Your data, in plain English.
Effective: 2026-08-01 · Last updated: 2026-08-01
Who we are
Taxottic is a tax forecasting and deduction-tracking service operated by Techno Optics LLC, a Massachusetts limited liability company ("we", "us", "Taxottic"). Contact: contact@taxottic.com.
For data-protection inquiries (GDPR / CCPA requests, deletion, portability): privacy@taxottic.com.
When you use Taxottic for your own taxes, we are the controller of your data. When your employer or an accounting firm puts you on Taxottic, that company decides what is collected about you and why, and we process it for them under our Data Processing Agreement.
What we collect, and why
We only collect what we need to forecast your taxes and run your account. We do not buy data about you.
- Account info from sign-in: email, full name, profile photo (when supplied by Google or Microsoft). Used for authentication and to greet you.
- Tax profile you enter: filing status, state, number of dependents, age, and business profile fields. Used to run forecasts. We store a count of dependents, never their names or identifiers.
- Income and expense entries you log or import. Used to calculate your federal and state tax estimate, surface deductions, and produce reports you ask for.
- Business tax identifiers. If you enter an EIN for your business, we store it encrypted. If you complete a W-9 that a firm sent you, the taxpayer identification number you type (an SSN or EIN) is encrypted before it is stored, and is shown masked afterwards. We also record the IP address and browser user-agent at the moment you sign a W-9, because a signed tax form needs an audit trail.
- Bank connection dataif you connect a bank through Plaid, or a Stripe account as an income source: the institution name, the last four digits of the account, the balance, and for each transaction the date, amount, merchant, and the bank's own description. We also keep the provider's raw record of the transaction. We never see your bank login. See "Bank connections" below.
- Documents you scan: receipts, pay stubs, W-2s, and prior-year tax documents. See "Documents and scanning" below, which explains what happens to the file.
- Bella conversations: messages you send to our in-app guide, and its replies. Used to answer you and to keep your conversation history.
- Team chat: messages and file attachments you send to other members of your company inside Taxottic.
- Location, only if you turn on automatic mileage tracking: GPS points while you drive, used to compute your IRS mileage deduction. Off by default, opt-in, and stoppable any time. See Location tracking and team visibility, which covers this in full.
- Device and diagnostic data from the mobile app while mileage tracking is on: platform, app version, whether tracking is enabled, which location permission you granted, whether precise location is on, whether battery optimisation or low-power mode is active, and how recently the app uploaded. Used to tell you when tracking has silently stopped.
- Push notification tokens if you allow notifications, so Apple, Google, or your browser can deliver them.
- Operational data: timestamps, IP address at request time, browser user-agent, and the events needed for security, debugging, and billing.
We do not collect your Social Security number for your own account, your bank account or routing numbers, your card numbers, or your dependents' details. We do not use any third-party analytics or advertising SDK, and there is no crash-reporting SDK in the app.
Location and automatic mileage tracking
Automatic mileage tracking is off by default. It turns on only when you flip the toggle on the Mileage screen, read the explanation, and grant your phone's location permission. You can turn it off there at any time.
While on, the app records GPS points as you drive, including in the background, so a trip is captured even when the app is closed. We use them to detect trips and calculate your IRS mileage deduction, and for nothing else. Location data is never sold and is never used for advertising or profiling.
It is shared in two specific ways, and you should know about both. Coordinates are sent to Google Maps Platform to draw maps, route thumbnails, and place names. And if you drive for a company, a manager at that company (and any accounting firm it has engaged) can see the drives you have marked as business, including the route line. Drives you mark personal, and drives you have not yet classified or confirmed, are not shown to them.
Retention is not uniform. Raw GPS fixes are deleted within roughly 30 to 75 days. Device-health history is deleted after 30 days. Completed trips and their route lines are kept until you delete them or the account is deleted, because a mileage deduction has to be substantiated to the IRS long after the drive.
The full account, including exactly what a manager sees and what employers should consider, is at /legal/location-monitoring.
