← Back to AskTomG.AI

Privacy Policy

Effective: 2026-05-21 · Last updated: 2026-08-12

AskTomG.AI (the “Service”) is a tax-research product for US tax practitioners, operated by TAG26 LLC, an Arizona limited liability company (“we,” “us,” or “TAG26”). This policy explains what the Service collects about you, what we use it for, who else processes it on our behalf, how long we keep it, and the rights you have over it. We do not sell your personal information.

Plain-language summary

  • We collect your email, your two-factor authentication factor (if you enable it), your tax-research queries and the answers we return, sign-in metadata, basic analytics, and (when you subscribe) Stripe billing identifiers.
  • We send your queries to Anthropic to generate answers. Anthropic is contractually prohibited from training its models on Service traffic.
  • We do not sell personal information, and we do not share it for cross-context behavioral advertising outside of the analytics cookies described below, which you can disable.
  • You can request access, correction, deletion, or export of your data at any time by emailing [email protected].
  • You must not paste personally identifying client information (names, SSNs, EINs, addresses, account numbers) into the Service. The Service is built for research framed around facts and tax issues, not client records.

Information we collect

  • Account identifiers. The email address and password you sign in with — your password is stored only as a salted hash by our authentication provider; we never see or store it in plaintext — and, if you enable two-factor authentication, the time-based one-time-password (TOTP) factor you register.
  • Research content.The tax questions you submit, the model's responses, citation metadata, conversation history, and any feedback (thumbs, written comments) you voluntarily provide.
  • Sign-in audit log. For each sign-in, we record the originating IP address, the browser user-agent string, the session timestamp, and an approximate country/region/city derived from the IP via an IP-to-geolocation lookup service. We use this solely to detect anomalous sign-ins and to alert you by email when a sign-in occurs from a country you have not previously used. We do not derive or store precise (street-level) geolocation, and we do not use sign-in location data for any inferential, advertising, or profiling purpose.
  • Billing data. When you subscribe, Stripe Checkout collects your payment instrument and billing address. Stripe returns to us a customer ID, a subscription ID, the plan tier, and metadata about successful or failed charges. We never receive or store your card number, CVC, or full bank account number.
  • Analytics cookies and events. Google Analytics 4 (with Google Signals enabled for cross-device measurement and demographic estimation) and PostHog place first-party cookies in your browser to count pageviews, identify the source of inbound traffic, and measure feature usage. We pass a randomly generated user identifier to each service; we do not pass your email, name, or any tax-research content.
  • Support correspondence. If you email us, we retain that correspondence so we can respond and follow up.

How we use this information

  • To operate the Service and return research answers to you.
  • To authenticate you and protect your account from compromise, including the country-change sign-in alert.
  • To bill you, manage your subscription, and handle refunds and disputes.
  • To improve the Service: debug issues, evaluate retrieval quality, measure citation accuracy, and prioritize features. Internal evaluation uses your queries and our answers; it does not train any third-party AI model on your content.
  • To send you transactional messages (account verification and password-reset emails, security alerts, billing receipts, material policy changes). We do not send marketing email without your express opt-in.
  • To comply with our legal obligations, including tax-record retention and responses to lawful process.

Subprocessors and service providers

The following processors handle data on our behalf under written data-processing terms. We update this list when it changes; users are notified by email before a new processor with access to research content is added.

  • Anthropic, PBC— LLM inference for tax-research answers (queries and prompts). Anthropic's commercial API terms prohibit training their models on our traffic.
  • Supabase, Inc. — Postgres database, authentication service, file storage, and transactional email delivery (account verification, password-reset, and security-alert emails).
  • Amazon Web Services, Inc. — application hosting in the US-West-2 region.
  • Cloudflare, Inc. — DNS, content delivery, TLS termination, and DDoS protection at the network edge.
  • Stripe, Inc. — payment processing and subscription management.
  • IP-to-geolocation lookup service — country, region, and city derived from IP for the sign-in audit log only.
  • Google LLC (Google Analytics 4) — web analytics cookies.
  • PostHog, Inc. — product analytics cookies.

We do not sell personal information to any third party, and we do not disclose research content to anyone outside this list except (a) with your direction, (b) to enforce our terms or protect the rights, property, or safety of TAG26, our users, or the public, or (c) where compelled by valid legal process.

AI processing details

When you submit a question, the Service constructs a prompt that includes your query, conversation history within that thread, and retrieved authority excerpts (statute, regulation, case law, IRS guidance, etc.), and sends it to Anthropic's Claude API. Anthropic returns a response, which we render to you and store in your account. Anthropic processes the request only to generate the response, retains it briefly per their Trust Center policy (currently 30 days for abuse monitoring), and is contractually prohibited from training their models on our API traffic. We do not enable Anthropic's human-review or content-feedback features on our account.

Cookies, analytics, and tracking choices

The Service uses first-party cookies for authentication (required) and for analytics (optional). Our analytics layer covers Google Analytics 4 — including Google Signals for cross-device measurement and demographic estimation — and PostHog for product analytics.

You can opt out of analytics by:

  • Blocking or clearing this site’s cookies in your browser settings. Authentication cookies are required to stay signed in; blocking them will sign you out.
  • Installing the Google Analytics opt-out browser add-on.
  • Emailing [email protected] to request that we disable analytics for your account or exercise any of the privacy rights described below.

