Tax60 Privacy Policy
Version 1.0 · Effective September 1, 2026 · Last updated September 1, 2026
Effective September 1, 2026. This Privacy Policy explains what PLUSH LLC, a Puerto Rico limited liability company doing business as Tax60 ("Tax60," "we," "us"), collects when you use the Tax60 iPhone app, the Tax60 web viewer, and the tax60.app website (together, the "Service"), what we do with it, and the choices and rights you have. It is written to be read in full; the most important facts are in Section 1.
Questions or requests go to privacy@tax60.app.
1. The short version
- Your record is yours, and we cannot read it. Location samples, jurisdiction classifications, day records, hours worked, payors, attached documents, decree details, medical-exception tags and their certifications are encrypted on your iPhone with a key that only you hold before anything is uploaded. Our servers store ciphertext and server-signed hash commitments. Tax60 has no key, no plaintext copy, and no way to produce readable versions of this data for anyone, including ourselves, a court, or a tax authority. Section 3 describes this architecture in detail.
- What we can see is a short list: your account email (or the Apple relay address), Apple's user identifier for you, device records and push tokens, your subscription state, when your device last uploaded, your device's location-permission and Background App Refresh state, your home time zone and reminder hour, and the metadata of the encrypted blobs (kind, size, hash, timestamps). Section 4 lists all of it.
- We never sell, share, rent, or license personal information, and we never use it for advertising. There is no advertising SDK in the app. We do not send personal information to any third-party artificial-intelligence service.
- Analytics contain no coordinates, no jurisdiction names, no day counts, no hours, and no decree data.
- Retention is your setting. Deletion has a seven-day grace period and completes within thirty days after it, subject only to legal holds.
- Adults only, U.S. and Puerto Rico only. Tax60 is not offered to anyone under 18 or to residents of the European Union, the European Economic Area, or the United Kingdom.
2. Who we are and what the Service does
Tax60 is a record-keeping tool for people who hold a Puerto Rico Act 60 tax decree. It records, on your iPhone, which jurisdiction you are in each calendar day (Puerto Rico, a U.S. state, another U.S. possession, or another country), the hours you clock in and out of work by jurisdiction, and the documents you attach as evidence. It computes the presence-test figures described in our published Methodology (https://tax60.app/legal/methodology) and produces exports and audit binders for you and the professionals you choose to share them with.
Tax60 is a record-keeper. It does not give tax, legal, or accounting advice. Our Terms of Service (https://tax60.app/legal/terms) govern your use of the Service; this Policy governs personal information.
3. Custody: how your record is protected and why we cannot read it
This section is the foundation of everything else in this Policy.
3.1 The architecture
- Your iPhone is the engine. Location capture, jurisdiction classification, day derivation, presence-test math, and binder generation all run on your device. There is no server-side copy of the rules engine that receives your data.
- Encryption happens before upload. Every record — location sample chunks, day records, work sessions, your profile (including your home base, decree details, and payors), document metadata, documents, presence snapshots, and the change log — is encrypted on your iPhone with AES-256-GCM using a 256-bit data key generated on your device during onboarding.
- You hold the key. Your data key is wrapped by a key-encryption key stored in your iCloud Keychain (which Apple end-to-end encrypts and synchronizes across your devices) and can be re-derived from a 24-word recovery phrase shown to you once during setup. Tax60 never receives your data key, your key-encryption key, or your recovery phrase. If you lose access to all of them, your record cannot be recovered by anyone, including us.
- Our servers store ciphertext plus commitments. For each encrypted blob, our servers store the ciphertext, the blob's kind, a nonce, the size, a SHA-256 hash of the plaintext computed on your device, your device's creation timestamp, and the time we received it. For each blob we also generate a commitment: a server-signed (Ed25519) record chaining the blob's hash to your previous commitment with the server's receipt time. The commitment proves when a record existed and that it has not changed since — without giving us any ability to read it.
- Sharing is yours to grant. The only ways your readable record leaves your device are actions you take: your own exports (CSV and JSON, the automatic monthly export to your own iCloud Drive, and the PDF binder and evidence ZIP in the app versions that generate them), a share link you create for a CPA or attorney (the decryption key travels in the link fragment and never reaches our servers), and the web viewer, which decrypts in your browser using a key handed off from your phone by QR code or typed from your recovery phrase. Each of these channels exists only in the app versions that include it, and none of them changes the custody design.
