Privacy
Last updated: 2026-05-18
CP2000 Helper is an educational document assistant for IRS CP2000 notices. This page describes what the app collects and how that data is handled. This is not tax advice.
What we collect
- The IRS notice file you upload (PDF), if you choose the upload path.
- The notice details you enter, if you choose the manual entry path.
- The fields we extract from your notice (notice type, tax year, response deadline, proposed amount, payer or source).
- The answers you provide on the questionnaire.
- The response report and draft letter we generate for you.
- An optional email field exists in our sessions schema and is not used to send you your response pack. Separately, we do send transactional email in two cases: a paid-access recovery link, if you request one, and a copy of your support message to our support inbox, if you contact us (see Contact).
How we use it
Your uploaded notice, manually entered details, and questionnaire answers are used to generate your response pack — the notice summary, response strategy, evidence checklist, mailing checklist, and draft response letter. Generated reports and draft letters may be stored for the duration of your session so you can come back and review them.
Where it's stored
Uploaded files are stored in a private storage bucket and are only accessed by our server-side workflow. Database rows live in our Supabase project. The browser never reads from storage directly — files and extracted fields are returned only as part of rendering your own session.
Who has access
Server-side only. Files and answers are not exposed to the client browser except as part of rendering your own session. The session URL is the access token; if you share it, others may see your data.
Logging
The app avoids logging the full content of your tax notice. Server logs record operational events (request paths, error codes, timing, model usage) and structured fields like session ids — they do not include raw notice text, extracted notice fields, prose body, or draft letter content.
Retention and deletion
Sessions are automatically deleted after a retention period (the database stores an expires_at timestamp; currently about 30 days from when the session was created). When a session is cleaned up, its uploaded file is removed from storage and the related records — extracted fields, your answers, and the generated response pack — are deleted along with it.
You can also delete your data manually at any time using the "Delete my data" button in the page footer on any session-scoped page. That removes the uploaded file from storage and the session record immediately.
AI processing
If you upload a notice, the text we read from your uploaded PDF may be sent to Anthropic's commercial API so we can extract the notice fields (notice type, tax year, response deadline, proposed amount, payer or source). When we later generate your response report and draft letter, we work from those structured fields rather than re-sending the raw notice text. If you would rather not send any notice text to Anthropic, you can use the manual entry path instead of uploading a file.
According to Anthropic's commercial product policy, inputs and outputs from the Anthropic API are not used to train models by default. See Anthropic's data usage policy for current details: anthropic.com/legal/privacy.
Third parties
We use Anthropic for AI inference, Supabase for database and storage, Microsoft Clarity for anonymized usage analytics (aggregated page-visit and interaction metrics — never your notice content), and Resend to send transactional email (the paid-access recovery link and support-message notifications). No other vendors process your data in this version.
Cookies and tracking
We use Microsoft Clarity for anonymized usage analytics, which may set cookies or use local storage to measure how pages are used (for example, the path from the home page to starting a response). It does not identify you and does not access your notice content. Aside from Clarity, we do not use cookies for advertising or cross-site tracking. We also use a small browser-storage value (localStorage) to remember your last session on this device. You can clear it via "Delete my data" or by clearing your browser data.
Rate limits
We apply per-session rate limits to prevent abuse. In this version rate limits are tracked in server memory and reset when the server restarts.
Current version
This is the current version of the product. Features, retention, and the policies described here may change as the product evolves.
Contact
For data requests, use the "Delete my data" button on any session-scoped page, or the "Send feedback" link shown on the report page.
To reach us about a refund, an access problem, or a question, use our support page. A support submission includes the email address and message you provide; we store it and use it only to respond to you, and we send a copy to our own support inbox through our email provider. Please don't include full financial-account numbers or other sensitive data in the message.