Data & security
What happens to your information.
Stated literally, and only what's true today. Where something isn't built yet, this page says so. OpenYear is operated by RegAtlas, LLC.
Right now
OpenYear is in early access and isn't taking anyone else's tax returns, documents or books yet. Everything below describes how the product handles them when it does — and it's running that way today on its founder's own businesses.
Your books
OpenYear reads your books and never changes them. When you connect VisiBooks, the connection itself only allows reading. QuickBooks doesn't offer a read-only permission, so its screen will ask you for full access — but OpenYear's software only ever reads. You can disconnect either one at any time.
Your documents
The file you upload is kept exactly as you uploaded it, including every identification number in it. It's stored in private storage with Backblaze, encrypted at rest.
To read it, OpenYear sends the whole file to Anthropic, through Anthropic's commercial API. Anthropic doesn't use API data to train its models, and deletes it within 30 days — unless its safety systems flag it, in which case it can be kept for up to two years. (Training,retention.)
What OpenYear keeps from reading it — the facts it found, the quoted words behind each one, and a summary — has Social Security, taxpayer and employer identification numbers belonging to anyone other than your business masked to their last four digits. That masking happens after Anthropic has read the file, and it applies to what OpenYear extracts, not to the original.
Nothing read from a document reaches your business's profile until you confirm it.
What's encrypted in the database
- Your business's employer identification number
- The facts read from your documents, and the quoted evidence behind them
- Document summaries and notes
- The credentials for your connected books
- Authenticator-app secrets
Each is encrypted field by field, with keys held apart from the database, so a copy of the database alone doesn't reveal them. Other data — business and owner names, return lines and figures from your books — is protected by access controls, not by field encryption.
Passwords aren't encrypted at all: they're stored only as one-way bcrypt hashes, which can't be turned back into the password.
Signing in
A password and a code from an authenticator app. Sessions end after seven days without use, and after thirty days regardless.
Retention and deletion
Documents, and everything read from them, are kept until they're deleted. There's no automatic deletion schedule.
Deleting a document, a business or an account isn't something you can do yourself yet — today it's done by hand, on request to RegAtlas, LLC at hello@openyear.tax. Self-serve deletion isn't built, and until it is, OpenYear isn't taking anyone else's documents.
Waitlist entries are kept until OpenYear opens to you or you ask to be removed.
This website
The site counts its own visits so it can tell whether it's working: which page was loaded, the site or campaign tag that sent the visit, the country Cloudflare reports, when someone starts the early-access form, and when someone applies. It records no IP address, no browser details, no cookie and no visitor identifier, so it can say how many people arrived and from where — never who. The origin of your visit is held in your browser's session storage, not a cookie, until you close the tab.
There are no third-party analytics or advertising scripts on the site or in the app.
Who processes it
The website and app run on Cloudflare. The application and its database run on OpenYear's own server, which accepts traffic only through Cloudflare's network with a service credential — it isn't reachable directly from the internet. Documents are stored with Backblaze. Anthropic reads uploaded documents.
OpenYear doesn't sell your information, share it for advertising, or use it for anything but your planning.