Privacy Policy - TAX TALK
Effective date: 10 May 2026
TAX TALK is a Thai personal income tax assistant app. This policy explains how TAX TALK collects, uses, shares, retains, and protects user data under the Thai Personal Data Protection Act B.E. 2562 (PDPA) and applicable Google Play requirements.
Data controller and contact
The data controller is the TAX TALK app provider. Privacy and account deletion requests can be sent to taxtalk66@gmail.com. The public developer name used in the Google Play listing should match TAX TALK or the legal entity operating TAX TALK.
Data we collect
- Account data: email address, display name, Firebase UID, authentication state, and policy acceptance state.
- Tax data entered by users: income, deductions, allowances, filing status, family-related tax fields, and P.N.D. 90/91 calculation inputs.
- Chat data: user questions, assistant responses, chat session state, and minimal metadata needed to display and improve the service.
- Attachments: images or PDF files uploaded by the user for OCR, only when the user chooses to attach files.
- Payment and subscription data: RevenueCat entitlement state, product identifiers, start/end dates, and store transaction state. TAX TALK does not collect full credit card numbers.
- Diagnostics: request IDs, error codes, app version, device category, crash diagnostics, and redacted technical logs.
How we use data
We use data to provide the app, authenticate users, calculate tax estimates, generate P.N.D. 90/91 drafts, answer tax questions, process OCR/RAG/LLM requests, manage subscriptions, prevent abuse, improve reliability, and respond to support or legal requests.
Processors and sharing
Data may be processed by Firebase/Google Cloud, OpenTyphoon, OpenAI, Supabase, Tavily, RevenueCat, and Sentry where required for app functionality, monitoring, payments, OCR, embeddings, retrieval, or AI responses. We do not sell personal data or tax data.
Security
We use HTTPS, Firebase Authentication, Firestore Security Rules, backend-only secrets, least-privilege backend access, structured error responses, and PII redaction for crash reports and logs. Logs must not include full chat content, OCR text, tax records, tokens, passwords, or secret values.
Retention and deletion
Account and user-created data is retained while the account is active or while needed to provide the service. OCR attachments, chat content, technical logs, and monitoring data are retained for limited periods based on the data retention policy.
Signed-in users may request account deletion from Settings > Data deletion. The request requires recent authentication and has a 7-day cancellation period. After that period, TAX TALK deletes the Firebase account and user-created Firestore data and automatically requests deletion of the corresponding RevenueCat customer record. Limited consent, payment, deletion, security, and external-provider cleanup evidence may remain for documented legal or operational retention periods. Deleting a TAX TALK account does not cancel an active Google Play or App Store subscription; users must cancel store subscriptions separately to avoid future charges. See the dedicated Delete TAX TALK account page for in-app and web request steps. Exceptional requests may be sent to taxtalk66@gmail.com.
User rights
Users may request access, correction, deletion, restriction, objection, withdrawal of consent, or a copy of their personal data where applicable. Some deletion requests may limit or disable app features that depend on the deleted data.
Children
TAX TALK is not designed for children. Users who are minors should use the app only with appropriate guardian consent.
Changes
We may update this policy when features, providers, or legal requirements change. The latest effective date will be shown on this page.