← taxytax.nl
Beta terms · draft, not yet legally reviewed
Privacy
Last updated 10 September 2026 · applies to the taxy macOS app and taxytax.nl
taxy is built so your bookkeeping stays on your own Mac. This page says, in plain
language, what stays with you, what leaves, who sees it, how long anything is kept,
and what you can switch off. No invented promises — just what the app actually does.
The short version: your books never leave your Mac. One thing does leave —
a receipt image, once, to be read. Everything else is you, your machine, and a file
you can delete.
Who is responsible
The controller for this data is the maker of taxy, based in the Netherlands. Questions, requests, complaints:
privacy@taxytax.nl, or the feedback button in the app — both
reach the maker directly, and there is only one of him.
What stays on your Mac
Every transaction, receipt, filing, mileage trip and setting lives in four local
databases on your Mac, plus a few preferences alongside it. Erasing your data clears
all four. There is no taxy account
and nothing syncs to a server. Scanned receipts are also copied into a dated archive
folder on your Mac, by year and quarter. None of this is visible to us, ever, unless
you choose to send us something yourself.
The technical detail
The four local databases are IndexedDB: prima-materia (version 5,
the ledger — stores for transactions, archive,
filings, filing_records and mileage_trips),
prima-materia-audit (the audit log), taxy-cache (already-read
receipts, so the same file is never sent twice) and taxy-fs-handles (the
folder permissions you granted). Your profile and
feedback preferences are in localStorage. Under the AVG/GDPR this is your own
processing on your own device — we are not a processor for it, because we cannot
reach it.
What leaves your Mac, and when
- Reading a new receipt. The image (or the text layer of a PDF) is sent
over the network to Anthropic's API — the AI behind Claude, which taxy uses to read
receipts — so it can pull out the amount, VAT and date. It is relayed by our
Cloudflare Worker, which does not store the image. Location and device metadata are
stripped before it leaves your Mac, and the file is renamed to a meaningless
content hash, so your real filename never crosses the wire.
- Everything else in your ledger needs no network connection at all.
Already-read receipts, all the maths, every export, every past year: offline.
- Foreign-currency conversion uses the official European Central Bank
reference rate for a receipt's own date — and that rate table ships inside taxy.
Nothing is asked of the ECB, and nothing about you leaves your Mac for it.
- A second AI is built in but switched off. taxy carries the wiring for
OpenAI as a fallback, in case Anthropic is ever unreachable. It is dormant: it
receives nothing today, and it cannot be reached until a quality gate is passed and
this page says so.
- Checking a supplier's VAT number. For a receipt from another EU country,
taxy asks the European Commission's VIES service whether that supplier's VAT number is
valid. The question goes straight from your Mac, so the Commission sees your IP address
along with the supplier's number — never your name, and never the receipt.
- Usage stats and crash reports — both off unless you turn them on. Never
your receipts, names or amounts. A crash report carries nothing that points back to
you — the app version, the platform, the error and when it happened — so if you ask us
to delete yours, we cannot find it to delete.
- Feedback and diagnostic reports travel to us only when you press the
button that sends them.
- Update checks. The app asks our Worker whether a newer version exists.
- After an update, once per step, whether it worked. taxy tells our Worker: a
random code for that one update attempt, not your install ID; the version before and
after; the update channel; whether it is an Apple-silicon or Intel Mac; the macOS major
version; which step it reached; an error code if it failed; and the day. Nothing else,
and no switch — this is how we know an update did not strand you.
Exactly what is stripped, per file type
JPEG and PNG: EXIF and XMP segments removed by a byte-walk, no re-encode. GIF:
comment blocks removed. WEBP: EXIF and XMP chunks removed. HEIC/HEIF: converted to
JPEG on your Mac before anything is sent, so the original container never leaves.
PDF: the /Info dictionary (author, creator, producer, title, subject,
keywords, dates) and the XMP metadata stream are stripped; the page content is
untouched, byte for byte.
One honest limit: we do not call an upload "anonymous." A receipt with
your name printed on it is identifiable by what is written on it, however carefully
the file itself is handled. Stripping metadata is not the same as anonymising, and
we will not pretend otherwise. For a PDF invoice with a text layer, the full text
of that invoice is what gets read — including your own name and VAT number if they
are printed on your own outgoing invoices.
Anthropic, and what they keep
Today, Anthropic's standard API retention applies to the receipts taxy sends
them. That is their policy on their systems, not ours, and it can change on their
end. We are telling you this plainly rather than implying the image evaporates.
What we are doing about it
We have asked Anthropic about Zero Data Retention (ZDR) for taxy's API account.
ZDR means the content of a request is not stored after the response is returned.
What we can promise regardless, because it is our own code: no name, no email
and no account identifier travels with a receipt, no per-user identifier is set on
the Anthropic request, and our own relay keeps no copy of the image.
