Privacy Policy
Last updated: 24 September 2026
1. Data controller
Luis Andrés-Vázquez
Graunstraße 30
13355 Berlin, Germany
Email: hello@taxcat.eu
2. The short version
This website is a static information page. It uses no cookies, no tracking, no analytics services, and embeds no third-party content (fonts are self-hosted; no Google Fonts or CDNs are loaded). There is no registration; the only form on this site is the contact form in the imprint (see section 4).
3. Hosting and server log files
This website is delivered by Google Firebase Hosting; the contact form runs on Google Cloud Run in europe-west3 (Frankfurt). These services process technically necessary access data such as IP address, time, requested URL and user agent to deliver and secure the site. The legal basis is Art. 6(1)(f) GDPR (secure operation of the website). Section 5 describes Google, possible international processing and safeguards.
4. Contact form in the imprint
The contact form requires email address, subject and message and processes an optional reference, language and submission time. Send only problem descriptions and redacted examples, never invoices, receipts, tax documents, passwords or access keys. Attachments are not accepted.
The submission is processed by Google Cloud Run in europe-west3 (see section 3). A TaxCat function first checks request limits. It receives technical checking data, including IP address and language, but neither sender address, reference nor message body; short-lived counters use derived identifiers. The message is then sent through Gmail (Google) to hello@taxcat.eu and forwarded to the owner's mailbox. Google and any involved mail providers process the message; global processing, including the USA, is possible. You can request information about recipients and applicable safeguards at hello@taxcat.eu.
The purpose is answering your enquiry and preventing abuse, not advertising or profiling. Necessary pre-contractual or contractual steps with you rely on Art. 6(1)(b) GDPR; otherwise answering business enquiries and proportionate abuse prevention rely on Art. 6(1)(f). Providing data is voluntary; the form cannot be processed without its required fields. You can also contact hello@taxcat.eu, with the same content restrictions. Retention is described in section 6.
5. The TaxCat app itself
TaxCat is local-first. Business data (invoices, clients, expenses and tax data) is still held in IndexedDB in your browser, on your own device, so you can keep working offline. A TaxCat account has been required to use app.taxcat.eu since 14 August 2026; for the account and synchronisation, TaxCat uses Google Firebase Authentication, Cloud Firestore and Cloud Storage for Firebase. This processes account data (in particular email address, user ID, and security data such as IP address and user agent), synced business records, and receipts you upload. If you select “Sign in with Google”, Google sends the basic account profile to Firebase after your selection. Legacy scanner API keys are deleted at startup; local backup-folder permissions remain excluded from sync.
TaxCat's contracting party for Firebase Paid Services and the Google Cloud services it uses (including Cloud Run and Vertex AI) is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. Under the Firebase Data Processing and Security Terms, Google generally processes customer data as a processor. TaxCat's Firestore is configured in the EU multi-region eur3; files are stored regionally in europe-west3 (Frankfurt). Firebase states that Authentication runs exclusively from US data centres. Support and services without a fixed location commitment may also process data outside the EEA. Google provides transfer mechanisms including the applicable EU Standard Contractual Clauses and, where relevant, the EU-US Data Privacy Framework.
The app at app.taxcat.eu is delivered through Firebase Hosting; its API runs on Google Cloud Run in europe-west3. Necessary session data and local copies are stored in the browser for sign-in, device settings and offline work. This technically necessary storage serves the expressly requested service (§ 25(2) no. 2 TDDDG); it is not marketing tracking. First sign-in and some functions need a connection. TaxCat does not make solely automated decisions with legal or similarly significant effects under GDPR Article 22.
TaxCat is controller for its own account, contract, support and security purposes. Necessary contractual processing with you relies on Art. 6(1)(b) GDPR; managing a business customer's contacts and proportionate security rely on Art. 6(1)(f). Legal duties rely on Art. 6(1)(c) where actually applicable. For personal business content you upload as controller, your business determines its legal basis and TaxCat acts on your instructions. Art. 6(1)(b) is not a blanket basis for your customers' data.
