Legal
Privacy Policy
How TaxSwarm protects firm, user, and client tax information across cloud and on-prem deployments.
1. Introduction
TaxSwarm AI, Inc. (“TaxSwarm,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, store, share, and protect information when you use our AI-powered tax strategy intelligence platform (the “Service”).
This policy applies to all users of our Service, including CPA firms, accounting professionals, and their authorized personnel. By using TaxSwarm, you agree to the practices described in this policy.
2. Information We Collect
2.1 Account Information
When you register for TaxSwarm, we collect your name, email address, firm name, professional credentials, billing information, and contact details.
2.2 Client Tax Data
To provide tax strategy analysis, our platform processes financial documents, tax returns (up to 7 years of history), income statements, balance sheets, entity structures, and other financial records you upload on behalf of your clients. You are the data controller for all client data; TaxSwarm acts as a data processor.
All client data processing is subject to IRC §7216 taxpayer consent requirements. You are responsible for obtaining appropriate written consent from your clients before uploading their tax return information to the platform.
2.3 Usage Data
We automatically collect information about how you interact with the Service, including log data, device information, IP addresses, browser type, pages visited, features used, and analysis requests.
2.4 Cookies & Tracking Technologies
We use the following types of cookies:
- Essential cookies: Required for authentication and session management
- Analytics cookies: Help us understand platform usage (with your consent)
- Preference cookies: Remember your settings and preferences
You can manage cookie preferences through your browser settings. We do not use third-party advertising cookies.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the TaxSwarm platform and its AI-driven tax strategy analysis
- Process and analyze financial data through our multi-agent swarm architecture
- Generate tax strategy recommendations, memos, and deliverables for CPA review
- Communicate with you about your account, updates, and support requests
- Ensure platform security, detect fraud, and prevent unauthorized access
- Comply with legal obligations, including tax regulations and data protection laws
- Improve our AI models and validation systems (using anonymized, aggregated data only; never individual client data)
4. Data Sharing & Disclosure
We do not sell your personal information or client data. We may share information only in the following limited circumstances:
- Service Providers: Trusted vendors who assist with hosting, analytics, and support, bound by strict data processing agreements
- Legal Requirements: When required by law, regulation, subpoena, or court order
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with advance notice)
- With Your Consent: When you explicitly authorize sharing
5. Data Storage & Security
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Our infrastructure is designed with SOC 2 compliance standards in mind, including strict access controls, audit logging, and network isolation.
5.1 On-Premise Deployment Option
For enterprise clients, TaxSwarm offers on-premise deployment on NVIDIA DGX infrastructure. With this option, all client data remains entirely within your own infrastructure and no data is transmitted to TaxSwarm servers.
5.2 Cloud Deployment
For cloud-hosted deployments, data is stored in United States cloud environments with SOC 2-aligned security controls. Client data is logically isolated per tenant.
5.3 AICPA Compliance
TaxSwarm is designed to support compliance with AICPA professional standards, including confidentiality requirements under the AICPA Code of Professional Conduct.
6. Data Retention
Our data retention periods are as follows:
- Account information: Retained for the duration of your subscription and 90 days after termination for account recovery
- Client tax data: Retained for the duration needed to complete analysis, or longer if you choose ongoing advisory storage. Minimum 7 years per IRS requirements
- Analysis results and strategy recommendations: Retained as part of your firm's engagement records, subject to the same 7-year minimum
- Audit logs: Retained for 7 years for regulatory compliance
- Usage logs: Retained for 12 months for security and analytics purposes
You may request deletion of client data at any time, subject to legal retention requirements.
7. Your Rights
7.1 GDPR Rights (EEA Users)
If you are located in the European Economic Area, you have the right to: access, rectify, erase, restrict processing, data portability, object to processing, and withdraw consent at any time.
7.2 CCPA Rights (California Residents)
California residents have the right to:
- Know what personal information we collect
- Request deletion of personal information
- Opt out of the sale of personal information (we do not sell data)
- Non-discrimination for exercising privacy rights
7.3 IRC §7216 Rights
As a CPA firm, you are responsible for managing your clients' rights under IRC §7216, which governs the use and disclosure of tax return information. TaxSwarm provides tools to help you document client consent and manage data access in compliance with these requirements.
7.4 Exercising Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within 30 days.
8. Children's Privacy
TaxSwarm is a B2B platform designed for professional use by licensed CPAs and accounting firms. We do not knowingly collect information from individuals under the age of 18. If we learn that we have inadvertently collected such information, we will promptly delete it.
9. International Data Transfers
If you access our Service from outside the United States, your data may be transferred to and processed in the United States. We implement appropriate safeguards, including Standard Contractual Clauses, to protect data transferred internationally.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service at least 30 days before they take effect. Your continued use of the Service after changes become effective constitutes acceptance.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us: