Privacy Policy
Last updated: January 1, 2026
1. Who We Are
Auditable.tax is operated by Auditable LLC, located in Orlando, Florida, USA. We provide electronic FBAR (FinCEN Form 114) filing services for individuals, expats, businesses, and tax preparers.
2. What Data We Collect
- Identity data: First name, last name, middle initial, date of birth, SSN/ITIN/EIN
- Contact data: Email address, phone number (optional)
- Filing data: Foreign account numbers, institution names, balances, currencies, addresses
- Technical data: IP address, browser user agent, timestamps
- E-signature data: Typed name, IP address, timestamp (as legal signature equivalent)
3. How We Use Your Data
- To prepare and transmit your FBAR filing to FinCEN via the BSA E-Filing SDTM protocol
- To generate your Audit Defense Folder (filing record, Form 114a, rate snapshots)
- To provide year-over-year account carryover functionality
- To send filing status notifications and deadline reminders
- To authenticate your account and prevent unauthorized access
4. Data We Send to FinCEN
We transmit only the XML data required by FinCEN Form 114. This includes your name, SSN, account details, and balances. We do not send bank statement PDFs, images, or any file attachments. FinCEN does not accept file attachments through the BSA E-Filing system.
5. Data We Do NOT Send to Third Parties
- We do not sell your personal data
- We do not share your data with advertisers
- We do not transfer your data outside of the United States, except as required for FinCEN submission
6. Data Encryption & Security
- At rest: SSNs, account numbers, and sensitive fields are encrypted using AES-256 at the application level
- In transit: All connections use TLS 1.3
- Authentication: Passwords are hashed using bcrypt (12 rounds). We never store plaintext passwords
- Storage: Data is stored in encrypted MySQL databases and S3-compatible object storage (MinIO)
7. Data Retention
- Filing data: Retained for 7 years (exceeds the 5-year FinCEN requirement)
- Account data: Saved accounts retained until user deletes them
- Audit logs: Retained for 7 years
- Session data: JWT tokens expire after 24 hours
8. Your Rights (GDPR / CCPA)
If you are a resident of the European Union or California, you have the right to:
- Access: Request a copy of all personal data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data (subject to FinCEN recordkeeping requirements)
- Portability: Download your data in a machine-readable format via the Audit Defense Folder
- Objection: Object to processing of your data for purposes beyond filing
- Restriction: Request that we limit processing of your data
To exercise these rights, contact us at privacy@auditable.tax. We will respond within 30 days.
9. Cookies
We use only essential cookies for authentication (session tokens) and security (CSRF protection). We use Google Analytics with anonymized IP addresses to understand site usage. You may decline non-essential cookies via the cookie consent banner.
10. Data Breach Notification
In the event of a data breach affecting your personal data, we will notify you within 72 hours via email and take immediate steps to contain and remediate the breach, in compliance with GDPR Article 33.
11. Data Processing Agreement
By creating an account, you consent to the processing of your personal data as described in this policy. We act as a data processor on your behalf for the purpose of transmitting your FBAR filing to FinCEN. You are the data controller of your own filing information.
12. Contact
Auditable LLC
Orlando, FL, USA
Email: privacy@auditable.tax