Privacy policy
What TaxoTax processes, why it is needed, which providers touch it, how long it is kept and the rights you hold.
Effective 20 July 2026. Controller: RELMOS AG, Weieracherstrasse 4, CH-8184 Bachenbülach, Switzerland — info@relmos.ch.
Paid checkout is disabled in this deployment.
1. Data you provide
Scoping and preparing a brief uses your situation description, the structured scope you confirm and an email address for delivery. Depending on what you write, this can include residence, citizenship, household, approximate asset bands, income sources and timing. Do not include names, account numbers, tax identifiers or documents unless they are necessary for the question.
2. Data kept in your browser
The intake draft, selected currency and any checkout claim are kept in session storage for the current browser tab. The checkout claim lets the completion page retrieve a private report only in the tab that opened Stripe. Your colour-scheme choice is kept in local storage. TaxoTax sets no advertising cookies and embeds no advertising trackers.
TaxoTax uses a first-party, data-minimised funnel count to understand whether visitors can move from the landing page to a delivered brief. It uses a random identifier limited to the current tab; the identifier is salted and hashed before storage. An event contains only the stage name, the page path without query parameters and, for the first landing view, at most the referring site's hostname. Payment, report and refund stages come from server-side state, not browser claims. Funnel events contain no email address, raw network address, description or report scope, and no data is sent to an analytics vendor. Browser Do Not Track and Global Privacy Control signals disable the browser events.
3. Scoping, generation and security
The scoping step sends your description to Anthropic once to structure a plan that you can correct. If you continue, the confirmed scope is used for research, verification, report generation and delivery. Abuse controls use a salted hash of the network address rather than storing the raw address. Cloudflare country information is signed for the checkout availability check.
4. Checkout and billing data
Stripe collects payment and billing details on its hosted checkout. TaxoTax receives limited transaction data needed to fulfil and account for the order, such as the Stripe session and payment references, payment status, amount, currency, billing country, tax status and refund status. TaxoTax does not receive or store your full card number or security code. Checkout payloads are bound to a single browser claim; Stripe's redirect alone cannot reveal a report token.
5. Why data is processed
Data is processed to take steps you request before a contract, perform an accepted order, deliver and secure the service, prevent abuse, measure and improve the reliability of the purchase flow, meet accounting obligations and handle legal claims. Where consent is legally required for immediate digital performance, that consent and its version are recorded with the order. Mandatory legal bases depend on the law applicable to you.
6. Service providers
These providers process data for TaxoTax under their applicable contractual and data-protection terms:
— Cloudflare, Inc. — site hosting, content delivery and the country availability check.
— Supabase — database and server-side report functions in the project's configured AWS Zürich region.
— Anthropic, PBC — model processing for scope, research and drafting under commercial API terms.
— Resend — transactional delivery email.
— Stripe — hosted checkout, payment, tax calculation where configured, fraud controls and refunds.
Some providers operate internationally. Where required, transfers are covered by recognised contractual or statutory safeguards. Provider-specific location and subprocessor details can change; current provider documentation governs those services.
7. Retention
The completed brief, confirmed scope and delivery address are scheduled for deletion 12 months after delivery. An abandoned checkout expires after 30 minutes; its intake payload is then normally purged within 48 hours. Pseudonymous funnel events are deleted after 13 months. Funnel and checkout abuse counters are deleted after a few days; other daily service-capacity counters are deleted within 32 days. Transaction, invoice, tax and refund records may be retained longer where Swiss or other applicable bookkeeping law requires it. Security logs are retained only for the operational and legal period for which they are needed.
8. Your choices and rights
You can request access, correction, deletion or a portable copy, and object to or restrict processing where the Swiss FADP or applicable EU/EEA law provides those rights. Contact info@relmos.ch. Some billing records cannot be deleted before statutory retention periods expire. You can also complain to the Swiss Federal Data Protection and Information Commissioner or your competent local authority.
9. Changes
Material changes are published on this page with a new effective date before they take effect. Live payment activation remains gated on final legal, tax, security and end-to-end review.