Privacy Policy

Last updated: July 13, 2026

RAG Tax AI ("RAG Tax AI", "we", "us", or "the App") provides AI-assisted tax return review, workpaper preparation, client request workflows, tax research support, document analysis, accounting software integrations, and related CPA firm productivity tools. This Privacy Policy explains what information we collect, how we use it, how we protect it, and what choices authorized users have.

This policy is written for firms and professionals using RAG Tax AI in connection with tax, accounting, and advisory work. The App is not intended for children, consumer social use, or unrelated personal data processing.

1. Information we collect

2. How we use information

3. AI processing

RAG Tax AI uses third-party AI model providers, including Anthropic Claude, to process prompts and user-provided materials for the requested workflows. Information submitted for AI-assisted review may be sent to those providers solely to generate the requested output. We do not sell client data, and we do not use client tax documents, Google Workspace data, accounting data, or uploaded files to train generalized AI or machine-learning models. Users should review all AI-generated outputs before relying on them. The App is a professional assistance tool and does not replace qualified tax judgment, CPA review, or firm quality-control procedures.

4. Google API data

If you connect a Google account, RAG Tax AI uses Google data only to provide user-facing features requested inside the App, such as identifying the connected user's email address, reading only Drive files the user explicitly selects through Google Picker, and sending a reviewed email only after the user confirms the recipient and message. Depending on the scopes granted and the user's actions, raw Google user data may include the user's Google email address, selected Drive file metadata, selected Drive file content, user-reviewed outgoing email content, and OAuth token metadata. Aggregated or operational Google-related data may include connection status, timestamps, action type, audit events, and error diagnostics.

RAG Tax AI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The App does not sell Google user data, does not use Google user data for advertising, credit eligibility, lending, or unrelated profiling, and does not transfer Google user data except as necessary to provide or improve the requested user-facing feature, comply with law, secure the App, or process data through service providers operating under confidentiality and security obligations. Raw or derived Google Workspace API data is not used to develop, improve, or train generalized AI or machine-learning models, and it is not transferred to third-party AI providers for their model training. Refresh tokens are stored server-side and encrypted at rest when configured. A short-lived access token may be provided to an authenticated user's browser solely to display Google Picker and authorize files that user explicitly selects.

Google user data is retained only as long as needed to provide the connected workflow, maintain security/audit records, comply with legal obligations, or support user-requested operations. Users can revoke Google access from their Google Account or request deletion of connected-account data by contacting an administrator or the privacy contact listed below.

5. Accounting integrations

If you connect QuickBooks Online, Xero, or another accounting platform, RAG Tax AI uses the authorized connection to retrieve accounting reports and related business data needed for tax review, workpaper preparation, reconciliation, and analysis. OAuth tokens are stored server-side. Users can revoke access from within the relevant provider account or by contacting an administrator.

6. How we share information

We do not sell personal information, client tax information, Google user data, or accounting data. We may share information only with:

7. Data retention

Retention depends on the type of information and the purpose for which it is used. Account records, audit logs, cost logs, workflow records, access requests, and OAuth tokens may be retained while needed to operate the App, maintain security, support firm workflows, comply with legal obligations, or preserve business records. Uploaded files may be processed temporarily or retained when a workflow requires persistent storage. Stored document metadata includes retention information, and retained local documents may be removed when the configured retention period expires. Administrators may request deletion or revocation of user accounts, OAuth tokens, or stored records, subject to legal, tax, accounting, backup, and security requirements.

8. Security

RAG Tax AI uses administrative, technical, and organizational safeguards designed to protect information, including authenticated access, role separation, tenant or firm identifiers, HTTPS transport, server-side token handling, password hashing, budget enforcement, rate limiting, audit logging, and restricted server-side storage. No system can guarantee absolute security, so users should avoid uploading unnecessary sensitive information and should promptly report suspected unauthorized access.

9. Firm separation and access control

The App is designed so users, client records, budgets, and audit events can be associated with a firm or organization. Administrators should create accounts only for authorized personnel, assign appropriate roles, disable inactive users, and avoid sharing credentials. Access-control features are a safeguard, but each firm remains responsible for deciding who may access client materials.

10. Incident response

If we become aware of unauthorized access, data loss, or another security incident affecting App data, we will take reasonable steps to investigate, mitigate, preserve relevant records, and notify affected administrators when legally or contractually required. Users should promptly report suspicious account activity, exposed credentials, or misdirected client data.

11. User responsibilities

Users are responsible for ensuring they have authority to upload, connect, or process client materials in the App. Users should review generated outputs, preserve required source documents, follow firm policies, comply with applicable tax and privacy laws, and avoid sharing credentials or unauthorized access.

12. Your choices

13. Changes to this policy

We may update this Privacy Policy as the App evolves, including when new integrations, workflows, vendors, or security features are added. The "Last updated" date reflects the latest version.

14. Contact

For questions about this Privacy Policy, access, data deletion, or connected accounts, contact us at ramiroflores@ragtax-ia.com.