Privacy Policy
We built this product for the most privacy-sensitive documents people have, and the policy is shaped by one rule: your documents are used to give you your data back, and for nothing else.
Last updated: 26 July 2026
1. What we process, and why
Documents you scan. Uploaded images and PDFs, and the structured data extracted from them (which can include names, addresses, SSNs/EINs, wages, and account details). Processed for one purpose: producing your result. For a plain scan nothing is stored — files are held in memory for the request and discarded with the result.
Documents you choose to store. If your organization has enabled encrypted storage and you save a scan, the extracted data is stored encrypted at rest under your organization’s own key — including listing metadata such as the form type and tax year. Stored documents are deleted automatically after the organization’s retention window (default 72 hours; configurable from 1 hour to 1 year by its administrators).
Account data. Name, email, password (secure hash only), page balance and purchase history, organization memberships, and a security audit log (logins and login failures, email-code verification, API token issuance, document access and saves, retention and encryption-key changes). The audit log records that an action happened — never document content — is tamper-evident, and is kept for 365 days.
Anonymous usage analytics. Our own consent-based, first-party analytics measure aggregate page usage over short (30-minute) anonymous sessions. They honor Do Not Track and Global Privacy Control, are never linked to your account or your documents, and can be erased or switched off any time via “Tracking settings” in the footer.
2. What we never do with your data
Document content and extracted data are never used to train or improve AI models (ours or any third party’s), never used for marketing or advertising, never analysed for any purpose beyond providing the Service, and never sold or shared with data brokers. This is a commitment consistent with the confidentiality obligations that apply to tax return information (26 U.S.C. §7216).
3. Who processes data on our behalf
Three subprocessors, each doing one job:
Google (Gemini API) — reads your documents to perform the
extraction, under Google’s paid-tier terms: content is not used to train or improve
Google’s models and is processed under a data processing agreement.
Stripe — payment processing. Card details go directly to Stripe
and never touch our servers.
Our hosting provider — runs the infrastructure the Service is
deployed on.
4. Retention at a glance
Plain scans: not stored. Saved organization documents: 72 hours by default, or the window your organization sets (1 hour–1 year). Security audit log: 365 days. Account data: for the life of the account. Analytics sessions: 30 minutes, aggregate statistics only.
5. Your rights
Regardless of where you live, you can ask us to access, correct, or delete the personal data we hold about you, and we will act on the request within 30 days. Email contact@taxdocscanner.com from the address on your account. Organization-stored documents belong to the organization; direct requests about them to its administrators, who can delete them or shorten retention at any time.
6. Security and breach notification
Encryption in transit and at rest, mandatory email second-factor on logins, per-organization encryption keys, and a tamper-evident audit trail — the full picture is on the security page. If a breach affects your personal data, we will notify you and the authorities required by your state’s law without undue delay after we become aware of it.
7. Cookies
Two first-party cookies: the session cookie that keeps you signed in, and (only with your consent) a 30-minute anonymous analytics session cookie. No advertising cookies, no third-party trackers.
8. Changes and contact
Material changes to this policy are reflected in the date above and notified to the email on your account. Questions: contact@taxdocscanner.com.