Bank connections (Plaid and Stripe)
When you connect a bank account through Plaid, your bank credentials are entered into Plaid's secure interface and never reach Taxottic servers. Plaid returns an access token and the transaction stream we display. We store that access token encrypted with AES-256-GCM, and we request only transaction data, not account or identity verification products.
You can also connect a Stripe account as an income source. In that case the record we store for each payout or charge is the one Stripe gives us, which can include the name and email your own customer gave Stripe.
We store the last four digits of an account, never the full account number and never a routing number. Plaid's privacy practices are documented at plaid.com/legal. You can disconnect a bank at any time from Banks » Disconnect, which stops syncing and moves the connection to your recycle bin.
Documents and scanning
When you scan a receipt, a pay stub, a W-2, or a prior-year tax document, the file is sent to Anthropic, which reads it and returns the figures. We then store only the structured result, for example the wage and withholding amounts from a W-2, plus the filename. We do not store the image or PDF itself for any of these four document types.
Be aware of what that means in practice: the whole file is transmitted, not just the parts we ask for. If you photograph a W-2, that image contains your Social Security number and address even though Taxottic never reads, parses, or stores either. If you would rather not transmit a document, type the figures in by hand instead.
Other files you upload are stored rather than passed through. Chat attachments, company and firm logos, avatars, and documents a firm exchanges with a client are kept in private storage (logos and avatars are public by design, since they are displayed). Documents in a firm workspace are retained for the firm and are visible to the firm members working on your engagement.
Bella and AI features
Bella is our in-app tax guide. Replies are generated by Anthropic on your behalf. When you ask Bella a question we send it your question, the last few turns of that conversation, and a summary of your situation: tax year, filing status, state, age, your company's name, industry and entity type, and your year-to-date income and expense totals. We also use Anthropic to suggest categories for imported bank transactions, which sends the transaction description, amount, and date.
We do not sell your data and we do not use it to train any model of our own. We do not permit our AI provider to train general models on your content, and our contractual terms with them govern that. If you would rather not send anything to an AI provider, do not use Bella and enter figures manually rather than scanning documents.
Your Bella conversation history is stored on your account so you can return to it, and you can delete it.
Team chat
Messages you send in a company channel are readable by the members of that company who belong to the conversation. Messages in a private group or direct message are readable by the participants. A company manager can delete a message in their company. Losing your seat in a company removes your access to that company's conversations.
Chat is not scanned, not analysed, and not sent to any AI provider or any other third party. There is currently no automatic expiry on chat, so messages remain until they are deleted or the company or account is deleted. If someone messages you and you have notifications on, the notification says who messaged you but never includes the message text.
Notifications
If you allow notifications, we store a device token so Apple, Google, or your browser can deliver them, and we keep a record of what we sent. Notification text is kept deliberately thin, because it appears on a lock screen: it can include a drive's mileage, a goal or badge name you chose, or the name of the person who messaged you. It does not include financial totals or message contents.
How we use your data
- To operate the service (sign-in, forecasts, exports).
- To send service emails: receipts, security alerts, quarterly-tax reminders you opted into.
- To keep the service working and secure, including telling you when mileage tracking has stopped.
- To take payment for paid plans.
- To improve the product, in aggregated and de-identified form.
- To comply with law, respond to lawful requests, and protect our rights.
Legal bases (UK and EU)
- Performance of a contract: running the account, forecasting, billing, and the features you ask for.
- Consent: location tracking for automatic mileage, push notifications, and marketing email. You can withdraw any of these at any time without losing the rest of the service.
- Legitimate interests: security, fraud prevention, debugging, and product improvement, balanced against your rights.
- Legal obligation: keeping billing and tax records we are required to keep.
Where a company puts you on Taxottic, that company chooses the legal basis for monitoring you, not us. See /legal/location-monitoring.
Who else processes your data (subprocessors)
We rely on a vetted list of vendors to operate Taxottic, including our hosting and database providers, our bank-data provider, our payments provider, our AI provider, Google Maps for mapping and geocoding, Apple and Google for push delivery, and our email provider. See the full list with roles and data residency at /legal/subprocessors. We update that page when we add or change a vendor.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Where your data lives, and international transfers
Application data is stored in the United States (Supabase, Postgres, AWS us-east-1) and served via Vercel's global edge. Data is encrypted at rest and in transit (TLS 1.2+). Sensitive fields, specifically bank access tokens and taxpayer identification numbers, are additionally encrypted at the application layer with AES-256-GCM. Backups are encrypted and retained for 30 days.
