1. Overview
TaxAssembly LLC (“TaxAssembly,” “we,” “us,” or “our”) operates an education platform for accounting and related subjects (including financial, managerial, and intermediate accounting; taxation; auditing and assurance; and related practice tools). This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you.
This Policy applies to taxassembly.com, related subdomains, classroom pilots, and other services that link to it (the “Service”). It does not apply to third-party websites or services that we do not control. By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
If your school or organization has a separate data processing agreement or pilot memorandum with us, that agreement may provide additional or different terms for institutional education records. Where required by that agreement or by law, those terms control for the covered data.
2. Who this Policy covers
Depending on how the Service is used, we may process information about:
- Website visitors
- Students and other learners
- Professors, instructors, teaching assistants, and school staff
- Account contacts at universities, colleges, departments, or firms evaluating or purchasing the Service
3. Information we collect
We collect information in the following categories. Exact fields depend on the features you use and whether you are in a classroom pilot or another environment we operate.
3.1 Information you provide
- Email-join students — school email address, password, and the time you accepted the signup notice. We do not collect a name on this path. Self-registration currently requires an address ending in “.edu”.
- Code-join students — a sign-in code issued by the instructor (stored so the instructor can read it back). We do not collect a name or email on this path.
- Instructors and administrators — email address, password, and a name if an administrator enters one when creating the account. Instructors cannot self-register.
- Classroom and coursework data — course enrollment, assignments, due dates, submitted answers, scores, answer-release timing, and document markup (pen strokes and notes on case PDFs).
- Communications — such as messages you send through contact forms or support requests
- Payment or contracting data — if you purchase or contract for the Service, billing and agreement details needed to administer the relationship (payment card data, if any, is typically processed by a payment provider and not stored by us in full)
3.2 Information collected automatically
- Usage data — pages and features used, clicks, timestamps, referring URLs, and similar interaction data
- Device and technical data — IP address, browser type, operating system, device identifiers, language settings, and diagnostic or error logs
- Cookies and local storage — a signed session cookie keeps you signed in; the browser may also hold a copy of your display account for the interface (see Section 7)
3.3 Information from institutions or instructors
Instructors create a class and either share a join code (students register with their school email) or issue sign-in codes (no name or email is collected). We do not currently provide a roster-file upload that enrolls students from a school spreadsheet. If you are an instructor or institution, you are responsible for having a lawful basis to use the Service with your students and for notifying them as required by your policies and applicable law.
3.4 What we do not want in classrooms
Demo and typical classroom environments are built around fictional clients, documents, and scenarios. Please do not upload real Social Security numbers, real taxpayer ID numbers, real client working papers, bank account numbers, passport numbers, or other highly sensitive personal data unless we have agreed in writing to a production configuration with appropriate safeguards. If you submit such data contrary to this request, we may delete it and suspend related access.
4. How we use information
We use information to:
- Provide, operate, maintain, and improve the Service
- Create and authenticate accounts and maintain sessions
- Deliver coursework features — for example, assignments, submissions, scoring, answer release, instructor dashboards, and progress views
- Respond to inquiries and provide support
- Monitor performance, reliability, security, fraud, and abuse
- Communicate about pilots, product updates, service notices, or agreements you or your institution enter into
- Comply with law, enforce our Terms, and protect rights and safety
- Create aggregated or de-identified statistics that do not reasonably identify you, which we may use for research, product improvement, and reporting
We do not sell personal information, and we do not use student education data for targeted advertising.
5. Education records and FERPA
When the Service is used by a U.S. educational institution in a way that involves student education records under the Family Educational Rights and Privacy Act (“FERPA”), we intend to process such records as a “school official” or service provider to the institution, with a legitimate educational interest, as described in the institution's policies and any data processing or pilot agreement with us.
- The institution (not TaxAssembly) determines the educational purpose for which student data is used in its courses.
- We use education records only to provide the Service to the institution and its authorized users, and for related security, support, and legal compliance — not for unrelated commercial marketing to students.
- Instructors and institutions should share only the student data needed for classroom use and should not require sensitive identifiers that are unnecessary for the product.
