Why the AI assistant needs access to your data
For the AI assistant to answer specific questions about your business — like "How much have I invoiced this year?" or "Who owes me money?" — it needs access to your data in Taxorio. Without that access, it could only answer general legislative questions, not questions tied to your own business.
What data the AI can see
The AI assistant has access to these categories of data from your account:
- Invoices — issued invoices: numbers, customers, amounts, dates, status (paid/unpaid), line items.
- Expenses — received invoices and other costs: suppliers, amounts, categories, dates.
- Clients — name, company ID (IČO), tax ID (DIČ), address, contact email and phone number.
- Company settings — company name, company ID (IČO), tax ID (DIČ), VAT payer type, bank details (IBAN, account number), default VAT rate and payment term.
- Financial overview — total income, expenses, profit and VAT for the current year.
- Tax overviews — VAT records, the income tax overview, the status of social and health insurance advances, and the nearest deadlines from the tax calendar.
- Document inbox — documents you've uploaded or emailed in: file name, supplier, document number, amount.
- Incoming payments — payment notifications from email and their matching status against invoices.
What data the AI doesn't see
To protect your privacy and security, some data is deliberately excluded from AI processing:
- Your account password — the password isn't accessible or displayable by any part of the app.
- Payment and credit cards — billing details for your Taxorio subscription.
- MCP authentication tokens — security keys for integrations with external AI tools.
- Sign-in tokens — session authentication data.
How the data is processed
The AI assistant in Taxorio is built on the Google Gemini model. With every question, the relevant data from your account is sent along with the question to the Gemini API, and once the answer is generated, Google doesn't store it for training its models — Taxorio uses the API in a no-data-training mode.
Data is transmitted encrypted, and every request is tied to your authenticated session — no other user has access to your data.
When the assistant sends something to our support
When the assistant can't help, or runs into an app error, it may pass the issue on to our support team by email. The report includes your identification and a snippet of the conversation, so support knows what it's about. For an obvious app error, the assistant does this on its own so as not to hold you up; otherwise, it asks you first. The report goes exclusively to us — nowhere else.
GDPR — your rights
Taxorio processes data in compliance with the GDPR regulation. Data sent to the Gemini API is processed under Art. 28 GDPR — Google acts as the processor, Taxorio as the controller. Your rights (access, erasure, portability) are guaranteed against Taxorio as the data controller.