Legal

Privacy Policy

We built DeductSam to help you find money, not to sell your data. Here is exactly what we collect, why, and how it is protected.

Last updated: July 2026  ·  Effective: July 2026

This Privacy Policy describes how DeductSam LLC ("DeductSam," "we," "us," or "our") collects, uses, and shares information when you use our website at deductsam.com and our application at app.deductsam.com (collectively, the "Service"). By using the Service, you agree to the collection and use of information as described in this policy.

1. Information We Collect

Information you provide directly

When you create an account or use the Service, we collect:

  • Account information — your name, email address, and password (stored as a secure hash — see Section 4).
  • Business profile — the type of business you operate, whether you use a home office or vehicle for work, number of employees, state of operation, and other context you share during the onboarding interview. This is used exclusively to personalize Sam's guidance.
  • Expense data — merchants, amounts, dates, categories, notes, and business purpose descriptions you enter for your expenses.
  • Receipts and documents — images and PDFs you upload. Receipt files are stored in encrypted cloud storage and accessed only to perform optical character recognition (OCR) and match them to your expenses.
  • Invoice data — client names, email addresses, amounts, and line items for invoices you create inside the Service.
  • Payroll and contractor data — if you use the payroll tracking feature, you may enter wage, salary, and contractor payment information.
  • Stripe Connect onboarding (only if you choose to get paid through invoices) — DeductSam lets you connect your own Stripe account so your clients can pay your invoices. If you start that setup, DeductSam sends you to Stripe's own hosted onboarding, and the information Stripe asks for there goes to Stripe directly, not through us: your legal name and business details, your address and date of birth, a government identification number where Stripe requires one, and your bank account details for payouts. That collection is governed by Stripe's own privacy policy and the Stripe agreement you accept with them — DeductSam is not a party to it and never sees, receives, or stores those details.

    What DeductSam stores from that process is only what it needs to know whether invoicing works: your Stripe account identifier, two status flags (whether Stripe has enabled charges, and whether you finished the onboarding form), and the date you connected. Nothing else. You can disconnect at any time in Settings.
  • Household tax facts — if you use a Personal workspace, you can record a small set of structured answers that the app's household checks need in order to run: whether you have a spouse and whether they have employment income; whether you or your spouse have a workplace retirement plan; whether anyone in the household is a student; whether you own or rent your home; whether you paid for childcare this year; the state you live in; your total tax and adjusted gross income from last year's return; and the birth years of your children. You can also add a free-text note in your own words.

    This is the one category that includes information about people other than you — a spouse, and children who may be minors. Three things about how we handle it:
    • We store birth years, never names or full dates of birth. This is deliberate. A birth year is all the tax rules need — a child's age at the end of the tax year decides whether a credit or an exemption applies — and it is far less identifying than a name or a full date of birth. The app has nowhere to enter a child's name.
    • Nothing is saved until you confirm it. Where the app proposes these facts by reading a description you already wrote, it shows you each proposed answer and the sentence it came from, and writes nothing until you confirm. You can change any answer, or leave it unanswered, at any time in Settings.
    • It is used only to run tax checks for your own return — for example, whether a childcare or education credit is worth discussing with your preparer. It is never used for advertising or profiling, never sold, and never shared with anyone outside the service providers listed in Section 3.
    These answers are stored under your account, protected by the same row-level security as the rest of your data (Section 4), and are deleted with your account (Section 6).

Information collected automatically

  • Usage data — pages visited, features used, and general interaction patterns. This is used to improve the product, not to build advertising profiles.
  • Error and diagnostic reports — if the application crashes or encounters an error, a report is sent to our error monitoring provider, Sentry. It includes the error message, a stack trace, the app version, the device model and OS version, and the IP address the request came from. It does not include the content of your financial records. This is diagnostic data used to fix faults. We do not use it for advertising, we do not combine it with data from other companies' apps or websites, and DeductSam contains no advertising identifier and no third-party analytics or tracking SDKs.
  • Authentication tokens — short-lived session tokens managed by Supabase Auth. We do not store your password in plaintext at any point.