- Support cannot see your data either. If you want us to look at a problem, you create a diagnostic grant in Settings: your phone packages app logs and health state (never your location samples, documents, or day contents unless you deliberately include specific records), encrypts the package, and shows you a one-time key. Only if you give that key to support can we open that package, and the grant expires automatically.
3.2 What this means in practice
- We cannot answer "where was this user on March 3" for anyone. We cannot run reports across users. We cannot restore a record for a user who has lost their keys.
- A subpoena, summons, court order, or data breach reaching our servers yields ciphertext, commitments, and the account metadata listed in Section 4 — nothing readable about your location, jurisdictions, hours, documents, or decree. Our Legal Process Policy (https://tax60.app/legal/legal-process) explains exactly what we do when we receive legal process.
- Apple's App Store privacy label for Tax60 lists "Precise Location — linked to you" because Apple's definitions count any location data transmitted off the device, in any form. That label is accurate as to transmission and does not mean we can read it.
4. Information we collect, and what we can and cannot see
4.1 Information that exists only in encrypted form (Tax60 cannot read it)
| Category | Examples | Source |
|---|---|---|
| Precise location | Latitude/longitude fixes with accuracy radius, timestamps, visit arrivals/departures, geofence events; on-device classification results (jurisdiction, marine band, ambiguity flags) | Your iPhone's Location Services, with your permission |
| Day records | Jurisdictions touched each day with time ranges, day type (work/vacation/holiday/sick), confidence, confirmations, edits and reasons, exception tags (transit, medical, disaster) and their checklists | Your device and your entries |
| Work ledger | Clock-in/clock-out sessions, hours split by jurisdiction, payor names and office states | Your entries |
| Profile | Home base address, decree type, decree vintage, application filing date, elections, attestations for presence tests 4 and 5, activity chips, consent records | Your entries |
| Documents | Boarding passes, receipts, lodging folios, physician statements and other files you attach, and their metadata | Your camera, photo library, Files, or share sheet |
| Medical-exception data | Days tagged as qualifying medical treatment (yours, or a parent's, spouse's or child's whom you accompanied) and attached certifications | Your entries; see our Consumer Health Data Privacy Notice (https://tax60.app/legal/health-data) |
| Computed outputs | Presence snapshots, per-state counts, Form 8898 figures, binder contents | Computed on your device |
| Change log | Append-only history of edits and overrides, permission-state changes recorded as coverage evidence | Your device |
4.2 Information our servers hold in the clear
| Data | Why we hold it | Retention |
|---|---|---|
| Account email address, or the Sign in with Apple private-relay address if you hide your email | Sign-in, receipts, security and legal notices, transactional email | Life of the account, then deleted with the account |
| Apple user identifier (the stable identifier Sign in with Apple assigns to you for Tax60) and your Tax60 account ID | Authenticating you | Life of the account |
| Name, only if you choose to share it through Sign in with Apple | Addressing you in email | Life of the account; you may remove it in Settings |
| Device records: device model, iOS version, app version, an app-generated device identifier, whether the device is your primary presence device, current IANA time zone | Multi-device rules, compatibility, scheduling reminders in your time zone | Until you remove the device or delete the account |
| Push tokens (Apple Push Notification service tokens for alerts, widgets and, where enabled, Live Activities) | Delivering content-free push notifications | Until the token is invalidated by Apple or the device is removed |
| Location-permission state (Always / While Using / Denied; Precise on/off), Background App Refresh state, Low Power Mode state, and the time of your device's last upload | Tracking-health alerts ("Always was turned off," "no uploads for 24 hours") and catch-up reminders | Current state only, plus the last-upload timestamp |
| Home time zone, evening reminder hour, onboarding flags, rules pack in use | Scheduling reminders; showing the right features | Life of the account |
Subscription state: plan, status, renewal date, Apple originalTransactionId and appTransactionId, billing plan type, purchase channel; for web purchases, the Stripe customer and subscription identifiers |
Entitlement; receipts; refunds; tax and accounting records | Life of the account; billing records retained as long as tax and accounting law requires (seven years) |
| Encrypted-blob metadata: kind, size, nonce, key identifier, the SHA-256 hash of the plaintext computed on your device, your device's creation time, our receipt time | Storage, sync, integrity | Per your retention setting (Section 6) |
