Privacy Policy
Last updated: August 2026
1. What We Collect
taxmcp.io is operated by Gray & Company LLC ("Gray & Co.", "we", "us"), which is the controller of the personal data described in this policy. You can reach us at hello@taxmcp.io.
We collect only what's needed to run the service:
- Account info: your email and name for managing your subscription.
- Usage records: the associated account or API key, timestamp, tool or API endpoint called, and response time. For MCP calls, we record the tool name but not the tool arguments. Direct REST lookup paths may contain a public citation, section, publication, ruling, or case identifier.
- Research inputs: when you use TaxMCP search, we send the search text to OpenAI's API to create a search embedding. When semantic reranking is used, we also send the search text and short excerpts and metadata from candidate authorities to OpenAI to order the results. TaxMCP does not write MCP tool arguments or URL query-string search text to its application database or usage log.
- Session data: a secure identifier that keeps you logged in.
2. How We Use It
- Running the service: authenticating requests, enforcing rate limits, returning results.
- Search quality: creating search embeddings and, when enabled, reranking candidate authorities.
- Improving reliability: using limited request metadata to keep the service fast and dependable.
- Billing: processing payments for paid plans.
- Support: helping you when something goes wrong.
3. Security
- All connections encrypted with TLS.
- We and our service providers process data in the United States and other locations where they operate, subject to the safeguards and terms that apply to those services.
- Passwords are hashed; we never store them in plain text.
- Sessions are server-side with secure, HTTP-only cookies.
4. Third Parties
Payments are processed by Stripe; we never store your card number. We use Fathom Analytics to measure aggregate website usage and standard providers for hosting and transactional email.
TaxMCP uses OpenAI's API to generate search embeddings and, when enabled, rerank candidate results. OpenAI states that API data is not used to train its models unless the API customer explicitly opts in. Under OpenAI's default controls, abuse-monitoring logs that may contain customer content can be retained for up to 30 days; approved Modified Abuse Monitoring or Zero Data Retention controls may reduce that retention. See OpenAI's data-controls documentation.
We don't use ad networks or data brokers.
5. Cookies
We use a few cookies to keep you logged in and protect against cross-site request forgery. All are functional; none are used for tracking or advertising.
6. Data Retention
| Data Type | Retention |
|---|---|
| Account information | For the duration of your account and as needed to complete deletion requests or meet legal obligations |
| Usage records | For the duration of the associated account or API key, unless deleted or de-identified sooner |
| Research inputs processed by OpenAI | Not persisted in TaxMCP's application database as MCP query text. OpenAI's default API abuse-monitoring retention may be up to 30 days unless approved retention controls apply. |
| Session data | Cleared on logout or expiry |
7. Your Rights
You can request an export, correction, or deletion of your data at any time. You can unsubscribe from non-essential emails via any email link.
If you're a California resident, these are your rights under the CCPA/CPRA; if you're in the EU or UK, they're your rights under the GDPR. They apply to everyone regardless of where you live. We don't sell your personal data or share it for targeted advertising, and we won't discriminate against you for exercising any of these rights.
For any requests, reach out at .
8. Changes
If we make meaningful changes to this policy, we'll email you at least 30 days before they take effect.