TaxCat confirmed this contracting party on 22 September 2026 from the direct Google Cloud billing account linked to the TaxCat project, a Google-issued statement and Google's contracting-entity table; neither a reseller nor a different individual agreement was found. The Google terms accepted online when the account was set up apply, including the data processing terms; for transfers outside the EEA, Google provides the safeguards named above. Information and available safeguards can be requested through hello@taxcat.eu; exclusively European processing is not promised.
Where synced business records contain third-party personal data for which you are the controller, TaxCat processes that data solely on your instructions as a processor; Google is then a subprocessor. The customer DPA under Art. 28 GDPR is expressly accepted with the B2B terms before new uploads of such data. Without acceptance, no new third-party personal business data should be uploaded; existing data remains accessible, exportable and deletable.
Optional invoice delivery through a connected Google mailbox
Google Sign-In for the TaxCat account and connecting a Google mailbox are separate actions. Only when you explicitly choose “Connect Google mailbox” in the invoice composer does TaxCat request the narrowly limited gmail.send permission. It permits sending messages on your behalf only. TaxCat does not request permission to read, modify or delete your mailbox, or to access drafts, contacts, Calendar or Drive.
When you send, your browser transmits the sender address, recipient address, the subject and message text you edited, and the selected invoice PDF directly to the Gmail API. Google processes and delivers the message and attachment and manages sent messages and non-delivery reports according to your Google Account settings. To verify which mailbox was connected, a TaxCat server function forwards the short-lived access token once to Google's UserInfo service and receives the verified email address and an opaque Google account ID. The server function neither logs nor stores the token, message, recipient or PDF. The access token exists only in the open tab's memory and is removed from TaxCat when you disconnect the mailbox, reload or close the tab.
TaxCat stores in Firestore only a technical delivery receipt containing the invoice ID, provider, opaque provider account ID, timestamps, outcome, an attachment checksum and, where applicable, a limited error code. Recipient, sender, subject, message text, PDF/MIME content, access token and raw Google responses are not stored there. Delivery receipts appear only in redacted form in an account export and are deleted when the TaxCat account is deleted. You can also revoke Google's permission at any time in your Google Account's third-party access settings.
Recipients and disclosure of Google user data: TaxCat shares, transfers or discloses this data only to the following recipients: (1) Google for the TaxCat server function in Cloud Run (europe-west3), UserInfo, the Gmail API, email delivery and the technical delivery receipt in Cloud Firestore; and (2) the email recipients you select and their email service providers, only as necessary to deliver the message and invoice that you explicitly ask TaxCat to send. TaxCat does not share, transfer or disclose Google user data to any other third party, except where required by law or necessary to investigate a security incident or abuse.
TaxCat's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This data is used solely for the visible, user-initiated invoice-delivery feature, not for advertising, profiling, sale, creditworthiness decisions, or training generalized AI or machine-learning models.
Delivery is performed on your explicit instruction to provide the app feature you requested (Art. 6(1)(b) GDPR). Where the invoice contains your customer's data, you remain responsible for the content, recipient and legal basis for sending it.
TaxCat's managed document scanner is enabled only for a closed testing group. TaxCat sends only the invoices and receipts you select for scanning, after a prior disclosure, to Google Cloud Vertex AI (gemini-3.1-flash-lite, EU multi-region). Its sole purpose is to extract bookkeeping fields such as parties, date, amount, VAT and line items. The result is a draft that you must review before accepting it. TaxCat does not enable grounding, provider files or context caching for this route; it does not offer customer API keys or a freely selectable AI provider. You can turn the scanner off and use manual entry or local PDF-text extraction instead.
The request first passes through the TaxCat server function in Google Cloud Run in europe-west3 (Frankfurt) and then Vertex AI in the EU multi-region. Google states that it does not use customer data to train or fine-tune AI/ML models without prior permission or instruction. On 22 September 2026 Google approved the exception from prompt logging for abuse monitoring for TaxCat's Google Cloud project. The scanner nevertheless remains limited to the closed testing group; general availability is a separate decision. For third-party personal data, your business normally remains the controller, TaxCat the processor, and Google the subprocessor.
