Skip to content

Privacy Policy

Last updated: 6 October 2026

1. Who we are

Australian Tax MCP (ato-mcp.com.au) is operated by William Laverty (ABN 90 296 100 276), Canberra ACT ("we", "us"). It is an independent service, not affiliated with or endorsed by the Australian Taxation Office.

We follow the Australian Privacy Principles in the Privacy Act 1988 voluntarily. Questions about this policy go to privacy@ato-mcp.com.au.

2. What we collect

CategoryWhat
AccountYour email address and your name, if we have it (the name Google shares when you sign in with Google, or the billing name you give at checkout). With Google sign-in, also your profile picture.
Tax profileThe fields in the table below, if you choose to save a profile.
UsageFor every tool call: the tool's name and the time. Which documents in our library we returned to you each day (document IDs only), so we can spot an account copying the library in bulk. Monthly lookup counts. The name and version of the AI app you connect (for example Claude or Cursor) and when it first and last connected.
Billing (Pro)Stripe customer and subscription IDs, plan, status, billing period dates, renewal amount, card brand, last four digits and expiry month and year, and a history of payments, refunds, plan changes and cancellations (dates, amounts, Stripe invoice IDs).
Cancellation feedbackThe reason you pick and any comment you type when you cancel Pro, and which offer you saw.
How you found usThe first page you visited, the site that sent you, any campaign tags in that link, the ad click identifier if you came from an ad, and the browser identifiers set by Google Analytics, Meta and Reddit cookies. Your approximate location when you signed up (city, state, postcode and country, worked out from your IP address).
Last browser you signed in withIts IP address, browser type, the page and the time, and its Google Analytics, Meta and Reddit browser identifiers. Replaced each time you sign in.
Email preferencesWhich email topics you're subscribed to, and which product emails we've already sent you.
Emails you send usThe message, your address and anything attached.

Your tax profile is optional: you can use the service without one. If you save a profile, these are the fields it holds. This table is generated from the database schema.

FieldDescription
given_nameYour first name
stateYour state or territory of residence
residency_statusYour Australian tax residency status
has_abnWhether you hold an Australian Business Number
abnYour ABN (if applicable)
business_structureYour business entity type
business_nameYour registered business name (if applicable)
industry_codeYour ANZSIC industry classification code
occupationYour occupation
gst_registeredWhether you are registered for GST
gst_periodYour GST reporting period
payg_instalmentsWhether you pay PAYG instalments
fbt_payerWhether you are registered for Fringe Benefits Tax
has_spouseWhether you have a spouse or de facto partner
dependantsNumber of dependants
hecs_help_debtWhether you have a HECS/HELP debt
private_health_insuranceWhether you hold private health insurance
has_investment_propertyWhether you own investment property
has_shares_or_managed_fundsWhether you hold shares or managed funds
has_cryptoWhether you hold cryptocurrency
super_fund_typeYour superannuation fund type
current_fyThe current financial year
prior_fy_lodgedWhether you have lodged your prior year tax return
accepted_disclaimer_atTimestamp when you accepted the disclaimer
facts_updated_atTimestamp when your facts were last updated
schema_versionInternal data schema version

3. Where it comes from

  • You, when you sign up, save your tax profile, cancel, or email us.
  • Google, if you choose Google sign-in.
  • Stripe, which tells us about your subscription and card (never the full card number).
  • Your AI app, which tells us its name and version when it connects.
  • Your browser, through cookies, analytics and ad tags (section 6).

4. Why we use it

  • Run the service: sign you in, answer your AI app's tool calls, and personalise workflow tools to your tax profile.
  • Enforce plan limits and prevent abuse.
  • Bill you, and send receipts and account notices.
  • Send product emails you can unsubscribe from (section 11).
  • Understand how the service is used and found, including which ads bring people to it, so we can improve it.
  • Meet legal obligations, such as keeping tax records.

We don't sell your information.

5. Who we share it with

These providers process information for us. Most are overseas, so your information is stored or handled outside Australia in the countries listed.

ProviderWhat forWhere
SupabaseDatabase and sign-inAustralia (Sydney)
VercelHosting and the servers that handle every requestUnited States
OpenAITurns search queries into vectors so we can find matching passagesUnited States
StripePayments, invoices and the billing portalAustralia and United States
ResendSending and receiving emailUnited States (inbound mail via Japan)
GoogleGoogle sign-in, Google Analytics, Google Ads, and the operator's inbox for forwarded emailUnited States
Meta, Reddit, LinkedIn and XMeasuring which of our ads bring people to the service (section 6)United States

Your AI app. When you connect an AI app, it receives what our tools return, including your tax profile when it calls get_user_facts. From there your app and its model provider (for example Anthropic or OpenAI) handle it under their own terms. You choose which app to connect.

Search queries. The text of each search call is sent to OpenAI to compute a search vector. We don't store it. OpenAI handles it under its API data terms.

