Privacy policy
Effective date: June 23, 2026 · Last updated: June 23, 2026
CaseAgents is a product of RESO.tax LLC (“we,” “us,” or “our”).
1. What we collect
We collect only what is necessary to provide the service.
Account and firm data
- Firm name and billing contact information you provide at signup.
- User email addresses and hashed passwords for staff accounts.
- Authentication session tokens (stored server-side, cleared on logout).
Case and client data
- Client names and email addresses you enter when creating a case.
- Documents your clients upload through their secure portal link.
- Case notes, item descriptions, and rejection reasons you record.
- We do not collect Social Security Numbers, EINs, financial account numbers, or tax return data unless you or your client explicitly uploads a document containing that information. Such documents are stored encrypted and served only via short-lived signed URLs.
Event log data
- Timestamps of every action taken on a case (requests sent, reminders delivered, documents submitted, etc.).
- Email delivery, open, and link-click events returned by our email provider.
- Cryptographic hashes linking each event to the previous one (the tamper-evident chain).
Usage and analytics data
- Page views and feature interaction events collected through Vercel Analytics.
- These events are anonymized and do not include client data or case content.
2. How we use it
- To provision and operate your firm account and all cases within it.
- To send document request and reminder messages to your clients on your behalf.
- To generate and maintain the tamper-evident event record for each case.
- To authenticate staff users and protect your firm's data from cross-firm access.
- To communicate with you about your account, billing, service updates, and security notices.
- To detect and prevent abuse of the platform.
We do not sell your data. We do not use your case data or client data to train machine learning models. We do not use your data for advertising.
3. Communication channels we use on your behalf
CaseAgents sends communications to your clients at your direction. The following channel types are in use or planned. You remain responsible for obtaining any consent required by applicable law (including TCPA, CAN-SPAM, and state equivalents) before using these channels.
Document request emails, reminder emails, and completion confirmations are sent via our email delivery provider (Resend). Delivery, open, and click events are tracked and written to the event log to support the defense record. You can configure the sender name and reply-to address in your firm settings.
Voicemail drops (planned)
A future feature will allow firms to deliver pre-recorded voicemail messages to client phone numbers without ringing. These drops are logged to the event chain with timestamp, number attempted, and delivery status. No voicemail content is stored by CaseAgents beyond the delivery event.
AI-assisted calls (planned)
A future feature will allow AI-assisted outbound calls to clients for document follow-up. Call attempts, outcomes (answered, no answer, voicemail), and duration will be logged to the event chain. Recordings or transcripts, if generated, will be stored encrypted, associated only with your firm, and deleted per your firm's data retention settings. All AI calls will identify themselves as automated at the start of the call.
SMS / text messages (planned)
A future feature will allow SMS reminders to be sent to client phone numbers you provide. Message delivery and opt-out events will be logged to the event chain. Opt-outs are honored automatically and permanently at the firm level.
In-portal messages
Messages displayed inside a client's secure portal link (e.g., request descriptions, item notes) are visible only to the holder of that link. They are not indexed by search engines and do not require a client account.
For all channels, the content of communications is determined by you (the firm). CaseAgents records that a communication was sent, delivered, and — where trackable — read or acted upon. This record is the core of the defense record the service generates.
4. Data storage, security, and Vercel infrastructure
Hosting and edge infrastructure
CaseAgents is hosted on Vercel. Vercel operates a global edge network for serving the application and handles TLS termination, DDoS protection, and edge caching. Vercel's infrastructure is SOC 2 Type II audited. Vercel does not have access to your case data or event log contents. Vercel Privacy Policy · Vercel Security.
Database and file storage
Your firm's structured data (cases, clients, items, events) is stored in Supabaseon AWS infrastructure. Every table is protected by row-level security (RLS) policies that enforce firm-level isolation — no query from one firm can read or write another firm's data. The event log table is append-only at the database trigger level: UPDATE and DELETE operations are rejected.
Documents uploaded by your clients are stored in a private Supabase Storage bucket. They are never publicly accessible. Access is granted only via short-lived signed URLs generated at request time and scoped to the requesting firm.
The tamper-evident event log
Each event in the log is linked to the previous event via a SHA-256 hash of the prior hash plus a canonical representation of the new event. This chain means that any alteration to a past event — including by us — would produce a detectable break. The chain integrity is verified on every record export and displayed in the exported record.
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Supabase/AWS encryption). We do not maintain application-layer encryption keys that would allow us to decrypt individual client documents independently of Supabase.
