review by the designated tax preparer.
| Category | Service | Data Access | Location | AI Training |
|---|---|---|---|---|
| AI Processing | Chat, extraction, voice AI | Messages, documents | US | No |
| Speech Processing | Speech-to-text, text-to-speech | Voice audio, AI text | US | No |
| Telephony | Voice calls, SMS | Call audio, phone numbers | US | No |
| Database & Auth | Database, authentication, storage | All user data | US | No |
| Hosting | Application hosting | Request metadata | US | No |
| Payments | Payment processing | Billing info (processor-side) | US | N/A |
| Analytics | Usage analytics | Events, anonymized IP | US/EU | No |
| Transactional email | Email address, name | US | No | |
| Rate Limiting | Security rate limiting | IP address (ephemeral) | US | No |
| Support | Live chat | Chat messages, email | EU | No |
A detailed sub-processor list with specific provider names is available upon request. Contact privacy@taxlytic.ai.
We do not sell, rent, or share your personal information with third parties for advertising, marketing, or any purpose unrelated to providing our service.
We will update this sub-processor list when adding new providers. Material changes will be communicated via email with 30 days notice.
We may create aggregate, de-identified, or anonymized data from personal information by removing identifiers. Anonymized data is not personal information and may be used for product improvement, industry benchmarking, and service analytics. We will not attempt to re-identify anonymized data.
Infrastructure protected by firewalls, DDoS protection, and rate limiting.
Multi-tenant architecture with logical isolation of customer data at the database level via RLS policies.
Core infrastructure providers maintain SOC 2 certification. Provider-specific certification details are available upon request.
Antivirus, firewalls, MFA, encryption, secure data wiping, regular security updates.
Security vulnerability reporting: If you discover a security vulnerability, please report it to security@taxlytic.ai. We will acknowledge receipt within 48 hours and work to resolve confirmed vulnerabilities promptly.
| Category | Retention Period | Legal Basis |
|---|---|---|
| Tax intake data (active account) | Duration of subscription | Contract |
| Tax intake data (cancelled account) | 6 years from last filing year | IRS 26 CFR 1.6107-1 |
| Voice call transcripts | 6 years from call date | IRS record-keeping |
| Account credentials | Until account deletion | Contract |
| Payment/billing records | 7 years | Tax/accounting obligations |
| Analytics data | 12 months | Legitimate interest |
| Rate limiting data | 24 hours (ephemeral) | Security |
| Deleted account data | Purged within 30 days | Privacy right |
| Backups | Per database provider retention policy | Disaster recovery |
Fraud exception: If a fraudulent return was prepared or no return was filed, data may be retained indefinitely per IRS requirements (no statute of limitations). After retention period expiration, data is securely deleted using industry-standard methods.
Upon discovery of unauthorized access to personal information:
All personal data is processed and stored in the United States. If you access our services from outside the US, your data will be transferred to and processed in the US. By using our services, you consent to this transfer. We maintain contractual protections with all sub-processors.
We do not currently target services to EU/EEA residents. If we expand to serve international markets, we will implement appropriate transfer mechanisms (Standard Contractual Clauses or adequacy decisions).
We may disclose personal information when required by law, subpoena, court order, or government investigation. We will use commercially reasonable efforts to notify affected users before disclosing their data to government authorities, unless:
We will challenge overbroad or inappropriate requests where feasible. The Stored Communications Act (18 USC 2702) governs our handling of government requests for electronic communications.
Access, correction, deletion, portability, opt-out of targeted advertising and profiling.
Access, correction, deletion, portability, opt-out of targeted advertising, profiling, and sale.
Access, correction, deletion, portability, opt-out of sale, targeted advertising, and profiling.
Access, correction, deletion, data portability.
Email privacy@taxlytic.ai. We will verify your identity and respond within 45 days (30 days for some state laws). If we need more time, we will notify you of the extension.
| Technology | Provider | Purpose | Type | Opt-Out |
|---|---|---|---|---|
| ph_* | PostHog | Analytics | Performance | posthog.opt_out_capturing() or browser settings |
| sb-* | Supabase | Authentication | Essential (required) | Cannot opt out |
| tawk.to widget | tawk.to | Live chat | Functional | Do not initiate chat |
We do not use advertising cookies, retargeting pixels, or third-party tracking for advertising purposes.
Marketing communications are opt-in only. You may unsubscribe at any time via the link in any marketing email. Operational and transactional emails (intake invitations, billing receipts, security alerts) cannot be opted out of while your account is active.
By using our services, you consent to receive communications from us electronically (email, in-app notifications). Electronic communications satisfy any legal requirement for written notice. Per the E-SIGN Act, electronic records and signatures have the same legal effect as physical documents.
Taxlytic is not intended for use by individuals under 18. We do not knowingly collect personal information from children. If discovered, we will delete such information within 30 days. If you believe a minor has provided personal information, contact privacy@taxlytic.ai.
Material changes: 30-day advance notice via email plus an in-app reconsent banner. Continued use after the notice period constitutes acceptance.
Non-material changes: Updated "Last updated" date at the top of this page. We encourage you to review this policy periodically. Previous versions are available upon request.
Taxlytic
Privacy requests: privacy@taxlytic.ai (response within 45 days)
General support: support@taxlytic.ai
3727 Greenbriar Dr Ste 203, Stafford, TX 77477
Governing law: State of Texas