The DeductSam iOS app

This policy covers the DeductSam iOS application distributed on the Apple App Store as well as the web application at app.deductsam.com. The iOS app collects the following in addition to everything above:

  • Location — only while you are tracking a drive. The mileage feature uses your device's GPS to measure the distance of a drive for the IRS standard mileage deduction. The app requests "While Using the App" location permission — never "Always" — and location is collected only between the moment you tap Start drive and the moment the drive is stopped, paused, or automatically ended. Because a drive must keep measuring while your phone is locked or you are using another app, tracking continues in the background during an active drive only; iOS displays its standard indicator whenever this is happening. We store the resulting trip records (distance, start and end time, and the route points needed to compute distance) so the deduction is substantiated if it is ever questioned. We do not track your location when no drive is running, and we do not use location for advertising or sell it to anyone. You can decline location permission entirely and still use every other part of DeductSam; you can revoke it at any time in iOS Settings.
  • Camera, photo library, and microphone — used only when you photograph or attach a receipt, or dictate a note. When you dictate, the short audio clip is sent to OpenAI to be transcribed into text and is discarded immediately after transcription — it is never written to our database or storage. Each permission is requested at the moment you use the feature and each can be declined without affecting the rest of the app.
  • Device and app identifiers — your account identifier, and the device model and OS version attached to error reports, used to operate the app and diagnose faults. DeductSam does not create or read a device or installation identifier. DeductSam does not collect the Advertising Identifier (IDFA), does not ask for tracking permission, and does not track you across other companies' apps or websites.
  • App Store purchase records — if you subscribe inside the iOS app, Apple provides us a purchase receipt and a subscription transaction identifier so we can verify your subscription and unlock paid features. See the in-app purchases entry in Section 3.
  • Notifications — notifications in the iOS app are generated locally on your device (for example, a reminder that a drive is still running, or a count of transactions awaiting review). We do not operate a push server and we do not collect a push notification device token.

Information from connected services

If you choose to connect third-party services, we collect data from those services on your behalf:

  • Plaid (bank and credit card sync — Pro plan) — with your explicit authorization, Plaid provides us read-only access to your transaction history. We receive transaction amounts, dates, merchant names, and categories. We do not receive your full account number, routing number, or login credentials — Plaid handles that directly. You can revoke access at any time from Settings.
  • Square (revenue sync — Pro plan, coming soon) — Square integration is not yet available, so we do not currently receive any data from Square. When it launches, connecting Square will let us receive your sales and payment data to populate your income ledger. We will not access customer data, refund information, or employee records from Square beyond what is needed to calculate your revenue.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service
  • Power Sam's AI analysis — identifying potential deductions, generating Tax Health scores, creating Year-End Packets, and responding to your questions
  • Perform OCR on receipts you upload so they can be automatically matched to expenses
  • Send invoices to clients on your behalf when you use the email send features
  • Process payments and manage your subscription via Stripe
  • Send you transactional emails (receipt confirmations, subscription renewals, security alerts)
  • Diagnose and fix technical errors
  • Comply with applicable legal obligations

We do not use your data to train AI models for external use, sell your information to advertisers, or build advertising profiles.

3. How We Share Your Information

We share your information only as necessary to operate the Service:

Service providers

We work with the following companies to deliver the Service. Each receives only the minimum data necessary to perform their function:

  • Supabase — database and file storage. Your data is stored in Supabase-managed PostgreSQL databases and object storage, encrypted at rest.
  • OpenAI — powers Sam's AI capabilities. We send expense descriptions, merchant names, receipt text, business profile details, invoice line items, and — when you use dictation — the short audio clip for transcription (discarded after transcribing) to OpenAI's API to generate Sam's responses. We do not send Social Security numbers, bank account numbers, government IDs, or your email address to OpenAI. OpenAI processes this data under their API data usage policy.
  • Stripe — payment processing, in two separate roles. (1) Your subscription to DeductSam: Stripe collects and processes your payment information directly; DeductSam does not store full card numbers or CVV codes. (2) Invoice payments from your clients (Stripe Connect): if you connect your own Stripe account, your client pays your Stripe account directly and the money lands in your Stripe balance — it never passes through a DeductSam account, and we take no fee from it. Your identity and bank details for that account are held by Stripe under your agreement with them, not by us.
  • Plaid — bank data access. Plaid acts as the intermediary between DeductSam and your financial institution. Your banking credentials go directly to Plaid, not to us.
  • Apple (In-App Purchase / StoreKit) — if you subscribe from inside the iOS app, the transaction is processed by Apple, not by us. Apple handles your payment method entirely; we never see or store your card details. We receive a purchase receipt and a subscription identifier, which we verify with Apple to confirm your subscription status. Billing, renewals, refunds, and cancellation for an App Store subscription are managed by Apple in your Apple Account settings.
  • Sentry — error monitoring. Sentry receives anonymized error reports. Error reports do not include your financial data.
  • Resend — transactional email delivery. Resend sends emails on our behalf, including invites and the invoice emails you send to clients. Resend receives recipient email addresses and message content for these emails. If you contact us through the in-app support form, the message you write (and the category you pick) is emailed to our support address through Resend; it is not stored in our database.
  • Vercel — application hosting. Your requests pass through Vercel's infrastructure to reach our servers.
  • Microsoft Clarity — website analytics on our marketing site only (deductsam.com). Clarity records session replays and builds heatmaps of the marketing pages you visit — which pages you view, where you scroll, and where you click — so we can see which explanations are working. It runs only if you accept cookies in the banner; decline and it is switched off and any Clarity cookie already set is erased. Clarity is not present in the DeductSam app. Your expenses, income, receipts, bank transactions, invoices, and household facts are never seen by Clarity, because it is not loaded on any screen that shows them.

