Tax60 Legal Process and Data Custody Policy
Version 1.0 · Effective September 1, 2026 · Last updated September 1, 2026
Effective September 1, 2026. This Policy states how PLUSH LLC, a Puerto Rico limited liability company doing business as Tax60, handles subpoenas, summonses, warrants, court orders, and other requests for information about our users, and how legal holds work. It is a public commitment that binds us; it is incorporated into our Terms of Service (https://tax60.app/legal/terms) and Privacy Policy (https://tax60.app/legal/privacy). A copy is available inside the app under Settings › Legal.
Service of process and requester questions: legal@tax60.app, or by mail to PLUSH LLC, Attn: Legal Process, 348 Calle Mendez Vigo 1001, Dorado, PR 00646, United States.
1. Tax60 is a neutral record-keeper
Tax60 keeps the record; the record belongs to the user. We are not a party to any user's tax position, we do not advocate for or against it, and we do not evaluate it. The value of a Tax60 record to an examiner, a court, or the user is that Tax60 could not have altered it and, under our custody architecture, could not have read it.
We take the same posture toward everyone who asks us for information: the user's own request is always honored in full; everyone else receives only what valid, specific legal process compels, and only after the steps in this Policy.
2. What we hold, and what we can and cannot produce
2.1 What exists on our servers
Everything a user records — location samples, jurisdiction classifications, day records, hours worked, payors, attached documents, decree details, medical-exception tags and certifications, the change log, and computed presence-test figures — is encrypted on the user's iPhone with a key only the user holds before it is uploaded. Our servers store ciphertext and, for each record, a server-signed hash commitment. Tax60 holds no decryption key and has no technical means of producing readable versions of that data. This is not a policy choice that could be changed on request; it is how the system is built.
2.2 What we can produce under valid legal process
| Category | Contents |
|---|---|
| Subscriber information | Account email address (or Apple private-relay address); name if the user shared it through Sign in with Apple; Apple user identifier; Tax60 account identifier; account creation date; account status |
| Billing information | Subscription plan, status and dates; Apple transaction identifiers; for web purchases, the payment-processor customer and subscription identifiers (not card numbers, which we never hold) |
| Device information | Device model, iOS version, app version, app-generated device identifier, primary-device flag, current time zone, location-permission state, Background App Refresh state, last-upload timestamp, push tokens |
| Encrypted blobs | Ciphertext, blob kind, size, nonce, key identifier, the device-computed SHA-256 hash of the plaintext, the device's creation timestamp, and our receipt timestamp — none of which reveals content |
| Commitments | The user's hash chain: per-record hashes, chain hashes, server signatures, and server receipt times |
| Server logs | IP addresses, timestamps, request types and response codes, retained up to 30 days |
| Legal-hold records | Whether a hold exists, when it was placed, and by whom (user or Tax60) |
| Support correspondence | Messages the user sent to support or privacy addresses |
2.3 What we cannot produce for anyone
Readable location samples; the jurisdiction of any day; day types, confirmations, or edits; hours worked or payors; documents or their contents; decree numbers, home addresses, or attestations; medical-exception tags or certifications; presence-test results; the contents of any share or diagnostic grant. We cannot produce these because we cannot decrypt them, and we cannot compel, assist, or trick a user's device into decrypting them. A request for this material will be answered with a statement to that effect and this Policy.
3. When we disclose
3.1 Valid legal process only
We disclose information described in Section 2.2 only in response to legal process that is valid on its face, properly served, specific to identified accounts, and issued under U.S. federal, Puerto Rico, or state law. Recognized forms are:
- a subpoena issued by a court, a grand jury, or an agency with statutory subpoena authority;
- an Internal Revenue Service summons under IRC § 7602, including a third-party summons under IRC § 7609 and a John Doe summons approved by a federal court under IRC § 7609(f);
- a court order, including an order under 18 U.S.C. § 2703(d);
- a search warrant issued by a court on probable cause;
- a request from the Puerto Rico Department of the Treasury (Hacienda) or the Department of Economic Development and Commerce (DDEC) that is issued under, and complies with, a statute granting that agency compulsory process, served in the same manner as any other process.
We treat ourselves as a provider of remote computing services to the public within the meaning of the Stored Communications Act (18 U.S.C. §§ 2701–2713) and apply its protections as a floor: we do not voluntarily disclose the contents of stored records or subscriber records to any governmental entity (18 U.S.C. § 2702(a)), and we do not disclose the contents of stored records to private civil litigants in response to a civil subpoena, because the Act does not permit a provider to do so. Private litigants seeking a user's record must obtain it from the user, who alone can decrypt it.
