Deductsy ("we", "us", "our") operates the website deductsy.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service you agree to the practices described below.
1. Information we collect
Information you provide directly:
- Your account details. You can sign up with an email address and a password, with a one-time sign-in link sent to that address, or through Google. We always receive your email address; we receive a name only when Google supplies one. Accounts are held by our authentication provider, Supabase.
- Tax-planning inputs you enter — income, deductions, filing status, state and similar figures. We do not ask you to type your Social Security number or a government-issued ID, and we never receive the password to any bank, payroll or accounting account.
- Documents you choose to upload. If you upload a W-2 so the app can fill in its figures for you, we send that image or PDF to Anthropic’s API, which reads the numbers off it and returns them. A W-2 carries your Social Security number, so it is present in the document you upload even though we never ask you to type it and do not store it as a field of your account. Uploading is optional — every figure a W-2 supplies can be typed in by hand instead.
- Accounts you choose to connect. If you connect your books we use QuickBooks or Xero. You enter your credentials with that provider, not with us; we receive the accounting data they return, and never the login itself. Connecting is optional.
- Email correspondence you send to support@deductsy.com, and anything you send through the support form — including a screenshot or PDF you attach to it.
Information collected automatically:
- Standard server logs (IP address, browser type, pages visited, referrer) collected by GitHub Pages, our hosting provider.
- Anonymous performance metrics (page load time, interaction latency) to monitor site health. No personally identifying information is included.
- Cookies and similar storage: essential storage that keeps you signed in (Supabase); Google Analytics cookies (such as _ga) that tell visits apart; and Microsoft Clarity cookies (_clck and _clsk, plus Microsoft’s own cookies such as MUID) that join page views into sessions. The analytics cookies are not needed for the Service to work, and they are off by default for visitors in the EEA, the UK and Switzerland.
- Google Analytics, on public pages only. We use Google Analytics to measure visits to our public pages, such as the home page, guides, calculators and blog. It records the page address, with anything after a “?” or “#” removed except standard campaign tags (such as utm_source) that say which link or ad brought you; the page title; the site that referred you; and your browser, device and approximate location, which Google estimates from your IP address. On our calculators it also records which calculator you used and, on state calculators, the state — never the numbers you enter or the results. On the sign-in page and every page of your account it is set to send nothing, apart from a notice, with no details attached, that a new account was created. We never send it your tax figures, your name or your email address. Google signals and ad personalization are turned off. Google Analytics uses its own cookies to tell visits apart; if you visit from the European Economic Area, the United Kingdom or Switzerland, that storage is denied by default and Google receives only cookieless signals that a page was viewed. See How Google uses information from sites or apps that use our services.
- Microsoft Clarity, on pages that don’t ask you for anything. We use Microsoft Clarity on our home page, guides, blog, state guides and pricing page, to see how they are used. It records sessions — how each page looks and changes, mouse movements, clicks and scrolling — and builds heatmaps. All text is masked in your browser before anything is sent, so a recording shows the layout of a page but not its words. We never use it on our calculators, on pages with a search box or a form, on the sign-in page, or on any page of your account, where your account and tax information is shown, and if a page we use it on ever gains a field, Clarity switches itself off there. Clarity records the address of each page it runs on, including anything after a “?” or “#”, so we also keep it off any address that carries a sign-in, password-reset or payment code. We never give Clarity your name, your email address or your account ID. Clarity sets first-party cookies (_clck, which keeps a Clarity user ID, and _clsk, which joins page views into one session), and Microsoft may set its own cookies (CLID, ANONCHK, MR, MUID and SM). If you visit from the European Economic Area, the United Kingdom or Switzerland, Clarity sets no cookies and treats each page view separately, because we do not ask for cookie consent. Third parties such as Microsoft collect personal data from visitors to our site through Clarity: Microsoft collects or receives this data from us and may use it, as described in the Microsoft Privacy Statement, to provide and improve its products, including Microsoft Advertising.
2. How we use information
- To operate the Service — running calculations, saving your scenarios, signing you in.
- To improve the Service — diagnosing errors and understanding which features are used.
- To respond to your support inquiries.
- To send you transactional emails (e.g., account-related notifications) if you've signed up.
We do not sell your personal information. We do not use your tax-planning inputs to target ads or share them with advertisers.
3. Service providers
We rely on the following providers to operate the Service:
- Supabase — authentication and database storage for your account and saved scenarios.
- Google — sign-in via Google OAuth, if you choose it, and Google Analytics on our public pages (see section 1).
- Microsoft — Microsoft Clarity session recordings and heatmaps, on our home page, guides, blog, state guides and pricing page only, with all text masked (see section 1).
- GitHub Pages — static site hosting and content delivery.
- Squarespace — domain registrar and DNS.
- ImprovMX — email forwarding for our support address.
- Resend — delivery of the emails we send you (sign-in links, password resets, reminders).
- Anthropic — reads the figures off a W-2 you upload, and only then. Your tax-planning inputs, saved scenarios and connected-account data are not sent to it.
- Stripe — payment processing for paid plans. Card details are entered with Stripe and never reach us.
- Intuit (QuickBooks) and Xero — accounting connections, if you choose to connect one.
- Web3Forms — delivers the support form to our inbox, including any file you attach to it.
Each provider is bound by its own privacy practices and data processing terms. The three optional ones — Anthropic, Intuit and Xero — receive nothing unless you upload a document or connect an account.
4. Affiliate links
Some pages on the Service contain affiliate links — links that may earn us a commission if you sign up for a third-party service through them, at no additional cost to you. When you click an affiliate link, the partner may set their own cookies and collect data according to their privacy policy. See our Affiliate Disclosure for the current list of partners.
5. Your choices
- Access and export: you can view and download all scenarios you've saved by signing in to the dashboard.
- Delete your data: email us at support@deductsy.com to request deletion of your account and all associated scenarios. We typically process requests within 7 business days.
- Cookies and analytics: you can clear cookies in your browser settings; clearing Deductsy’s sign-in storage signs you out. To stop Google Analytics, install Google’s opt-out browser add-on (https://tools.google.com/dlpage/gaoptout) or use a content blocker. A content blocker also stops Microsoft Clarity. The Service works the same without either.
6. Data retention
We retain your account information and saved scenarios for as long as your account is active. If you delete your account, we remove all associated data within 30 days. Anonymous server logs are retained for up to 90 days. Google Analytics keeps visit-level data for 14 months and then deletes it; aggregated reports are kept longer. Microsoft keeps Clarity recordings for 30 days, except recordings we mark as favorites and a random sample, which it keeps for up to 9 months.
7. Children
The Service is not directed to children under 13 (or under 16 in jurisdictions where that is the applicable threshold). We do not knowingly collect information from children. If you believe a child has provided us with information, please contact us and we will delete it.
8. Security
We use reasonable administrative and technical safeguards to protect your information, including encrypted connections (HTTPS) and access controls on our backend. No system is perfectly secure — we cannot guarantee that information is immune from unauthorized access.
9. International users
The Service is operated from the United States. If you access it from outside the U.S., your information will be transferred to and processed in the U.S. By using the Service you consent to this transfer.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. We will announce material changes, such as a new provider receiving information about your visits, on the Service and by email to account holders, and update the date above.
11. Contact
Questions about this policy or your data? Email support@deductsy.com.