Skip to content

Privacy & data

When you use Lodgey, the following data is processed:

Data typeHow it’s used
Chat messagesSent to Anthropic’s API for agent reasoning. Not stored by Anthropic beyond the session.
Uploaded documentsStored in your project’s database. Content is extracted and filed as evidence.
Evidence itemsStructured tax facts stored in the project database. Drive the Live Report.
Tax situationStructured data (properties, employers, income, deductions) stored per-project.
Gmail accessRead-only search via OAuth. Lodgey searches for documents — it cannot send, delete, or modify emails.
API keyEncrypted at rest using AES-256. Never logged, never sent anywhere except Anthropic’s API endpoint.
ComponentLocation
DatabaseNeon Postgres (serverless) — hosted in AWS, data encrypted at rest
File uploadsStored in the project database as binary data
Chat historyManaged by Anthropic’s Managed Agents platform during active sessions. Not persisted by Anthropic after the session ends.
Workbook stateStored in the project database as structured JSON

Each agent session runs in its own isolated container on Anthropic’s infrastructure. Sessions cannot access each other’s data, filesystem, or memory. When a session ends, the container is destroyed.

Within your Lodgey account, projects are strictly isolated — the agent operating in one project has zero access to data in another project.

DataRetention
Projects, documents, evidence, workbooksRetained until you delete them
Chat messagesRetained within the session. Session data is retained until you delete the project.
Project memoryRetained until you delete the project
Anthropic API processingAnthropic does not store inputs or outputs from API calls. See Anthropic’s data policy.
Gmail OAuth tokenStored encrypted. Revocable at any time via the Gmail connector panel.

Click your avatar → Delete all tax data. This permanently deletes:

  • All projects
  • All chat sessions
  • All uploaded documents
  • All evidence items
  • All workbook data
  • All project memory

Your account remains active. This action is irreversible.

Click your avatar → Delete account. This permanently deletes:

  • Your user account
  • All associated data (same as “Delete all tax data”)
  • Your stored API key
  • Your settings and preferences

This action is irreversible. You cannot recover your account after deletion.

In the side panel, click the Gmail connection indicator → Disconnect. This revokes Lodgey’s OAuth access to your inbox. Previously searched results remain as evidence items, but no new searches can be performed.

You can also revoke access directly from Google’s security settings.

Click your avatar → SettingsRemove next to your API key preview. This deletes the encrypted key from the database. Lodgey will stop working until you add a new key.

ServicePurposeData shared
AnthropicAI reasoning and agent executionChat messages, document content (for extraction), tool inputs/outputs
NeonDatabase hostingAll structured data (encrypted at rest)
ComposioGmail integrationOAuth tokens, search queries
ResendSystem emails (password reset, feedback confirmation)Email address only
VercelFrontend and API hostingRequest metadata (standard web hosting)
LangfuseObservability and tracingAgent turn metadata (no PII, no document content)
  • Your bank login credentials
  • Your myGov or ATO Online portal
  • Your email content beyond search results (Gmail access is search-only, not full inbox access)
  • Other users’ data
  • Other projects’ data (even within your own account)