| Commitments: hash chain entries with server signatures and receipt times | Contemporaneity proof | Never deleted while the account exists; deleted with the account |
| Legal-hold flags you set or we set on receipt of legal process | Suspending deletion while a hold is active | Until released |
| Share grants (expiry, access count) and diagnostic grants (expiry, one-time key hash) | Operating shares and support diagnostics you create | Until expiry or revocation |
| Server request logs: IP address, timestamps, request type, response code, user agent | Security, abuse prevention, debugging | Up to 30 days |
| Support correspondence sent to support@tax60.app, privacy@tax60.app, legal@tax60.app or hello@tax60.app | Helping you; keeping a record of requests | Three years after the last message |
| Launch-list email address, if you ask on tax60.app to be told when Tax60 is released, and then confirm by opening the link we email you. Stored as a contact with our email provider (Resend), with the date you confirmed. Nothing is stored if you never open that link | Sending you one email when Tax60 is on the App Store | Until you unsubscribe, until you ask us to remove you, or until 30 days after that release email is sent, whichever comes first. One-click unsubscribe in the email, or write to hello@tax60.app |
| Consent records for location, health-data tagging and marketing email (text version and timestamp) | Demonstrating consent | The consent record for location and health tagging lives inside your encrypted profile; a hash of it and the version number are kept in the clear for the life of the account |
4.3 Information from Apple
When you use Sign in with Apple, Apple gives us a stable user identifier, your email or a private-relay address, and (if you allow it) your name. When you subscribe through the App Store, Apple gives us signed transaction information (product, dates, status, transaction identifiers) and App Store Server Notifications about renewals, refunds and billing problems. Apple does not give us your payment card or Apple ID password, and we never ask for them.
If you hide your email, Apple issues a relay address on privaterelay.appleid.com or private.icloud.com. We register our sending domain with Apple's relay service so that our receipts and notices reach you; Apple forwards them, and we never learn your real address unless you add it in Settings yourself. If you later add an email address, we store it as your account email and stop using the relay address for new messages.
4.4 Information from our website
The tax60.app website is a marketing site with a free presence-test calculator. The calculator runs entirely in your browser and does not send your inputs to us. Our website hosting provider records standard request logs (IP address, pages, timestamps) for up to 30 days.
The site also has a launch list. If you enter your email address there, we send that address one email containing a confirmation link and store nothing. Your address becomes a contact with our email provider only when you open that link, and only then; the link expires after 48 hours, and if you never open it your address is not kept anywhere. The release email carries a one-click unsubscribe link, and hello@tax60.app removes you on request. The launch list is separate from any Tax60 account, is never merged with account data, and is used for that one announcement and nothing else. To stop abuse of the form we count requests per network address in server memory for up to a day and record no other information about you; we do not use cookies, pixels, or tracking of any kind on the site.
If you sign in to the web viewer, in the app versions that include it, we authenticate you with a one-time code sent to your email address, or with Sign in with Apple; decryption happens in your browser and nothing decrypted is sent to our servers.
4.5 Information we do not collect
We do not collect your Social Security number, taxpayer identification number, decree number in the clear, contacts, calendar, photos other than the ones you attach, health records from HealthKit, browsing history, advertising identifier, or any information from data brokers. We do not use cookies for advertising or cross-site tracking, and the app uses no advertising or attribution SDK.
5. How we use information
We use the information in Section 4.2 only to:
- Provide the Service you asked for: authenticate you, store and return your encrypted blobs, generate commitments, deliver content-free push reminders, keep your subscription active, and operate exports and shares you create.
- Keep the Service reliable and secure: detect abuse, enforce owner-only access to storage, investigate crashes, and respond to security incidents.
- Communicate with you about your account: receipts, renewal and trial-ending notices, security notices, changes to these documents, and legal notices.
- Send product news, only if you opt in, and you can opt out with one tap in any such email; and, if you confirmed a launch-list request on tax60.app, tell you once that Tax60 has been released.
