What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email, password hash, OAuth method | Authentication and account security | Contract performance |
| Onboarding (canton, language, civil status, children, free-text context) | Generate an accurate guide for your canton | Contract performance |
| Uploaded documents and extraction results | AI extraction and guide generation | Contract performance |
| Billing details held by Stripe and replicated to our database (name, email, billing address, card brand and last four digits) | Process your payment, refunds and chargebacks | Contract performance + legal obligation (accounting) |
| Broker export you upload to the statement converter | Produce your eCH-0196 tax statement | Contract performance |
| A record that a conversion ran (broker, tax year, canton, PDF language, page count, upload size, success or failure, number of securities and warnings, processing time, error code and reference, random request ID) | Count your free runs and diagnose failures | Contract performance |
| Service usage and security logs | Operate the service, detect abuse | Legitimate interest |
We count page views with Vercel Web Analytics. It uses no cookies and does not follow you to other websites. For each page view it records the page, where the visit came from, your country, region and city, and your browser and device type; Vercel builds a short-lived identifier from your request, including your IP address, and discards it after 24 hours. We never see your IP address ourselves, and paths inside your account are redacted before the event leaves your browser.
Vercel Speed Insights measures loading speed, responsiveness and visual stability (Core Web Vitals) to help us improve performance. Measurements include the page URL, route, network, browser, device and country, without identifying individual visitors. Account URLs are redacted before sending.
We count page views with PostHog, hosted in Frankfurt, in the same cookieless way — for everyone. Until you answer the analytics question, and if you refuse, PostHog derives a short-lived hash on its servers that is discarded the same day. It uses it to count the visit once and to see how that visit went: which pages were opened, how fast they loaded, how long each stayed open and how far it was scrolled, and which links, buttons and forms were used. No cookie, nothing stored in your browser, no identity: the visit cannot be linked to another day or to an account. Refusing costs you no part of the public website.
If you accept analytics, PostHog also records how the app is actually used, linked to your account: which screens you opened, what you clicked, and a replay of those screens. Form inputs and marked personal content are masked, and document previews are blocked, before the recording leaves your browser, and the events carry identifiers and categories only — never the contents of a document, a file name, or an amount in francs. The Cookie Policy explains how to change that choice.
Once you have an account, we also record a small number of product events on our own servers, whether or not you accepted analytics: that the account was created, a return started, a document received, a guide ready, a payment made, and the like. Each carries your account identifier, the return it concerns, your canton and language, and — if you arrived through a partner link — which one. They contain no document and no file name, and the only amount is the price you paid. They set no cookie and go to PostHog's EU Cloud in Frankfurt, and a few of them reach Google Ads as described in §03. We record them under our legitimate interest in knowing whether the service works and which partners send us customers (Art. 6 FADP; Art. 6(1)(f) GDPR where it applies). Screen recording, and the link between your browser and your account, remain consent-only. We do not use advertising trackers or third-party marketing pixels, or build behavioural profiles. Your password is stored as a one-way cryptographic hash — we never see it. Card numbers, CVVs, and bank details go directly to Stripe and never reach our servers.
Your tax documents — special handling
Your tax documents are the most sensitive data we process. They may contain income, financial, government-identifier (AHV number), health-adjacent (disability, medical expenses), family, and property data.
We process your documents to perform our contract with you (Art. 31 para. 2 lit. a FADP). We do not ask you for separate consent, and you do not need to give any. You can stop the processing at any time by deleting the document or your account.
Documents are stored in Supabase Storage in an encrypted bucket, accessible only to your account. Row Level Security enforces per-user isolation at the database level. AES-256 at rest, TLS 1.3 in transit. Other users cannot access your files — ever.
How the AI actually reads your documents, what Microsoft and Anthropic receive, the no-training commitments, and each provider's retention policy are all described in the AI Disclaimer.