We do not sell your personal information, and we do not use it for cross-context behavioral advertising.

Security

  • All traffic is served over TLS 1.2 or higher.
  • Database storage is encrypted at rest. Backups are encrypted and access-controlled.
  • Two-factor authentication is required for administrator accounts and is available — and strongly recommended — for all accounts.
  • Administrative access to production systems requires hardware-bound credentials and is logged.
  • We continuously scan our application dependencies and container images for known vulnerabilities and patch on a risk-prioritized schedule.
  • No system is perfectly secure. If you believe your account has been compromised, email [email protected] immediately.

Data retention

  • Research content (questions, answers, conversation history, feedback): retained while your account is active. Deleted within 14 days of an account-deletion request.
  • Sign-in audit log (IP, user-agent, geolocation): retained for 12 months, then deleted.
  • Email verification & password-reset tokens: single-use and expire within minutes; not retained after use.
  • Analytics events (GA4, PostHog): retained for no longer than 14 months at the user-identifier level.
  • Billing records (Stripe customer ID, subscription history, invoices): retained for 7 years to comply with US tax-record requirements, even after account deletion.
  • Support correspondence: retained for 3 years after the last interaction.

Your privacy rights

Regardless of where you live, you may exercise the following rights with respect to data we hold about you:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to fix inaccurate information.
  • Deletion — ask us to delete your account and associated data, subject to the billing-record retention described above.
  • Portability — receive a machine-readable export (JSON format) consisting of your account email, your submitted queries, the model responses we returned to you, and your conversation history. The export does not include internally-generated retrieval metadata, ranking signals, our prompt templates, internal evaluation labels, or any data we have enriched or derived for our own analytics; those are not personal information for these purposes and are not included.
  • Opt outof analytics cookies and of any processing that qualifies as “sharing” under California law.
  • Withdraw consent to optional processing at any time.

To exercise any of these rights, email [email protected] from the address registered to the account. For deletion and portability requests, we may require additional identity verification matching at least two of: registered email address, account creation date, and most recent billing transaction (where applicable). We respond within 45 days; we may extend by an additional 45 days where reasonably necessary and will notify you. We will not discriminate against you for exercising your rights.

California residentshave specific rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), including the rights of access, correction, deletion, portability, to know about disclosures, to opt out of “selling” or “sharing,” and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising outside of the analytics cookies described above, which you may decline. We do not use sensitive personal information for purposes beyond those allowed without the right to limit. You may designate an authorized agent to make a request on your behalf; we will require reasonable verification.

Residents of Colorado, Connecticut, Virginia, Texas, Utah, Oregon, Montana, and other US states with comprehensive privacy laws have similar rights, including access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling decisions. The same request channel applies. Where state law provides an internal appeal process for denied requests, you may appeal by replying to our response within 60 days; appeals are reviewed by a different person than the one who handled the initial request.

Tax-practitioner ethics: do not upload client data

The Service is provided to licensed and unlicensed tax practitioners whose handling of client information is governed by Treasury Department Circular 230 (including §§10.21 and 10.51) and by state-bar, AICPA, or comparable professional rules. By using the Service, you agree that you will not submit, paste, upload, or otherwise transmit personally identifying client information, including but not limited to client names, Social Security numbers, employer identification numbers, account numbers, addresses, dates of birth, or any data that would constitute taxpayer return information under IRC §6103. The Service is designed for research framed around facts and tax issues, not client records. We may terminate access where we detect repeated misuse.

Children

The Service is not directed to, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a minor has registered for an account, please contact us, and we will delete the account.

Data-breach notification

If we determine that personal information held by us has been subject to a confirmed security breach that creates a reasonable likelihood of harm, we will notify affected users as soon as practicable after we have identified the affected accounts, and in any event within 30 days of confirmation, by email to the address registered to the account. Where state law requires faster notice, that law controls. Where required, we will also notify state attorneys general and other regulators on the timelines those laws specify.

International users

The Service is operated from, and data is stored in, the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States.

The Service focuses on US federal tax authority and is built for tax practitioners; its content is unlikely to be relevant outside that context. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your information is transferred to and processed in the United States, where data- protection laws may differ from those in your location. You may exercise any applicable rights over your information, including access and deletion, by contacting [email protected].

Deleting your account

To delete your account and all associated research content, email [email protected] from the address registered to the account. We will confirm within one business day and complete deletion within 14 days. Billing records will be retained for the period required by US tax law, typically 7 years, but will not be used for any purpose beyond legal compliance.

Changes to this policy

We will update the “Last updated” date above when we change this policy. Material changes — for example, adding a new subprocessor with access to research content, changing retention periods, or expanding the categories of data collected — will be announced by email to your account address before they take effect.

Contact

Questions, complaints, or privacy requests: [email protected]. A postal notice address is available on request for verified data-subject requests and lawful process. The data controller is TAG26 LLC, an Arizona limited liability company.

This policy is informational and does not create rights beyond those provided by applicable law. Where this policy conflicts with a mandatory provision of US state privacy law applicable to you, the mandatory provision controls.