- Comply with law, respond to valid legal process as described in our Legal Process Policy, enforce our Terms, and protect rights and safety.
We do not use personal information to build profiles, to make automated decisions with legal or similarly significant effects, or for any purpose incompatible with the one you gave it to us for. We do not train any machine-learning or AI model on user data.
Analytics and crash reporting. The app records a small set of product events (for example, "onboarding completed," "day confirmed," "Always permission downgraded," "export generated") and crash reports. These are tagged with app version, iOS version, device model, and a random per-install identifier that is not linked to your account. They contain no coordinates, no jurisdiction names, no day counts, no hours, no payor names, no document contents, and no decree data. Crash reports are scrubbed of location breadcrumbs before they leave your device. Our current providers are listed at https://tax60.app/legal/subprocessors.
Push notifications. Every push we send is content-free: it carries a type and an identifier, and the text you see ("Today: Puerto Rico · 6 h 12 m — confirm your day") is composed on your iPhone by the app's notification extension from your local, decrypted store. Apple's push service never sees your location or hours.
6. Retention
Retention of your encrypted record is a setting you control in Settings › Data › Retention:
| Tier | Raw location sample chunks | Day records, work sessions, documents, change log, commitments |
|---|---|---|
| Full evidence (default) | Kept for the life of your decree plus seven years; chunks older than one year move to cold storage | Kept for the life of the account |
| Balanced | Kept three years | Kept for the life of the account |
| Minimal | Kept 90 days (the app warns that this weakens the record) | Kept for the life of the account |
Day records are never automatically deleted under any tier, because they are the record. You may delete a date range of your record; the deletion is carried out on your device and our servers, and the fact that a range was deleted (dates only, not contents) is permanently noted in your exports so that the record's integrity statement stays truthful.
Account-level metadata is retained as stated in Section 4.2. When you cancel a subscription, nothing is deleted: tracking continues locally, export stays free, and cloud sync becomes read-only until you resubscribe or delete the account.
7. Deletion
You may delete your account at any time in Settings › Data › Delete account or by emailing privacy@tax60.app from your account email.
- The app first asks you to download your evidence, because deletion is irreversible and we cannot recover a deleted record for you.
- Deletion starts a seven-day grace period during which you can cancel it by signing in.
- After the grace period we permanently delete your encrypted blobs, stored objects, commitments, device records, push tokens, share and diagnostic grants, and profile within 30 days, and delete your authentication account. Our deletion job verifies that zero rows remain for your account.
- What survives deletion, and why: billing records that tax and accounting law require us to keep (seven years); entries in our internal register of legal process, if any process concerning your account was received; support correspondence for three years; and aggregate analytics that were never linked to you.
- Legal holds. If you have placed an audit hold on your account (for an open examination or litigation), or we have placed one because we received legal process concerning your account, deletion is deferred, not refused: we tell you the hold exists, and deletion proceeds automatically when the hold is released. See the Legal Process Policy for how holds work.
Deleting the app from your iPhone does not delete your account or your cloud data; use the deletion control above.
8. No sale, no sharing, no advertising, no third-party AI
- We have never sold or shared personal information for money or any other consideration and we never will. This includes precise location, which is the most valuable thing a data broker could ask us for and the one thing we structurally cannot provide.
- We do not disclose personal information to third parties for their own marketing, and we do not engage in "sharing" for cross-context behavioral advertising as California law defines it.
- We do not send personal information to any third-party artificial-intelligence or large-language-model service. If we ever offer a feature that would send any of your data to such a service, it will be off by default and require your explicit, separate consent at the moment you turn it on, as Apple's App Review Guideline 5.1.2(i) requires.
- Because we do not sell or share personal information, there is nothing to opt out of; we nonetheless honor Global Privacy Control signals on tax60.app as a valid opt-out request.
9. Service providers who process data for us
We use a small number of service providers ("processors") who act only on our instructions and who are contractually prohibited from using your information for anything else. They receive only what is necessary for their function; none of them receives a decryption key. The current list, with each provider's role, location, and what it receives, is maintained at https://tax60.app/legal/subprocessors and is part of this Policy. As of the effective date, the categories are:
- Apple (Sign in with Apple, App Store billing, Apple Push Notification service, iCloud Keychain and iCloud Drive on your own Apple account).
