Privacy Policy
Last updated: April 9, 2026
1. Information We Collect
When you use AutoTax AI, we collect the following information solely for the purpose of preparing your tax return:
- Personal Information: Name, email address, Social Security Number (SSN), date of birth, mailing address, phone number, and filing status.
- Tax Documents: W-2 forms, 1099 forms, and other tax-related documents you upload.
- Financial Data: Income amounts, tax withholdings, and deduction information extracted from your documents.
- Payment Information: Processed securely by Stripe. We never see or store your credit card number.
2. How We Use Your Information
- To prepare and generate your federal and state tax returns.
- To verify the accuracy of your tax return through automated checks.
- To process your payment via Stripe.
- To communicate with you about your tax return status.
- We do NOT sell, rent, or share your personal information with third parties for marketing purposes.
3. Data Security
- Encryption: Your SSN is encrypted using AES-256-GCM before storage. All data is transmitted over HTTPS/TLS.
- AI Processing: Your tax documents are sent to AI services (via OpenRouter) for data extraction. Documents are processed in real-time and are not stored by the AI provider.
- Storage: Your data is stored in Supabase with row-level security (RLS) policies ensuring only you can access your own data.
- Access Control: All API endpoints require authentication and verify resource ownership.
4. Data Retention & Deletion
- Your tax return data is retained for 7 years (IRS recommended retention period).
- You may request deletion of your account and all associated data at any time by contacting us.
- Uploaded document images are stored in encrypted cloud storage and can be deleted after your return is generated.
5. Third-Party Services
We use the following third-party services:
- Supabase: Authentication, database, and file storage.
- Stripe: Payment processing. See Stripe's Privacy Policy.
- OpenRouter: AI document extraction. Documents are processed in real-time and not retained.
- Vercel: Application hosting.
6. Your Rights
- Access your personal data at any time through your dashboard.
- Request correction of inaccurate data.
- Request deletion of your account and data.
- Export your tax return data.
7. Contact Us
For privacy-related inquiries, contact us at: privacy@self-tax.com