Legal requirements

We may disclose your information if required by law, legal process, or government request — for example, in response to a court order or subpoena. We will notify you of any such request if permitted to do so.

Business transfers

If DeductSam is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.

With your consent

We will share your information with additional parties only with your explicit consent.

4. How We Protect Your Data

  • Encryption at rest — all data stored in Supabase databases and file storage is encrypted using AES-256.
  • Encryption in transit — all connections to DeductSam use TLS 1.2 or higher. HSTS headers ensure browsers enforce HTTPS for all future visits.
  • Row-level security (RLS) — Supabase RLS policies enforce that every database query is scoped to your authenticated user ID. You cannot query another user's data.
  • Passwords — we never store your password in plaintext. Authentication is managed by Supabase Auth, which uses bcrypt hashing.
  • Two-factor authentication — you can enable TOTP-based two-factor authentication from Settings. Recovery codes are hashed before storage.
  • API keys — all third-party API keys (Plaid, OpenAI, Stripe) live only on our servers. They are never bundled into the frontend application code.
  • Rate limiting — all API endpoints are rate-limited to protect against abuse.

No method of transmission over the internet is 100% secure. We take reasonable precautions, but cannot guarantee absolute security.

5. Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • Your personal data is deleted from our production database immediately — the deletion runs while you wait, not on a queue.
  • Receipt and document files are deleted from storage in the same operation.
  • Backup copies may persist for up to 90 days before being overwritten.
  • Anonymized, aggregated usage data (with no personally identifiable information) may be retained indefinitely for product analytics.

Two things deletion does not reach — stated plainly

Deleting your account removes your records from our systems, including your receipts and documents in storage, and revokes any bank connection at Plaid. Two things sit outside that, and we would rather say so than let you assume otherwise:

  • Your Stripe customer record. If you subscribed through Stripe, we cancel your subscription when you delete your account, but Stripe keeps its own record of the transactions. Stripe is required to retain payment records under its own legal, accounting, and anti-fraud obligations, and that retention is governed by Stripe's privacy policy, not ours. The same is true of any Stripe account you created to get paid on invoices — that account is yours, it belongs to you rather than to DeductSam, and deleting your DeductSam account does not close it.
  • Error and diagnostic reports. The crash and error reports described in Section 1 are held by Sentry and are not deleted when you delete your account. They age out automatically on Sentry's retention schedule. These reports contain the error message, a stack trace, app and device version, and the originating IP address — never the content of your financial records.

6. Your Rights

You have the right to:

  • Access your data — you can export all your expense data and invoices from Settings at any time.
  • Correct your data — you can edit any expense, business profile field, or account detail directly in the app.
  • Delete your account — you can delete your account from Settings › Account. Deletion is permanent and cannot be undone.
  • Revoke third-party access — you can disconnect Plaid at any time from Settings › Integrations. (Square support is coming soon and will be similarly revocable.)
  • Opt out of AI processing — you can choose not to use Sam's AI features. Expense entry without AI assistance is available on all plans.

If you are a resident of California, the EU, or another jurisdiction with specific privacy laws, you may have additional rights. Contact us at admin@deductsam.com to exercise any of these rights.

7. Children's Privacy

The Service is not directed at children, and children do not use it. We do not knowingly collect personal information from a child, and no child can create an account.

There is one place where an adult account holder may record information about their own children: the household tax facts described in Section 1. If you tell us you have children, we store their birth years only — never their names, and never a full date of birth — because a child's age at the end of the tax year is what decides whether certain credits apply to your return. You enter it, you can change or remove it at any time in Settings, and it is deleted with your account.

If you believe a child has provided us information directly, please contact us and we will delete it promptly.

8. Cookies and Tracking

We use a minimal set of cookies:

  • Session cookies — required for authentication. These expire when you close your browser unless you select "Remember me."
  • Preference cookies — stores your cookie consent choice and billing preference (monthly/annual). Stored in localStorage, not transmitted to our servers.

We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that build profiles across the web.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the app at least 14 days before the change takes effect. Continued use of the Service after a change constitutes your acceptance of the updated policy.

10. Contact Us

If you have questions, concerns, or requests regarding your privacy, please contact us at:

DeductSam LLC
Email: admin@deductsam.com

We will respond to all privacy inquiries within 10 business days.