Effective August 13, 2026
Privacy Policy
This policy describes the current SargoTax AI applications, their local record-organizing features, optional bank sync, optional cloud AI, analytics, and privacy choices.
Current application
SargoTax AI organizes expenses, mileage, and educational tax estimates. Local matching, statement extraction, and other local features can be used without cloud AI or bank sync. Expense, mileage, receipt, and estimate records remain on the customer’s device unless the app clearly identifies a cloud feature and the customer chooses to use it.
The current iPhone / iPad App Store build of SargoTax AI does not send personal data to OpenAI or another third-party AI service. Merchant suggestions, Schedule C categorization, statement OCR, and tax estimates in that iOS build run on-device.
Account information
When account access is available and you sign in, Supabase processes the email address, account or authentication-provider identifier, and security-session information needed to create and protect the account. If you use Apple or Google sign-in, your Apple or Google password is handled by that provider and is not shared with SargoTax.
Account security
The website protects account sessions with encrypted HTTPS connections and browser security controls. The Supabase access token is used to authenticate optional cloud AI and optional bank-sync requests; it is not included in merchant data sent to the AI model, and it is never a bank password.
Information entered in the app
Questionnaire choices, household facts, dates, eligibility categories, entered financial amounts, expense transactions, mileage trips, and locally selected receipts are processed on the device.
Optional bank sync
Bank linking is optional and off until a signed-in customer turns on a separate bank-sync consent control and connects an institution through Plaid Link. Bank login credentials are entered only inside Plaid and are not stored by SargoTax. When connected, SargoTax’s protected service stores connection metadata (institution name, status, sync cursor) and synced purchase fields needed for expense review (such as date, merchant description, amount, pending state, provider identifiers, and suggested category metadata) in the customer’s Supabase expense workspace. Plaid access tokens are stored only on the server in encrypted form and are never sent to the browser.
Customers can disconnect an institution, stop syncing, and request removal of synced purchase rows from the cloud workspace. PDF and CSV statement import remains available as a device-local fallback that does not require bank sync. Bank sync does not create mileage trips and is not tax advice; every synced purchase starts unclassified until the customer marks business or personal and confirms a category.
Optional cloud AI merchant review
Cloud AI is off until a signed-in customer turns on the AI consent switch. When enabled, SargoTax sends OpenAI only the merchant description, a temporary transaction identifier, the identifiers and names of available expense categories, and the consent-policy version. The purpose is to suggest a standardized merchant name and an expense category. SargoTax does not send transaction dates or amounts, the original PDF or CSV statement, receipt image, account number, statement balance, full statement text, business purpose, mileage route, or notes to OpenAI for this feature.
The app records the consent version and the time consent was granted or revoked in local device storage. Turning the switch off revokes consent, stops automatic review, and cancels an active request. Local merchant matching remains available. AI suggestions are not tax advice, use confidence controls, never replace a customer-confirmed category, and can be undone or separated by the customer.
AI requests are sent through SargoTax’s protected service after Supabase verifies the signed-in session. The model request is submitted with response storage disabled. OpenAI and Supabase may process limited service, security, and diagnostic information under their respective service terms and privacy practices.
Sensitive information
SargoTax does not ask for full Social Security or taxpayer identification numbers or bank-login credentials. Bank passwords are handled only by Plaid during Link. Do not enter those values in notes, descriptions, or support messages.
Location
The iPhone app requests location only after a customer starts mileage tracking. Optional background access is used only for a trip the customer chose to record. Completed trips store dates, mileage, classification, and purpose—not a map of the route—and customers can delete local mileage data in the app.
Support communications
If you email support, we receive the information in your message, including your email address and issue description. Support messages are used to respond to requests and maintain the product. Do not include taxpayer data.
Tracking and advertising
The public SargoTax homepage, public feature pages, support page, and privacy page use Google Analytics to understand basic visits, such as the page viewed, approximate session and device information, and referral source. Public marketing pages also record anonymous selections using fixed event names and placements, such as starting the estimator, opening the expense tracker, choosing Go Pro, or following an available app-store link. Google may use cookies or similar technologies to provide this measurement service. SargoTax disables Google Signals, advertising-personalization signals, and automatic enhanced measurement for this website analytics configuration.
Analytics is disabled for the tax estimator, expenses, account, dashboard, sign-in callback, and the installed Apple apps. Direct visits to those areas do not initialize analytics, and public-to-private navigation uses a fresh page load as an additional boundary. SargoTax sends only a sanitized public page address without query strings or fragments. When a public campaign link is used, SargoTax may keep only validated source, medium, campaign, and content labels for the current browser-tab session so later public-button selections can be attributed to that campaign. Raw query strings, duplicate or malformed campaign values, and all other query parameters are discarded from analytics.
SargoTax does not configure Google Analytics to receive clicked text, destination URLs, tax-estimator answers, financial amounts, imported statement or receipt contents, account passwords, Social Security numbers, bank-account details, mileage routes, or cloud AI merchant descriptions. The current application does not sell personal information and does not include advertising or cross-app tracking. You may limit cookies through your browser settings. Learn more in Google’s Privacy Policy.
Your choices
You may keep cloud AI off, revoke AI consent at any time, keep bank sync off, revoke bank-sync consent, disconnect institutions, remove synced cloud purchase data, use local merchant matching and PDF/CSV import, clear local expense and mileage workspaces, remove individual receipt records, and turn location permission off in system settings. Signed-in customers can permanently delete their SargoTax account from Account → Delete account in the iPhone / iPad app, or by emailing gpluidze@gmail.com from the account email address. Deleting the account removes the cloud authentication record and cloud-owned sync data; local records on a device must also be cleared in the app unless you choose Delete account and local data. Apple subscriptions must be managed separately in Apple Account settings.
Contact
Privacy questions may be sent to gpluidze@gmail.com.