Privacy Policy

Last updated: April 9, 2026

1. Information We Collect

When you use AutoTax AI, we collect the following information solely for the purpose of preparing your tax return:

  • Personal Information: Name, email address, Social Security Number (SSN), date of birth, mailing address, phone number, and filing status.
  • Tax Documents: W-2 forms, 1099 forms, and other tax-related documents you upload.
  • Financial Data: Income amounts, tax withholdings, and deduction information extracted from your documents.
  • Payment Information: Processed securely by Stripe. We never see or store your credit card number.

2. How We Use Your Information

  • To prepare and generate your federal and state tax returns.
  • To verify the accuracy of your tax return through automated checks.
  • To process your payment via Stripe.
  • To communicate with you about your tax return status.
  • We do NOT sell, rent, or share your personal information with third parties for marketing purposes.

3. Data Security

  • Encryption: Your SSN is encrypted using AES-256-GCM before storage. All data is transmitted over HTTPS/TLS.
  • AI Processing: Your tax documents are sent to AI services (via OpenRouter) for data extraction. Documents are processed in real-time and are not stored by the AI provider.
  • Storage: Your data is stored in Supabase with row-level security (RLS) policies ensuring only you can access your own data.
  • Access Control: All API endpoints require authentication and verify resource ownership.

4. Data Retention & Deletion

  • Your tax return data is retained for 7 years (IRS recommended retention period).
  • You may request deletion of your account and all associated data at any time by contacting us.
  • Uploaded document images are stored in encrypted cloud storage and can be deleted after your return is generated.

5. Third-Party Services

We use the following third-party services:

  • Supabase: Authentication, database, and file storage.
  • Stripe: Payment processing. See Stripe's Privacy Policy.
  • OpenRouter: AI document extraction. Documents are processed in real-time and not retained.
  • Vercel: Application hosting.

6. Your Rights

  • Access your personal data at any time through your dashboard.
  • Request correction of inaccurate data.
  • Request deletion of your account and data.
  • Export your tax return data.

7. Contact Us

For privacy-related inquiries, contact us at: privacy@self-tax.com