The closed scanner beta is limited to expressly enabled accounts. After accepting the customer DPA, eligible business customers may also select real invoices and receipts containing third-party personal data within the agreed scope. The approved exception covers prompt logging for abuse monitoring; zero-day retention is not promised for other reviews that Google documents separately. Scanning is optional; manual entry requires no transmission to Vertex AI.
6. Retention, export and deletion
Synced business data is stored during the account's life until a permitted deletion or complete account closure. Issued invoices are protected against individual subsequent deletion in the ordinary editor. Complete closure first creates and verifies an export and shows a retention warning, then deletes issued invoices, attachments and the Auth user. You fulfil your own tax-retention duties through saved exports; TaxCat does not retain that content after termination for this purpose. Separate cloud backup or historical recovery is not promised.
A minimal server-side closure record is kept separately: account/operation IDs, timestamps, export checksum and aggregate deletion counts, without invoice content. It may still be personal data. TaxCat processes it as controller to evidence closure and prevent improper repeated requests or claims under Art. 6(1)(f) GDPR. Its configured expiry is 1 January of the fourth year after closure (closure in 2026: 1 January 2030). Firestore TTL then initiates deletion; it does not guarantee physical removal to the second. Necessity and justified objections to this retention are assessed case by case.
Professional acceptance of the B2B terms and DPA is also recorded separately: the authenticated TaxCat account ID and email address, time, business-use declaration, language choice, and versions and checksums of the texts. No name, business address or separate contact address is requested for this record. It contains no invoice content. After account closure it follows the same expiry rule as the closure record; during an active contract it is needed to evidence the agreed terms.
On sign-out or account closure, TaxCat removes this browser's local app copies: Firestore cache, attachment cache, device settings and account-related interface preferences. Failed cleanup is retried before the next workspace start. A device remaining offline can only respond on its return. Downloaded exports and local backup files are not remotely erased.
Support content is deleted when handling ends and no concrete retention reason remains; separate support working copies are deleted within seven days of resolution. Only minimised correspondence necessary for contractual claims is normally retained until the end of the third calendar year after closure. An active dispute or specific legal duty can justify longer retention of necessary parts. The target for ordinary non-security technical logs is at most 30 days; this is not a confirmed maximum for all provider and mail logs. Security evidence receives a case-specific deletion date. Future TaxCat invoices are generally subject to eight years from year-end where § 14b UStG applies; end-customer billing is currently inactive.
Firebase states a few weeks for authentication IP logs and up to 180 days to remove other Auth data from active and backup systems following account deletion. Firebase's processing terms also allow up to 180 days for instructed deletion, subject to legally required storage. If the provider contract between TaxCat and Google ends, a recovery period of up to 30 days may precede the subsequent deletion period. These residual periods do not mean TaxCat actively reuses your business documents.
7. Your rights
Under GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on Art. 6(1)(f) (Art. 21) against the data controller. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), in particular the Berlin Commissioner for Data Protection and Freedom of Information.
For privacy requests, contact hello@taxcat.eu initially without confidential attachments; identity is checked proportionately and a secure route agreed where needed. This also applies without account access or if you want deletion without downloading an export first. For a TaxCat customer's business data, we forward the request to the relevant controller and assist them. For its own processing, TaxCat normally responds within one month and explains any permitted extension. Where processing relies on consent, you may withdraw it for the future. Contract acceptance and privacy information do not request blanket consent.
8. Changes and provider lists
Current Firebase and Google Cloud subprocessor lists are published at firebase.google.com/terms/subprocessors and cloud.google.com/terms/subprocessors. Before launching end-customer billing, analytics, additional Firebase products or a different AI route, this policy will add the relevant provider, purpose, data transfer and retention.