Tool arguments. Figures your AI app sends to a tool (for example an asset's cost for the depreciation helper) pass through our servers to compute the answer and aren't saved.

Stripe. At checkout Stripe collects your name, billing address, card and, optionally, your ABN. We copy only your name to our database, and only if we don't already have one. We pass Stripe how you found us, which AI app you use, your Google Analytics ID, and your IP address and browser type so purchases can be attributed. Stripe's privacy policy applies to what it holds.

We may also disclose information when the law requires it.

6. Cookies and analytics

  • Sign-in cookies keep you signed in.
  • A first-party cookie remembers how you found us for up to 90 days; when you sign up we copy it to your account.
  • Google Analytics sets cookies to measure page views and actions such as starting sign-in or checkout. When you buy Pro, we send Google Analytics the purchase (plan and amount). When you're signed in, it also receives your account ID and your email address hashed. With Google signals on, Google can link visits to your Google account if you've turned on ad personalisation. You can block it with a browser extension or Google's opt-out add-on.
  • Ad tags from Google Ads, Meta, Reddit, LinkedIn and X set cookies so we can tell which ads bring people here. When you sign up, connect your AI app, start a checkout, pay or reach the Free plan's monthly limit, we also tell those platforms from our servers, with your account ID (hashed for Meta and Reddit), your email address hashed (scrambled so it can be matched but not read), the ad click and browser identifiers from your visit, and, for actions on this website (including approving an AI app), your IP address and browser type. Google and Meta also receive your name and approximate location, hashed: your sign-up location, or your billing address when you pay. We never send your tax profile or anything your AI app asks. To opt out, block third-party tracking in your browser or turn off ad personalisation in your Google, Meta, Reddit, LinkedIn and X settings.
  • Ad audiences: Google Ads and Meta hold your email address, hashed, in one of two lists we keep up to date each day: Pro subscribers, so they stop showing you ads for Pro, or Free users, so they can show you ads about Pro. Deleting your account removes you from both. Turning off ad personalisation in your Google and Meta settings stops those ads.
  • Vercel Web Analytics counts page views without cookies.

7. What we don't collect

  • Your Tax File Number (TFN). We never need it. Please don't type it into your profile or your AI app.
  • Your tax returns or ATO correspondence.
  • Bank account details or full card numbers.
  • Income amounts or asset values, other than passing through in a tool call (section 5).
  • The text of your queries, the arguments your AI app sends, or the content of the results we return. These are not saved to our database.

8. How long we keep it, and deletion

InformationKept
Account, tax profile, usage, lookup counts, connected apps, how you found us, last browser you signed in with, cancellation feedback, email preferencesWhile your account is open. Deleted when you delete your account.
Billing historyKept after you delete your account, with the link to you removed. Stripe invoice IDs remain.
Your Stripe customer record and invoicesKept by Stripe. Australian tax law requires invoice records to be kept for five years.
Rate-limit countersAbout an hour.
Which documents we returned to you each day30 days, or until you delete your account if sooner.
How-you-found-us cookieUp to 90 days in your browser, then copied to your account when you sign up.
Emails you send usUntil we delete them.
Provider logs (hosting, sign-in, OpenAI, email, analytics, advertising)Under each provider's own retention schedule.

You can delete your account any time from your account page. Deleting cancels any subscription immediately, removes your email from our mailing list, and deletes your account, tax profile and usage records. It doesn't remove the billing history, Stripe records or provider logs listed above. To have your Stripe customer record deleted too, email privacy@ato-mcp.com.au; Stripe keeps what tax law requires.

9. Security

Information is encrypted in transit and at rest with our providers. Database access is restricted so each signed-in account can reach only its own data. Sign-in is by one-time email code or Google, so there are no passwords to leak. If a data breach is likely to cause you serious harm, we'll tell you and the Office of the Australian Information Commissioner (OAIC). Report security issues to security@ato-mcp.com.au.

10. Access and correction

You can view and edit your tax profile and email preferences on your account page. For a copy of everything we hold about you, or to correct anything else, email privacy@ato-mcp.com.au. We'll respond within 30 days, free of charge.

11. Emails

Account and billing emails (sign-in codes, receipts, payment problems) are part of the service. When you sign up we also subscribe you to product emails: founder updates, tax tips and lodgement deadline reminders. Every product email has an unsubscribe link, and you can change topics on your account page.

12. Automated outputs

The workflow tools (deduction discovery, depreciation, BAS prep, audit risk) apply fixed, published rules to your tax profile and the figures your AI app sends. They produce general information for you to check. They don't make decisions about you, and nothing they output is sent to the ATO.

13. Complaints

If you think we've mishandled your information, email privacy@ato-mcp.com.au with the details. We'll respond within 30 days. If you're not satisfied, you can complain to the OAIC.

14. Changes

When this policy changes we update the date above. If a change affects how we use information you've already given us, we'll email you before it takes effect.