Privacy Policy

Last updated: 19 August 2026

This Privacy Policy explains how OpenAccountants ("OpenAccountants", "we", "us") collects, uses, and protects personal data when you use openaccountants.com, our API and MCP server, and related services (the "Service"). OpenAccountants is operated from Malta (EU). We act as the data controller for the personal data described here. Questions: info@openaccountants.com.

1. Data we collect

Account data. When you create an account we collect your name, email address, and authentication details. Sign-in is handled by our authentication provider.

Accountant data.If you apply to join the network as an accounting professional (a "Verified Accountant") we collect your professional credentials (e.g. designation, licence or registration number), jurisdiction, firm name, years of experience, and anything you choose to add to your profile or application.

Reviews. Guides you review, correct, or help keep current, and any comments or feedback you submit.

Fact review & suggestions (no account needed). On any public Guide page you can tell us whether a specific fact looks correct or needs a closer look, suggest a missing fact, or propose a new Guide, without signing in. If you choose to provide them, we collect your name, email, and any optional professional credential and practice jurisdictions you add, along with your reactions and any content you suggest. These submissions are stored in a private, admin-only queue and are reviewed by our team before anything changes on the site; we use them to improve the Guides and to match potential Accountants with Guides in their area.

Technical data. Standard server logs, IP address, device/browser information, and cookies necessary to keep you signed in and to operate the Service.

Communications. Messages you send us by email or through the Service.

MCP server usage. You can call our MCP server at openaccountants.com/api/mcp a small number of times without an account. After that we ask you to sign in, and usage is then recorded against your account. We log tool calls either way, signed in or not.For each tool call we record: the timestamp; the tool name; the jurisdiction and Guide referenced; the free-text question your AI sent (truncated to 500 characters, with automated redaction of email addresses, phone numbers, and identifier-shaped numbers such as SSN, EIN and long account or tax reference numbers, applied before storage); a derived topic label; the one-sentence reason your AI gave for calling, where it supplied one; whether the question was for yourself or a client; a per-conversation session identifier; a non-identifying summary of what we returned; and your account where you have one. When your AI first connects we also record the name and version it reports for itself (for example "ChatGPT" or "Claude") and a coarse country. We do notstore the caller's IP address in raw form, only a one-way salted hash. We never receive your underlying documents or financial records — only what your AI sends to our tools.

Your questions are visible to contributing accountants, without your name. The question text, your broad role (taxpayer or accountant), the jurisdiction, and which Guide answered may be shown to approved accountants who contribute to the library, so the named professionals maintaining the Guides can see how their work is used and improve it. We do not show them who you are— no name, no email, no account. They cannot contact you from it. An accountant sees only their own registered country, and their own usage and that of other accountants is excluded. This is a small, identifiable group of professionals maintaining the Guides — not the paying partners described in section 7, who never receive any of it.

You can switch this off, and it applies to you alone. Email us at the address below and we will exclude your account from every accountant-facing view, permanently, without affecting your use of the Service in any way. If you use the Service without an account, no name is attached to your questions at all.

2. Public information, please read

OpenAccountants is an open, public library. If you review a Guide as a Verified Accountant (an accounting professional in our network), your name and professional credentials are published publicly as the accountant who reviewed it, on the relevant Guide pages, in our public accountant listings, and surfaced to AI agents that load the Guides (for example via our MCP server, as machine-readable Skills). By submitting a review you consent to this public display. We do not publish your email address, phone number, or account login details.

3. How we protect the accountants

We take the same care with the accountants in our network that we ask them to trust us with.

We never see an end user's data.We do not receive or store the financial data, transactions, or client information an AI agent processes when it uses a Guide, so an accountant is never exposed to an end user's data through OpenAccountants.

We publish credit, not contact details.We publish only an accountant's name and professional credentials, and only with their consent, as credit for the reviews they choose to stand behind. We never publish their email, phone, login, or private contact details.

Reviewing creates no liability to users. Contributing a review to the public library does not form a client relationship with, or a duty of care to, any user, and users assume the risk of their own reliance. See our Terms of Use (sections 5 and 6).

4. How we use your data

To provide and operate the Service; to verify your professional credentials; to publish reviewed Guides and credit the accountants who reviewed them; to match users who request a professional review with accountants for their jurisdiction; to communicate with you; to maintain security and prevent abuse; and to comply with our legal obligations.

Inferring your home jurisdiction. If you hold a taxpayer account, have not told us which country you are in, and ask our tools about a specific country, we record that country on your profile as a best guess, so we can show you the deadlines and rules that are likely to matter to you. We never overwrite a country you set yourself, and we never do this for accountant accounts. A guessed country is stored marked as inferred rather than declared, and you can change or clear it at any time in your profile settings.

5. Legal bases (GDPR)

Where the GDPR applies, we rely on: contract (to provide the Service you sign up for), consent (e.g. publishing your name as the accountant who reviewed a Guide, optional communications), and legitimate interests (operating, securing, and improving the Service). You can withdraw consent at any time.

6. Sharing and processors

We do not sell your personal data. We share it only with the service providers who process it on our behalf, under appropriate agreements. Our current processors are: Supabase (database, authentication and file storage), Railway (application hosting), and Resend (transactional email). Where you engage with us through a third-party platform (for example a freelance marketplace), that platform's own terms and privacy policy also apply. Open-source edits and published review records are, by their nature, public, and Guide content is mirrored daily to our public GitHub repository carrying the name of the accountant credited with each change and no other personal data.

7. Commercial partners, and exactly what they receive

Firms and software companies can pay to sponsor a jurisdiction, a topic or a migration corridor. Sponsorship buys placement on Guides and aggregate demand statistics only— for example “capital gains in Malta: 14 questions this month, 8 in the last 30 days, no Guide yet”.

To be unambiguous about what a paying partner does not receive: they do not receive your name, your account, your session, the text of your questions, or any row-level record of an individual query. Aggregate counts are computed so that they describe a market, not a person. This is the same demand data we publish to contributing accountants in aggregate form, and it is the only usage data that is ever sold.

Introductions are opt-in and only ever by your choice. A partner may be offered the chance to help with a question our library could not answer, but you are never introduced to anyone unless you explicitly ask to be. We record that choice, with a timestamp, when you make it. Silence, inactivity, or simply using the Service is never treated as agreement to be contacted.

8. International transfers

Our providers may process data outside your country, including outside the EEA. Where required, such transfers are protected by appropriate safeguards (such as Standard Contractual Clauses).

9. Retention

We keep account and review data for as long as your account is active and as needed to operate the Service and meet legal obligations. We do not currently run an automatic deletion schedule for the tool-call records described in section 1: we keep them until you ask us to remove them, or until they are no longer needed to operate the Service. You can ask us to delete them at any time using the contact address at the end of this policy, and we will do so within 30 days unless we must keep something to meet a legal obligation. Published review records and open-source edits may remain part of the public record and the open-source repository even after an account is closed; you can ask us to remove your name from future displays where feasible.

10. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data; object to or restrict certain processing; request portability; and withdraw consent. To exercise these rights, email info@openaccountants.com. If you are in the EU/EEA you may also lodge a complaint with your supervisory authority (in Malta, the Information and Data Protection Commissioner).

11. Cookies

We use cookies that are necessary to operate the Service (for example to keep you signed in) and may use limited analytics to understand usage. You can control cookies through your browser settings.

12. Children

The Service is not directed to children and is intended for users aged 18 or over.

13. Changes

We may update this policy from time to time. We will post the updated version here with a new "last updated" date.

14. Contact

OpenAccountants: info@openaccountants.com. See also our Terms of Use.