Legal
Privacy Policy
Effective date: March 6, 2026
The short version
CRA Navigator helps Canadians understand letters from the Canada Revenue Agency. You paste or upload a letter, we analyze it using Claude AI (made by Anthropic), and we return a plain-English summary with a deadline and action plan. We collect only what’s necessary to do that job, we encrypt your data at rest, we strip Social Insurance Numbers immediately, and we never sell your information to anyone.
PIPEDA — 10 Fair Information Principles
1.Accountability
CRA Navigator is operated by its founder, who serves as the designated Privacy Officer. The Privacy Officer is responsible for ensuring compliance with this policy and with the Personal Information Protection and Electronic Documents Act (PIPEDA).
You can reach the Privacy Officer at any time: privacy@cranavigator.ca
2.Identifying Purposes
We collect and use your personal information only for the purposes described here, before or at the time of collection:
- To analyze your CRA letter and return a plain-English summary, deadline, and action plan.
- Your letter text is sent to Claude AI (operated by Anthropic, Inc.) for analysis. Anthropic processes it on our behalf under a data processing agreement. Your data is not used to train Anthropic's AI models.
- Analyzed letters are stored encrypted in our database (Supabase, hosted on AWS infrastructure) so you can access them again from your account.
- Letter data is automatically deleted after 2 years of inactivity.
- Payment information is processed by Stripe and never stored on our servers.
- Your data is never sold, rented, or shared with advertisers or third parties for their own purposes.
3.Consent
We require your explicit consent before you upload or paste any letter. A consent checkbox appears on every upload form and must be checked before analysis can begin. By checking that box, you confirm you have read this policy and agree to the described uses.
You may withdraw consent at any time by deleting your account or emailing us. Withdrawal does not affect analysis already completed.
4.Limiting Collection
We collect only the information we actually need:
- Your email address and password (for account creation and login).
- The text of CRA letters you choose to submit.
- Payment details (handled entirely by Stripe — we never see or store card numbers).
- Basic usage data (which letters were analyzed, when) to operate the service.
Social Insurance Numbers (SINs) are automatically detected and stripped from your letter text before it is sent to Claude AI or stored anywhere. We never retain your SIN.
5.Limiting Use, Disclosure, and Retention
Your letter data is used only to perform the analysis you requested. Specifically:
- Letter content is never used to train AI models (ours or Anthropic's).
- Letter content is never shared with third parties except Anthropic (analysis) and Supabase (storage) — both acting as processors under contractual obligations.
- We do not disclose your information to the CRA, government, or law enforcement except where required by law and after receiving a valid legal order.
- Letters are retained for 2 years from last activity, then permanently deleted.
6.Accuracy
You can view, correct, or delete your letters and account data at any time from your dashboard. If you believe information we hold about you is inaccurate, contact us and we will correct it promptly.
7.Safeguards
We use technical and organizational safeguards appropriate to the sensitivity of your information:
- All data in transit is encrypted via HTTPS/TLS.
- Letter text is encrypted at rest using AES-256 encryption (via pgcrypto). The encryption key is never stored in the database.
- Database Row Level Security (RLS) ensures you can only access your own data — even at the application layer.
- Social Insurance Numbers are stripped before any storage or AI processing.
- Access to production systems is restricted to the Privacy Officer.
- Stripe handles all payment data under PCI-DSS Level 1 compliance.
8.Openness
This privacy policy is publicly available at cranavigator.ca/privacy. We will notify registered users by email of any material changes to this policy at least 14 days before changes take effect.
9.Individual Access
You have the right to access a copy of the personal information we hold about you. To request a copy, email privacy@cranavigator.ca with the subject line “Data Access Request.” We will respond within 30 days.
You also have the right to request deletion of all your personal data. You can delete individual letters from your dashboard, or request full account deletion by emailing us. Deletion is permanent and irreversible.
10.Challenging Compliance
If you believe we have not complied with this policy or with PIPEDA, you may file a complaint with us first. Send your complaint to privacy@cranavigator.ca. We will investigate and respond within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Quebec residents — Law 25
If you are a resident of Quebec, you have additional rights under Loi 25 (Act to modernize legislative provisions as regards the protection of personal information). These include the right to data portability (receiving your data in a structured, commonly used format) and the right to be forgotten (erasure of your data). To exercise these rights, contact us at privacy@cranavigator.ca.
We conduct privacy impact assessments for any new technology that processes personal information, as required by Law 25.
Third-party service providers
We use the following service providers to operate CRA Navigator. Each is bound by contractual privacy obligations:
- Anthropic, Inc. — AI analysis of letter text. Anthropic does not use your data to train models. See anthropic.com/privacy.
- Supabase — Encrypted database storage and authentication. Data is hosted on AWS (us-east-1). See supabase.com/privacy.
- Stripe, Inc. — Payment processing. Stripe is PCI-DSS Level 1 certified. See stripe.com/privacy.
Contact us
For any privacy questions, data requests, or complaints:
Privacy Officer — CRA Navigator
Email: privacy@cranavigator.ca