What our server stores
We have no admin panel showing your receipts, your ledger or your filings — that
data never reaches us. Our Cloudflare database holds only this, and each row is tied
at most to a random install ID, never to your name:
- Extraction counters — one row per receipt read: a short content hash,
which model handled it, how long it took, what it cost us, whether it worked (with
a confidence score, an error code if it failed, and the app version). No
filename, no image, no amounts. Deleted automatically after 90 days.
- Update outcomes — those nine fields, no install ID, deleted automatically
after 90 days.
- Feedback you send — your message, app version, and which screen you were
on.
- Diagnostic reports, only the ones you generate and send yourself. Cleaned
on your Mac before upload.
- Crash reports, only if you switched them on — an error message and a
stack trace, no personal data.
- Service health and alerts — how our own system is doing. Nothing about you.
- Licences, once taxy Pro exists: a hash of your licence key, the plan, its
status and period, plus the install IDs it is used on. No name, no email, no
address, no card number.
- A daily counter of update checks — a single number per day. No device ID,
no IP address, not even a header is recorded.
The install ID, and what it is not
The install ID is a random UUID your Mac generates once and keeps locally. It is
not derived from your name, your email, your hardware or your profile. It lets us
see that thirty receipts came from one installation without knowing whose. This is
pseudonymous data under the AVG/GDPR, not anonymous — we treat it as personal data
and it is covered by your rights below. Clearing taxy's data on your Mac discards it.
When taxy Pro launches, a licence key will be bound to install IDs. That binding
is new: it links a pseudonymous identifier to a paying customer. Payment details
themselves stay with the payment provider — we never see or store a card.
This website, and updates
taxytax.nl has no cookies and no analytics. It is static pages. The in-app updater is
served from our own infrastructure, and every update is cryptographically signed — the
app refuses to install one that is not.
The one form on the site asks for your e-mail address if you want to hear when taxy is
ready. That address is not stored anywhere. It is put into a single message to
Stef's mailbox and then dropped — there is no list, no database row, and nothing to
export or delete later. Reply “stop” to that message and you will not hear
from us again.
Cloudflare, who host the site and the relay, keep their own standard connection
logs (IP address, timestamp, path) as any web host does. We do not collect, export or
analyse those ourselves.
Backups
A backup is a file you export yourself, optionally encrypted with a passphrase only
you know, saved wherever you choose. taxy never uploads a backup anywhere. If
you lose the passphrase, we cannot help you — we do not have it.
Your switches
- Usage stats and crash reports — both off by default. Settings, any
time, no consequences.
- Backup encryption — your choice, your passphrase.
- Clear all data (Settings → Advanced) permanently deletes everything taxy
stored on this device. Files already written to disk — your archive folder, your
exported backups — are left alone, because they are your files; remove those in
Finder yourself.
Your rights
Under the AVG (the Dutch GDPR) you have the right to see your data, correct it,
delete it, take it elsewhere, and object to how it is used. taxy's design makes most
of that self-service rather than a request you have to make and wait for:
- Access — your bookkeeping is on your Mac, in front of you, right now.
- Portability — export it any time, as a plain JSON backup or as an
accountant-ready auditfile. No request, no waiting, no export fee.
- Erasure — Clear all data deletes what is on your device. For the little we
hold, ask us and we will delete it.
- Correction and objection — the ledger is yours to edit. For anything on
our side, write to us.
The legal grounds, and the parts you have to ask us for
Reading a receipt is done to perform the service you asked for (AVG art. 6(1)(b)).
Usage stats and crash reports run on your consent (art. 6(1)(a)), off until you say
otherwise, withdrawable in Settings. Security, abuse-prevention and spend limits on
our relay rest on legitimate interest (art. 6(1)(f)) — without them one leaked
address could burn the whole service.
To act on a request for the data we hold, we need something to look it up by:
your install ID (Settings) or your licence key. We are not able to find you by name,
because we never stored one. If we cannot identify the data as yours, we cannot
delete it for you — that is the flip side of collecting so little.
Receipts sent to Anthropic are processed under our agreement with them as our
processor. Cloudflare hosts the relay and the site under the same kind of agreement.
You can complain to the Autoriteit Persoonsgegevens if you think we have this wrong;
we would rather you told us first.
How long we keep things
Data on your Mac stays until you delete it. Nothing expires on its own — including
receipts kept well past the seven-year bewaarplicht, because that is your call and not
ours. Extraction counters on our side are deleted after 90 days, automatically.
Feedback, diagnostic reports and crash reports are kept while they are useful for
fixing things; ask and we will delete them sooner. Licence records last as long as the
licence, plus what tax law requires us to keep for our own books.
Changes
If the data flow changes, this page changes with it, and the date at the top moves.
We do not quietly widen what we collect.
Contact
privacy@taxytax.nl, or the feedback button in the taxy app.
It reaches the maker directly.