Sub-processors and international transfers
We share your data with the service providers listed below and, to measure our ads, with Google as described after the table. We do not sell your data. Every provider has a Data Processing Agreement with us, or is engaged by one that does and named as such below, with Standard Contractual Clauses (SCCs) where required for transfers outside Switzerland.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Corporation (Azure), engaged by Vercel | AI processing — reads your uploaded documents; nothing is kept after the request | USA | Our DPA and SCCs with Vercel, which engages Microsoft as its sub-processor — Art. 16(2)(d) nFADP |
| Anthropic, Inc. | Claude Agent (AI processing) | USA | SCCs — Art. 16(2)(d) nFADP |
| Vercel, Inc. | Application hosting, CDN, compute, routing of AI requests | Frankfurt (EU) | SCCs — Art. 16(2)(d) nFADP |
| Supabase, Inc. | Database, auth, file storage | Zürich (Switzerland) | No transfer required |
| Stripe Payments Europe, Ltd. (Dublin) and Stripe, Inc. (USA) | Payment processing | Ireland and USA | Swiss–U.S. Data Privacy Framework (Federal Council adequacy, in force 15.09.2024), backed by Stripe's DPA and SCCs |
| Resend (Plus Five Five, Inc.) | Receives and stores email you send us | USA | SCCs — Art. 16(2)(d) nFADP |
| Discord, Inc. | Notifies our support channel that you wrote in, and shows the first part of your message | USA | SCCs — Art. 16(2)(d) nFADP |
| Vercel, Inc. (Speed Insights) | Measures page performance to identify and fix slow pages | Global infrastructure, including USA | SCCs — Art. 16(2)(d) nFADP |
| Vercel, Inc. (Web Analytics) | Counts page views. No cookies, no cross-site tracking | Frankfurt (EU) | SCCs — Art. 16(2)(d) nFADP |
| PostHog, Inc. (EU Cloud) | Counts visits without cookies for everyone, records product events for your account, and session replay only if you accept. Never receives documents | Frankfurt (EU) | No transfer outside the EU; DPA with SCCs for onward transfers |
Google Ads. If you arrive by clicking one of our Google ads and then create an account, we keep the click ID from that link. PostHog then tells Google Ads when you create the account, generate a broker statement, get the first card of your guide and pay, and how much you paid. Google receives nothing else about you. It uses this as an independent controller to show us which ads bring customers, and may process it in the USA under the Swiss–U.S. Data Privacy Framework. We rely on our legitimate interest in measuring our ads (Art. 6(1)(f) GDPR where it applies). To object, email contact@papertax.ch.
If you email us, your message reaches Resend in the United States and a short extract is posted to a private Discord channel our team reads. Do not send tax documents by email. Upload them in the app instead, where they stay on the path described above.
If we add or replace a sub-processor we will update this policy and notify you by email at least 30 days before the change takes effect. We disclose user data only when legally required by a binding request from competent Swiss authorities under Swiss law, and we challenge requests we have doubts about before complying.
How long we keep your data
Different types of data have different retention periods. The table below explains the rules for data stored by PaperTax.
| Data type | Retention |
|---|---|
| Active return (documents, extractions, guide) | Until you mark the return done or delete it, and in any case no more than two years after you last touched the return |
| Completed return | Deleted automatically 24 hours after you mark it done, or after two years of inactivity, whichever comes first |
| Account data | Deleted immediately when you delete your account |
| Payment reference (Stripe ID, amount, date) | 10 years — Swiss accounting law (Art. 958f OR, Art. 70 para. 2 VAT Act) |
| Security logs | 90 days |
How we protect your data
- Encrypted — AES-256 at rest, TLS 1.3 in transit
- Isolated — Row Level Security at the database level, not just the application
- Short-lived sessions — login sessions refresh and expire automatically
- No card data on our servers — payment details go directly to Stripe
If a breach is likely to result in high risk to your personal data, we will notify the FDPIC via their DataBreach online form as quickly as possible and notify you directly when necessary for your protection.
Your rights
Under Swiss nFADP and EU GDPR you have the rights below. Email us at contact@papertax.ch to exercise any of them. We acknowledge within 5 business days and provide a substantive response within 30 days.
- Access — know what we hold and receive a copy
- Rectification — correct inaccurate data
- Erasure — delete your data via account settings → Delete Account. Documents, guide data, and your account are wiped immediately. The only exceptions are the payment record, which Swiss accounting law requires us to keep for 10 years (Art. 958f OR, Art. 70 para. 2 VAT Act), and server security logs (up to 90 days under legitimate interest for fraud detection) — both listed in §04
- Restriction — pause processing during a dispute
- Portability — receive your data in JSON
- Object — stop processing based on legitimate interest
Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern. EU/EEA residents can contact their local data protection authority (list at edpb.europa.eu).
Changes to this policy
For material changes we will notify you by email at least 30 days before the change takes effect. Continued use after the effective date constitutes acceptance. In case of discrepancy between this English version and any translation, the English version prevails.