Access controls
CaseAgents staff access to production data is restricted, logged, and requires multi-factor authentication. We use role-based access control and the principle of least privilege. We do not access client data except when required to resolve a support ticket you open, and only with your explicit permission.
5. Third-party vendors
The following vendors process data as part of delivering the CaseAgents service. Each vendor processes only the data described below. No vendor has access to your full case database, event log, or document store beyond what is described.
Vercel (hosting)
Processes HTTP requests, serves application files, and runs serverless functions. Receives IP addresses and request metadata. Does not receive case data or event log contents. Privacy policy · Security.
Supabase (database, auth, storage)
Stores all structured case data, authenticates users, and stores uploaded documents. Supabase operates on AWS and is SOC 2 Type II compliant. Supabase does not access your data except for infrastructure operations (backups, replication) under their Data Processing Agreement. Privacy policy · Security.
Resend (transactional email)
Receives the recipient email address, sender name, subject line, and message body for each email CaseAgents sends on your behalf. Returns delivery, open, and click events via webhook. Resend does not have access to any other case data, documents, or event log contents. Privacy policy.
Plaid (planned — financial document verification)
When the Plaid integration is enabled, clients may choose to share financial account data directly through Plaid's own secure interface. CaseAgents does not receive raw financial account credentials or full account numbers from Plaid. We receive only the verification status and metadata Plaid makes available via its API under the permission scope you configure. Plaid operates under its own privacy policy and is responsible for the security of its own interface. Plaid Privacy Policy.
Phone / voice providers (planned)
When voicemail drop or AI call features are enabled, a voice infrastructure provider (provider to be named at feature launch) will receive the destination phone number and audio content for the call or voicemail. That provider will operate under its own terms and privacy policy, which we will link here at launch. CaseAgents will receive only the delivery outcome (connected, no answer, voicemail left) and log it to the event chain. CaseAgents does not retain audio recordings beyond the duration required to complete the delivery.
SMS providers (planned)
When SMS features are enabled, an SMS gateway provider (provider to be named at feature launch) will receive the destination phone number and message text. CaseAgents will receive delivery and opt-out status. Opt-outs are honored automatically. The provider will operate under its own terms and privacy policy, linked here at launch.
Vercel Analytics
Collects anonymized page view and interaction data for product improvement. Does not receive client names, email addresses, case data, or event log contents. Vercel Analytics privacy.
No vendor listed above receives your full case database, your complete event log, or document contents beyond what is explicitly described. We do not share data with any vendor for advertising, profiling, or model training purposes.
6. Data retention
- Active accounts: Data is retained for as long as your firm account is active.
- Canceled accounts: Case data, event logs, and documents are retained for 90 days after cancellation to allow export, then deleted from primary storage. Backups are purged within 30 days after that.
- Documents: Individual documents can be deleted by your firm at any time via the case detail view.
- Event log: Because the event log is the defense record and its integrity depends on the chain being complete, individual events cannot be deleted. If you require deletion of the entire log for a specific case or firm, contact us.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, port, restrict processing of, or delete your personal data. We support these rights regardless of where you are located. To exercise any of them, contact us at privacy@caseagents.ai. We will respond within 30 days (or the shorter period required by applicable law).
Data portability: You can export all cases, event logs, and uploaded documents at any time from within the application without needing to contact us.
California residents (CCPA / CPRA): You have the right to know what personal information we collect, the right to delete it, the right to opt out of sale (we do not sell data), and the right to non-discrimination for exercising these rights.
EEA / UK residents (GDPR / UK GDPR): Our lawful basis for processing is contract performance (operating the service you signed up for) and legitimate interests (security, abuse prevention). You have rights of access, rectification, erasure, portability, and objection. You may lodge a complaint with your local supervisory authority.
8. Children
CaseAgents is a professional B2B tool intended for adults operating tax resolution businesses. We do not knowingly collect personal information from anyone under 18. If you believe a minor's data has been submitted, contact us and we will delete it promptly.
9. Changes to this policy
We will notify you by email and in-app notice at least 14 days before any material change takes effect. The effective date at the top of this page will be updated on each change. Continued use of the service after a change becomes effective constitutes acceptance of the updated policy.
10. Contact
Privacy questions or requests:
- Email: privacy@caseagents.ai
- General: hello@caseagents.ai
- Mailing address: RESO.tax LLC, [ADDRESS — add before launch]
For a Data Processing Agreement (DPA), contact us at privacy@caseagents.ai.