- Database, object storage and authentication hosting on infrastructure located in the United States (AWS us-east-2, Ohio). This provider holds ciphertext, commitments and the metadata in Section 4.2.
- Website hosting for tax60.app and the web viewer.
- Transactional email delivery for receipts and notices, and for the launch-list confirmation and release announcement described in Section 4.4.
- Web payments processing for purchases made on tax60.app; the processor, not Tax60, holds your card details.
- Crash reporting and product analytics as described in Section 5.
We will update the subprocessor list at least 30 days before a new provider begins receiving personal information, except where an emergency replacement is needed to keep the Service running, in which case we update the list as soon as practicable.
10. Other disclosures
We disclose personal information outside Sections 8 and 9 only:
- To you, and to people you direct us to share with (a share link you create).
- Under valid legal process, strictly as set out in our Legal Process Policy: only on a valid, specific subpoena, summons, warrant or court order; never voluntarily to any tax authority; with notice to you before compliance unless a court or statute prohibits it; and with what exists to produce limited to ciphertext, commitments and the account metadata in Section 4.2.
- To protect life and safety, where we believe in good faith that disclosure of account metadata is necessary to prevent imminent danger of death or serious physical injury, as permitted by 18 U.S.C. § 2702(c)(4); we have never made such a disclosure and would report it in our transparency report.
- In a change of control. If Tax60 is acquired or merges, your information transfers with the Service under this Policy, and we will notify you at least 30 days before any transfer that would change how your information is handled, with time to export and delete first. The custody architecture in Section 3 cannot be changed retroactively: any successor inherits ciphertext it cannot read.
11. Your consent for sensitive data, and how to withdraw it
Precise location, information about medical treatment, and the contents of documents you attach are "sensitive" under the state privacy laws that apply to Tax60. We collect them only with your opt-in consent, only as strictly necessary to provide the Service you have requested, and never for any other purpose.
- Location. The app asks for "While Using" location permission after a screen that explains exactly what is collected, and asks for "Always" permission separately, after you have seen the app work. The text you consented to and the time are stored, encrypted, in your profile. You may withdraw consent at any time in iPhone Settings › Privacy & Security › Location Services › Tax60; the app continues to work in manual mode (you enter each day's jurisdiction yourself), and nothing about your subscription changes.
- Medical-exception tags. The first time you tag a day as qualifying medical treatment, the app shows the Consumer Health Data Privacy Notice and asks for your consent before saving the tag. You may withdraw by removing the tag, deleting attached certifications, or deleting the account.
- Documents. You choose every document you attach, and you may delete any of them.
- Marketing email and the launch list. Off by default. Product news is opt-in in Settings, and every such email carries a one-click unsubscribe link. The tax60.app launch list is double opt-in: your address is stored only after you open the confirmation link we email you, and the release email carries the same one-click unsubscribe link (Section 4.4).
12. Your privacy rights
Tax60 gives every user, wherever in the United States or Puerto Rico you live, the rights below. We extend them regardless of whether a particular state statute applies to a company of our size, and we apply the strictest applicable timeline to every request.
12.1 The rights
- Know and access. Confirm whether we process personal information about you and receive a copy of it, including the categories of personal information, sources, purposes, and the categories (and, for residents of states whose laws provide it, the names) of third parties to whom personal information was disclosed. The list of third parties is the subprocessor list; we disclose to no others.
- Portability. Receive your information in a portable, machine-readable form. Your complete record (all records, documents, raw samples and the commitment chain) is exportable at any time in Settings, free, including after your subscription lapses, in CSV and JSON and, in the app versions that generate it, as a full evidence ZIP.
- Correct. Correct inaccurate personal information. Your record is correctable by you inside the app (every correction is logged, and the original is preserved); account metadata can be corrected in Settings or by request.
- Delete. Delete personal information, as described in Section 7.
- Opt out of sale, sharing, targeted advertising and profiling. We do none of these, so the opt-out is permanently in effect for every user.
- Limit use of sensitive personal information. We already use sensitive information only for purposes that California law treats as necessary to provide the requested service (Cal. Code Regs. tit. 11, § 7027(m)); you may nonetheless ask us to confirm this in writing.
