How Virtus Professional Services LLC handles information when you use Virtus.
Effective August 27, 2026
Scope
This notice describes how Virtus Professional Services LLC, referred to here as Virtus, collects, uses, discloses, and retains information when you use the Virtus tax research service. Your organization may also have its own policies for activity in its workspace.
Information we handle
- Account and workspace information: your name, email address, organization membership, role, authentication records, and active sign-in sessions. If Google sign-in is enabled and you choose it, the authentication flow supplies the identifiers needed to sign you in.
- Research and workspace activity: search requests needed to return results, matters you create, documents you save, and related workspace activity. Raw research query text is not retained by default. If a workspace expressly approves and consents to retention, the maximum period is 30 days.
- Service records: operational, security, application, administrator, and audit events needed to run and protect the service.
- Commercial records: seat, entitlement, billing, tax, contract, and deletion-receipt information when those records apply to your organization.
- Workspace usage for administrators: daily counts of searches, documents opened, and seats in use for this workspace only. Those counts do not include the words you searched or any document text, and they are not used to train models.
How we use information
We use this information to:
- authenticate users and enforce workspace roles and access;
- provide search, document, matter, citation, and research-assistance features;
- maintain sessions, service reliability, security, and audit records;
- support workspace administration and respond to requests; and
- manage applicable subscriptions, entitlements, contracts, and legal duties.
Public source documents
The research library currently contains public IRS rulings. Virtus may add materials from other approved United States government sources in the future. Public source documents are separate from your account, workspace, and research activity. A question you ask or a matter you create does not become part of a public source document.
Cookies and browser storage
- Virtus uses a signed session cookie that is necessary for authentication. It is HttpOnly and SameSite=Lax, and it is marked Secure in live environments. The session initially expires after 30 minutes. Renewals never extend it beyond 12 hours from creation. Signing out ends it sooner.
- Browser local storage remembers the theme, navigation rail, and document-view preferences. Some features also keep device-local matters and update state there. Clearing site data in your browser resets those preferences and removes any data stored only on that device.
Virtus does not currently use browser analytics or advertising integrations, sell your personal information, or track you across other websites.
When information is disclosed
- Authorized workspace administrators and members can access workspace information according to their assigned roles.
- When a service integration is enabled, infrastructure, identity, email, billing, security, or AI providers may process the limited information needed to provide that feature.
- We may disclose information when required by law or when reasonably necessary to protect users, the service, or the rights and safety of others.
Virtus does not make one customer’s research available to another customer.
AI and transcription features
If an AI-assisted or transcription feature is enabled, it may process the current request and retrieved public source evidence to produce a research aid. If an external provider is configured for that feature, the provider processes the data needed for the request. Generated answers, summaries, and OCR text are not official source text and may contain errors.
Retention
The approved default retention schedule, where a record type applies, is:
- Active and archived account and workspace data: for the account or contract life.
- Scheduled deletion: a 30-day soft-deletion period followed by a 7-day final hold before deletion from active systems.
- Account export artifacts: 7 days.
- Raw research query text: disabled by default; if expressly approved and consented to, no more than 30 days.
- Operational logs: 30 days.
- Application, security, and administrator audit records: 24 months.
- Transactional email outbox records: 30 days.
- Email delivery metadata: 90 days.
- Billing, tax, contract, and deletion receipts: 7 years.
- Rolling encrypted backups: 35 days.
Deletion is not instantaneous. Encrypted backup copies expire through the rolling backup cycle. If an external integration is enabled, its retention and deletion rules also apply; a deletion request does not promise immediate removal from every provider system.
Security
Virtus uses administrative and technical safeguards intended to protect account and workspace information, including authenticated sessions and role-based access. No online service can guarantee absolute security. Tell your workspace administrator if you suspect unauthorized access.
Your choices and requests
- You can sign out to end the current session.
- You can clear browser site data to remove device-local preferences and records.
- Ask your workspace administrator to correct membership details or manage your workspace access.
- To request access, correction, export, or deletion, contact your workspace administrator. Requests are evaluated under applicable law, workspace authority, and contractual requirements.
Changes to this notice
We may update this notice when the service or applicable requirements change. The notice will show its effective date so you can identify the current version.
Contact
Direct privacy questions or requests through your workspace administrator.