3.2 No voluntary disclosure to tax authorities
We do not volunteer information to the Internal Revenue Service, Hacienda, DDEC, any state department of revenue, or any other tax authority. We do not participate in any information-sharing, data-matching, or referral program with any tax authority, and we will not sign any agreement to do so. The only channel through which a tax authority receives a Tax60 user's record is the user's own production.
3.3 Informal requests
Letters, emails, and telephone requests from government or private parties that are not legal process are declined, in writing, with a copy of this Policy. We do not confirm or deny whether a person is a user in response to an informal request.
3.4 Requests from outside the United States
We accept legal process only from U.S. federal, Puerto Rico, and state authorities. A foreign government or litigant must proceed through a mutual legal assistance treaty, a letter rogatory recognized by a U.S. court, or another U.S. legal mechanism.
3.5 Emergencies
We may disclose subscriber or device information (never the contents of any record, which we cannot read) to a governmental entity without process if we believe in good faith that an emergency involving imminent danger of death or serious physical injury requires it, as 18 U.S.C. § 2702(c)(4) permits. Any such disclosure is documented, reviewed by an administrator after the fact, counted in our transparency report, and notified to the user unless doing so would create the danger the disclosure sought to prevent.
4. What we do when process arrives
- Log it. Every request is entered in our internal register of legal process the day it is received, with its type, issuer, scope, accounts named, dates, and disposition.
- Review it. We check that the process is valid on its face, was properly served on PLUSH LLC, identifies specific accounts (by email, identifier, or other information sufficient to identify one account), states a lawful basis, and is limited to a reasonable time period and to information we actually hold.
- Place a legal hold on the named accounts (Section 6), so that nothing responsive is deleted by a retention setting or a deletion request while the matter is pending.
- Notify the user before compliance (Section 5).
- Narrow or contest where appropriate (Section 7).
- Produce the minimum. We produce only the specific categories in Section 2.2 that the process validly demands, in a form that preserves integrity (with hashes and, for commitments, the public key needed to verify signatures), with a custodian's cover statement describing exactly what was produced and what cannot be produced.
- Record the outcome in the register and count it in the transparency report.
We do not produce anything earlier than the law permits. For an IRC § 7609 third-party summons, we assemble responsive records but do not produce them before the twenty-fourth day after the IRS gives notice to the taxpayer, and we do not produce them at all while a timely petition to quash is pending, as the statute requires.
5. Notice to users
We notify the affected user by email, and by an in-app notice, before we comply with any legal process concerning their account, and we provide a copy of the process where the law allows, so that the user has the opportunity to seek to quash or narrow it. We give this notice in addition to any notice the requester is required to give (for example, the notice the IRS must give a taxpayer under IRC § 7609(a)).
We delay notice only when:
- a court order or a statute expressly prohibits notice (for example, an order under 18 U.S.C. § 2705(b)), in which case we ask that the prohibition be limited in duration and we notify the user as soon as it expires; or
- the process is a John Doe summons or other process issued in a proceeding the law makes ex parte, in which case we notify affected users as soon as the law permits.
When we are prohibited from giving notice, we still contest the prohibition where we have a good-faith basis to do so, and we count delayed-notice matters in the transparency report.
We do not delay notice merely because a requester asks us to. A request for delay that is not backed by an order or statute is declined.
6. Legal holds
A legal hold suspends retention pruning, date-range deletion, and account deletion for an account until the hold is released. Two kinds exist:
- Audit hold (placed by the user). A user with an open IRS or Hacienda examination, a DDEC inquiry, or litigation in which their record may be relevant can place an audit hold in Settings › Data › Audit hold. The user may release it at any time. The hold does not affect what the user can view, edit (with the change log), export, or share.
- Process hold (placed by Tax60). We place a hold on every account named in legal process on the day it arrives, and on any account for which we receive a lawful preservation request (a governmental entity may request preservation for 90 days, renewable once for a further 90 days, under 18 U.S.C. § 2703(f)). We release a process hold when the matter concludes, the preservation period lapses without process, or the process is withdrawn or quashed.
Holds are visible to the user in Settings, are printed on every export and binder generated while a hold is active, and cause a deletion request to be deferred with an explanation, never silently refused: deletion proceeds automatically when the hold is released. A hold never expands what we hold or what we can read.
7. Contesting overbroad, vague, and John Doe requests
We object to, seek to narrow, and where warranted move to quash process that:
- does not identify specific accounts (including "John Doe" summonses and class-wide subpoenas directed at Tax60 users as a group);
- seeks information we do not hold or cannot read, or is not limited to a reasonable time period;
- is unduly burdensome or is issued without the statutory prerequisites for the type of process (for example, a John Doe summons that lacks the court findings IRC § 7609(f) requires, or that is not narrowly tailored);
- is issued by a body without authority over PLUSH LLC; or
- seeks to compel us to alter our systems, to obtain a user's key, or to decrypt data.