- Withdraw consent to sensitive-data processing at any time (Section 11).
- Non-discrimination. We will not deny the Service, charge a different price, or provide a different level of quality because you exercised a right.
- Appeal. If we decline a request, you may appeal (Section 12.3).
12.2 How to exercise a right
- In the app: Settings › Data (export, delete, retention, holds) and Settings › Account (email, name, devices).
- By email: privacy@tax60.app, from your account email address. If you write from another address, we will verify you by sending a confirmation to your account email or by asking you to confirm from inside the app. We match requests to the account using only the email address and Apple identifier; we will never ask for your recovery phrase, and no legitimate Tax60 message ever will.
- By mail: PLUSH LLC, Attn: Privacy, 348 Calle Mendez Vigo 1001, Dorado, PR 00646, United States.
- Through an authorized agent: the agent must provide your signed written permission, and we will still verify your identity directly with you and confirm that you authorized the request. Requests under a power of attorney valid under Puerto Rico or state law are accepted without a separate permission.
We respond within 45 days of receiving a verifiable request. If we need more time (at most 45 additional days), we tell you why before the first 45 days end. We do not charge for requests unless they are manifestly unfounded, excessive, or repetitive (more than twice in a twelve-month period), in which case we may charge a reasonable fee or decline, and we will explain our decision.
12.3 Appeals
If we decline all or part of a request, you may appeal by replying to our decision or emailing privacy@tax60.app with "Appeal" in the subject line. A different person than the one who decided your request reviews the appeal, and we answer in writing within 45 days, explaining the reasons for the decision. If we deny the appeal, our answer includes how to contact your state attorney general or privacy regulator to submit a complaint. Residents of Puerto Rico may contact the Puerto Rico Department of Consumer Affairs (DACO).
12.4 California
This subsection is our notice at collection under the California Consumer Privacy Act as amended by the California Privacy Rights Act. In the preceding twelve months we collected the following categories of personal information (Cal. Civ. Code § 1798.140(v)), from the sources and for the business purposes in Sections 4 and 5:
| Category | Collected | Sold or shared | Disclosed to processors |
|---|---|---|---|
| Identifiers (email, account ID, Apple user ID, device ID, push token, IP address) | Yes | No | Yes (hosting, email, payments) |
| Personal records (name, subscription and payment records — card details are held by Apple or the payment processor, not us) | Yes | No | Yes (hosting, payments) |
| Commercial information (subscription history) | Yes | No | Yes (hosting) |
| Internet or network activity (app events, server logs) | Yes | No | Yes (hosting, analytics, crash reporting) |
| Geolocation data (precise; encrypted on your device with your key) | Yes | No | Yes (hosting, as ciphertext only) |
| Audio, visual or similar (documents and photos you attach; encrypted) | Yes | No | Yes (hosting, as ciphertext only) |
| Professional or employment information (payors, hours; encrypted) | Yes | No | Yes (hosting, as ciphertext only) |
| Sensitive personal information: precise geolocation, health-related information you tag, contents of documents, account log-in via Apple identifier | Yes | No | Yes (hosting, as ciphertext only) |
| Inferences | No | No | No |
| Biometric information, characteristics of protected classifications, education information | No | No | No |
We do not sell or share personal information, including that of consumers under 16 (we have no such consumers). We do not offer financial incentives in exchange for personal information. Retention for each category is stated in Sections 4 and 6. California's "Shine the Light" law (Civ. Code § 1798.83): we do not disclose personal information to third parties for their direct-marketing purposes.
12.5 Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states
Residents of these states have the rights in Section 12.1 under their state's law, exercised as in Section 12.2, with the appeal process in Section 12.3. Specifically:
- We obtain opt-in consent before processing sensitive data (precise geolocation and health-related tags) and process it only when strictly necessary to provide the Service you requested, which is the standard Maryland's Online Data Privacy Act imposes; we never sell sensitive data, consent notwithstanding.
- We conduct no targeted advertising, no sale, and no profiling in furtherance of decisions that produce legal or similarly significant effects.
- We recognize universal opt-out mechanisms (such as Global Privacy Control) on tax60.app.