If you are in the UK or the EEA, using Taxottic means your data is transferred to and processed in the United States. We rely on the UK and EU Standard Contractual Clauses, or an equivalent approved mechanism, in our agreements with the vendors listed on the subprocessors page. Write to privacy@taxottic.com if you need the transfer documentation for your own records.
Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you.
- Correct data that is wrong or incomplete.
- Export your data in a portable format.
- Delete your account and associated personal data.
- Restrict certain processing.
- Object to processing where we rely on legitimate interests.
- Withdraw consent at any time where processing is based on consent, including turning off location tracking.
California residents have additional rights under the CCPA and CPRA, including the right to know, delete, and correct, and the right to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information beyond the purposes described here. Exercising your rights will never get you worse service or a worse price.
EU and UK residents have rights under the GDPR and UK GDPR, including the right to lodge a complaint with a supervisory authority.
To exercise any right, write to privacy@taxottic.com. We respond within 30 days. If a company put you on Taxottic, we may need to route your request to that company, and we will tell you if we do.
Retention
We retain your data while your account is active. When you delete your account, personal data is deleted within 30 days from production systems and within 90 days from encrypted backups. We may retain de-identified, aggregated data.
Location data. Raw GPS fixes are deleted 30 days after they are built into a trip, and a fix that never became a trip is closed out at 45 days and deleted 30 days after that. Device-health history is deleted after 30 days. Completed trips and their route lines have no automatic expiry and are kept until you delete them or the account is deleted.
Companies and bank connections, 30-day recycle bin. When you close a company or disconnect a bank, the item moves to a per-user recycle bin at /settings/recycle-bin. During the 30-day grace window you can restore it in one click or delete it immediately. After 30 days it is hard-deleted automatically, the company with all its income, expenses, and transactions, or the bank connection with its accounts and historical transactions. We do not keep a separate archive of deleted customers.
Tax records. Reports and exports you have generated follow IRS retention guidance, typically 7 years from the relevant tax year. You may delete them earlier from the app. Billing records are kept as long as tax and accounting law requires.
Chat and Bella conversations are kept until you delete them or the account is deleted.
Firm activity log, 365-day rolling retention. Firms running on the Taxottic cockpit generate an event stream (document uploads, signature dispatches, invoice sends, notes added). Rows older than 365 days are deleted by a nightly job. The window covers a full tax cycle plus a buffer for amended returns. Tenants who need pre-retention rows for a specific investigation can ask trust@taxottic.com; we can serve them from point-in-time recovery snapshots for up to seven additional days.
Cross-tenant access log, indefinite retention. When a Taxottic support engineer accesses a tenant's data on the tenant's behalf, always recorded against the engineer's identity and never anonymised, the event is appended to an access log. These records are retained indefinitely and are visible to the account owner in the in-app audit log.
You can always export everything we have on you first, at /settings/data. The download is a single JSON file including items currently in the recycle bin.
Children
Taxottic is for adults. You must be at least 18 to hold an account, and the service is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has signed up, write to privacy@taxottic.com and we will delete the account.
Cookies
We use a small number of cookies, all of them strictly necessary for sign-in, passkeys, and security. We do not set advertising or cross-site tracking cookies, and we do not load third-party tracking pixels. Details: /legal/cookies.
Security
Our security posture is summarised at /legal/security. If you believe you have found a vulnerability, please email security@taxottic.com. We respond within 2 business days.
Google API user-data policy
When you sign in with Google, we receive your name, email address, and profile picture via the OpenID Connect openid email profile scopes. Taxottic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not share it with third parties for advertising, and do not use it for any purpose other than authenticating your Taxottic session and personalising your account.
Changes
We will tell you (in-app banner and email) when we make material changes. Routine updates are reflected by the "Last updated" date at the top of this page.