We will not build, modify, or operate any feature for the purpose of enabling access to user records by anyone other than the user, and we will contest any order that would require us to do so.
Where a John Doe summons or class request is enforced despite our objection, we produce only the categories in Section 2.2 for only the accounts the court's order covers, and we notify every affected user as soon as the law permits.
The cost of reviewing, contesting, and responding to legal process directed at Tax60 is borne by Tax60 and recovered from requesters under Section 9. We never charge a user for our response to process concerning their account, whatever the outcome.
8. Records-custodian declarations and certifications
Because a Tax60 record is meant to be used, we make custodian support available to users and, under Section 9, to requesters.
- System declaration. On request we will sign a declaration or certification under Federal Rule of Evidence 902(11) and 902(13) (or the Puerto Rico and state equivalents) describing the Tax60 system: how records are captured on the device, how they are encrypted, how commitments are generated and chained, the server's signing keys and their published history, and how a produced record's hash and commitment can be verified. The declaration describes the system and the commitment chain; because we cannot read a user's record, it does not and cannot vouch for the content of any record.
- Commitment verification. For a record the user or a requester has decrypted and presents, we will confirm whether its hash appears in the user's commitment chain and the server receipt time attached to it. The public keys needed to verify every commitment independently are published at https://tax60.app/legal/keys, so this confirmation is a convenience, not a necessity.
- Testimony. Where a court requires live testimony from a Tax60 custodian, we will provide it under the fee schedule in Section 9.
Requests for declarations are made to legal@tax60.app and are fulfilled within 15 business days, or sooner on an expedited basis under Section 9.
9. Fee schedule for requesters
Fees are charged to the party that serves process or requests a declaration, are payable before production except where a statute requires production without prepayment, and are set to recover our actual cost. Where a statute fixes the amount a provider may recover (for example, 18 U.S.C. § 2706 for governmental requests), the statutory amount governs.
| Item | Fee |
|---|---|
| Search, retrieval and production of subscriber, billing, device, blob-metadata, commitment, log or hold records for one account | $200, including the first two hours of work; $100 per additional hour |
| Each additional account named in the same process | $100 |
| Custodian declaration or certification (FRE 902(11)/(13) or equivalent), including commitment verification for up to 25 records | $400 |
| Commitment verification beyond 25 records | $2 per record |
| Live testimony (deposition, hearing or trial), including preparation | $300 per hour, four-hour minimum, plus reasonable travel and lodging outside Puerto Rico |
| Expedited handling (production or declaration within 5 business days) | 50 percent surcharge |
| Copies on physical media, notarization, apostille, courier | Actual cost |
Users are never charged for process served on Tax60 concerning their own account. A user who wants a system declaration for their own examination or proceeding may request one at the declaration fee above; the fee is waived where the user's plan, as described at the time of purchase, includes custodian support.
10. Transparency report
Each year by March 31 we publish at https://tax60.app/transparency a report covering the prior calendar year (the first report covers September 1 through December 31, 2026) stating:
- the number of requests received, by type: IRS summons, IRS John Doe summons, grand jury subpoena, other government subpoena, civil subpoena, court order, search warrant, Hacienda or DDEC request, preservation request, emergency request, and informal request;
- the number of accounts named in each type;
- the number of requests we objected to, narrowed, or moved to quash, and the outcomes;
- the number of requests in which we produced anything, and what categories;
- the number of matters in which user notice was delayed by order or statute, and how many of those delays had expired by publication;
- the number of legal holds placed by Tax60 and by users; and
- a statement of whether we have ever been asked to, or ordered to, alter our systems to enable access to user records, and the outcome.
Where a law requires that certain counts be reported only in bands, we report the narrowest band the law allows and say so.
11. Continuity
If PLUSH LLC ceases operations, is acquired, or its administrators become unavailable, the commitments in this Policy travel with the servers: any successor receives ciphertext it cannot read, and our Terms of Service require the successor to honor this Policy or to give users notice and a window to export and delete first. Our continuity arrangements (two organization administrators, credential and source escrow, and a read-only continuity mode that keeps exports working) are described in Terms of Service Section 12.
12. Changes
We will announce material changes to this Policy at least 30 days before they take effect, by email and in the app, and we will archive prior versions at https://tax60.app/legal/legal-process/versions. No change will weaken Section 2 (custody), Section 3.2 (no voluntary disclosure to tax authorities), or Section 5 (notice) as applied to information already held.
13. Contact
Service of process: legal@tax60.app and by mail to PLUSH LLC, Attn: Legal Process, 348 Calle Mendez Vigo 1001, Dorado, PR 00646, United States. Email service is accepted for convenience; it does not waive any requirement of formal service. Users with questions: privacy@tax60.app.