- We maintain a written data protection assessment covering our processing of sensitive data, and we make it available to state regulators on request as the law provides.
- Residents of Oregon, Minnesota and Delaware may request the list of specific third parties to which we have disclosed personal information; that list is the subprocessor list.
12.6 Nevada
We do not sell covered information as Nevada Revised Statutes Chapter 603A defines the term. Nevada's consumer health data law (SB 370) is addressed in our Consumer Health Data Privacy Notice.
12.7 Washington
Washington's My Health My Data Act is addressed in our Consumer Health Data Privacy Notice (https://tax60.app/legal/health-data), which is part of this Policy.
13. Children
Tax60 is for adults. We do not offer the Service to, and do not knowingly collect personal information from, anyone under 18. If we learn that an account belongs to someone under 18, we delete the account and its data. If you believe a minor has an account, email privacy@tax60.app.
14. Where the Service is offered, and where data lives
Tax60 is offered only to residents of the United States and Puerto Rico through the U.S. App Store storefront and tax60.app. It is not offered to residents of the European Union, the European Economic Area, or the United Kingdom, and we do not market to them; if you reside there, do not use the Service. Traveling abroad with the app is fine: the app keeps working, and your data stays encrypted with your key wherever you are.
Our servers are located in the United States (AWS us-east-2, Ohio) with our website and web viewer served from U.S. edge infrastructure. Apple services operate under Apple's own privacy terms and infrastructure.
15. Security
- Encryption: AES-256-GCM on device with per-user 256-bit data keys (Apple CryptoKit); keys wrapped in your iCloud Keychain and recoverable from a 24-word phrase derived with HKDF from the BIP39 word list; key rotation re-wraps the key and never re-encrypts history. Server signatures are Ed25519 with the private key held in Supabase Vault, encrypted at rest with a provider-managed key kept outside the database, never in the app or in our repository, and readable only by our server-side signing function; the history of public keys is published at https://tax60.app/legal/keys so that any commitment can be verified independently.
- Transport: TLS 1.2 or higher for every connection; App Transport Security enforced.
- Access control: row-level security on every database table and storage prefix so that an account can read and write only its own rows; encrypted blobs and commitments are insert-only (history is never overwritten); service credentials exist only in server-side functions and are never shipped in the app; production access by Tax60 personnel is limited to the two organization administrators, audited, and cannot yield readable user records.
- Verification: automated tests prove owner isolation on every table and storage prefix, that protected columns reject writes, and that a deleted account leaves zero rows.
- Device: local storage is protected by iOS Data Protection; the app can require Face ID to open and always requires it to reveal your recovery phrase.
- Backups: encrypted backups of the blob store are kept with a second provider in the United States; backups contain ciphertext only.
No system is perfectly secure. If a breach affects information in Section 4.2, we will notify you without unreasonable delay and within the time required by law, and we will notify the Puerto Rico Department of Consumer Affairs (DACO) as Puerto Rico Act 111-2005 requires and any other regulator whose law applies. A breach of ciphertext alone does not expose your record, and we will say so plainly if that is what happened.
16. Changes to this Policy
We will notify you of material changes at least 30 days before they take effect, by email to your account address and by a notice in the app, and we will keep a dated archive of prior versions at https://tax60.app/legal/privacy/versions. No change will retroactively weaken the custody architecture in Section 3 or permit sale, sharing, advertising use, or third-party-AI processing of your data; those would require a new, explicit, opt-in consent that we have no plan to ask for. Continued use after the effective date of a change means you accept it; if you do not, export and delete your account before that date.
17. Contact
PLUSH LLC, doing business as Tax60 348 Calle Mendez Vigo 1001, Dorado, PR 00646, United States
- Privacy requests and questions: privacy@tax60.app
- Legal notices and legal process: legal@tax60.app
- Support: support@tax60.app
Related documents: Terms of Service (https://tax60.app/legal/terms) · Consumer Health Data Privacy Notice (https://tax60.app/legal/health-data) · Legal Process Policy (https://tax60.app/legal/legal-process) · Methodology (https://tax60.app/legal/methodology) · Subprocessors (https://tax60.app/legal/subprocessors) · Transparency Report (https://tax60.app/transparency)