- Requests by students to inspect or amend education records should generally be directed to the school; we will assist the institution as required by our agreement and applicable law.
If your institution needs a signed data processing agreement before a pilot or production use, contact us before students join a class.
6. How we share information
We may share information in these circumstances:
- With your instructor — for a class you are in, the instructor who owns that class can see assigned work, submissions, scores, and progress, and can issue a temporary password for your account
- With TaxAssembly administrators — operators of the Service may look up an account (by email or sign-in code) to reset a password, delete a term, or handle a deletion request. Those actions are recorded in an administrative audit log
- Service providers — vendors that help us host, store, secure, authenticate, analyze, communicate, or operate the Service, under confidentiality and data-use restrictions appropriate to their role
- Legal and safety — when we believe disclosure is required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or security of TaxAssembly, users, or the public
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to continuing confidentiality protections
- With your direction — when you ask us to share information, or when an instructor copies scores into a school gradebook outside the Service
We do not sell personal information as that term is commonly understood under U.S. state privacy laws, and we do not share personal information for cross-context behavioral advertising.
7. Cookies and local storage
We use an httpOnly session cookie to keep you signed in (currently for several days). The browser may also store a copy of your display account and similar interface state in local storage so pages can render; that copy does not replace the signed cookie, which is what the server trusts. Error reporting (when enabled) may send technical diagnostics to our provider; we configure it not to include request bodies, cookies, or session replay of the screen. Disabling cookies may cause sign-in to stop working.
8. Data retention
For a class a student joins through the Service, an administrator deletes that class and its coursework data (roster rows, assignments, submissions, and related class records) within 90 days after the term ends. That deletion is done in the administrator console; it is not an automatic job. A student account is removed in that step only when the student is not enrolled in another class that is still running — the account belongs to the student, not to a single course. Instructor and administrator accounts are staff accounts and are not deleted with a term.
Document markup (pen strokes and notes on case PDFs) is stored with the student account, not with a course. If the account remains because the student is still enrolled elsewhere, markup from a finished course may remain until the account itself is deleted.
We otherwise retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. A signed institutional agreement may set a different schedule. Backup copies and legal holds may delay complete removal.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information appropriate to the nature of the data and our stage of product deployment. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk regarding residual security threats.
If we become aware of a security incident affecting personal information we process for an institution, we will notify the institution as required by our agreement and applicable law (for education-record incidents, our target is to notify the institution without unreasonable delay and, where a contract specifies a shorter period such as 72 hours, in line with that contract).
10. Children
The Service is intended for college-level and adult professional use and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
11. Your choices and rights
Depending on your location and role, you may have rights to request access, correction, deletion, or a copy of personal information we hold about you, or to object to or restrict certain processing. To make a request, contact jay@taxassembly.com. We will respond consistent with applicable law. We may need to verify your identity and, for student education records controlled by a school, we may direct you to your institution or coordinate with the institution.
In the product, students and instructors can change their password. Other account details are not edited in-app. The Service does not send email, including password-reset or marketing messages. To request deletion of an account, contact your instructor or jay@taxassembly.com.
12. International users
TaxAssembly is based in the United States. Student self-registration currently requires a “.edu” address, so that path is limited to U.S. institutions. If you access the Service from outside the United States, you understand that your information may be processed in the United States and other countries that may have different data-protection rules than your country. Where required, we will use appropriate transfer mechanisms or contractual terms.
13. U.S. state privacy notices
If you are a resident of a U.S. state that provides additional privacy rights (for example, California), you may have rights to know, delete, correct, or opt out of certain sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise applicable rights, contact us at the email below. We will not discriminate against you for exercising privacy rights under applicable law. Authorized agents may submit requests where the law allows, subject to verification.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect revisions. Material changes will be posted on this page and, where appropriate, we may provide additional notice. Continued use of the Service after the effective date constitutes acknowledgment of the updated Policy, except where applicable law or an institutional agreement requires a different process.
15. Contact
Privacy questions and requests: jay@taxassembly.com
TaxAssembly LLC