How Quincy handles data
Updated September 8, 2026.
Use Quincy for general tax questions. Do not enter Social Security numbers, account numbers, passwords, tax documents, or other sensitive client information. Questions are processed by AI services; this is not a private document portal.
Visitor conversations
Quincy sends your question and relevant conversation context to its AI providers to generate a reply. Cloudflare hosts the service. OpenAI or Anthropic may process text, depending on the configured service and fallback. Optional voice features use additional speech processing services, including xAI. Those providers' retention and processing are governed by their applicable service terms; Quincy does not promise that they retain no data.
Server-side conversation context expires one hour after its most recent save. The widget keeps the current conversation in page memory and uses browser storage for your information-notice and voice preferences. Closing a page does not erase copies already processed by service providers.
Operational records
New operational message logs retain selected metrics, such as response timing, model usage, detected topic and whether a supported calculation was checked, for up to 90 days. New logs omit the question, answer and page URL. Conversion and topic-count records can remain for up to one year. Error metrics can remain for up to seven days. These records support service operation and billing checks.
Earlier versions stored message text in operational logs for up to 90 days, question samples for up to one year, and short message previews in error logs for up to seven days, measured from collection. Changing new logging does not itself erase those historical records. Contact us if you need help locating or removing information you previously supplied.
Sentry provides error monitoring and receives limited operational diagnostics. New Sentry events omit conversation text and request details. Its processing follows its applicable service terms.
If you deliberately submit an answer or bug report, Quincy may include the selected conversation context so the issue can be investigated. Avoid including sensitive client information in reports.
Firm accounts and payments
We retain a firm's account email, configuration, allowed website addresses, credit balance and transaction records to operate its account, investigate billing issues and reconcile payments. Sign-in links expire after 15 minutes and can be used once. Account cookies expire after 30 days. Email sign-in uses Resend. Card checkout is hosted by Stripe; Quincy records payment identifiers and credit amounts rather than card details.
The firm website service is billed monthly through Stripe. Quincy records the bound customer, subscription, invoice, payment and charge identifiers needed to verify a paid service period, included conversion and billing corrections. It does not store card numbers or security codes.
Account and financial records are retained while needed to operate the account and meet recordkeeping requirements. Account backups follow the service's recovery retention. Ask us about account closure and data removal; financial recordkeeping may limit what can be deleted immediately.
Your firm's services
Booking and telephone links lead to your firm's services. Their privacy notices apply there. A click tracked by Quincy is not proof that an appointment was booked or a call completed.
Contact
For data questions or removal requests, email hello@quincy.tax. Please describe the account or approximate conversation date without sending sensitive tax information in your first message.