AI-Use Disclosure
Exactly where Hypertax uses AI, where it does not, why sending your return information to a model vendor needs your consent, and what happens if you decline.
- Effective
- Last updated
Plenty of tax products now say they are "AI-powered" without saying what that means, which leaves you to guess whether a language model is reading your T4, writing your return, or picking your credits. This page removes the guesswork.
The short version
- Every AI feature described on this page is currently switched off. The consents they depend on are still in draft and awaiting legal review, so nothing about anyone's return is being sent to a model vendor today. Hypertax runs the manual path for all of them, and the return you get is the same return.
- When they are turned on: AI reads your uploaded T4, rephrases questions when you ask for one to be explained differently, and answers support questions from our published help content.
- AI does not compute your tax. Not one number on your return is produced by a model, then or now.
- Nothing about your return is sent to an AI vendor unless you have specifically consented, on a separate document, beforehand.
- If you decline, you can still complete the whole return by typing your figures in. It is the same return.
Where AI is used
Reading your T4
You can photograph or upload your T4 and have Hypertax read it, instead of typing every box. The image or PDF is sent to a vision-capable model, which returns the field values it can see in a fixed, structured shape.
What happens next is the part that matters: we show you every extracted value next to a confidence indicator and ask you to confirm it against the slip in your hand. An unconfirmed value does not enter your return. The model's output is a suggestion for a form field, never an accepted fact.
Rephrasing a question
The interview asks the same questions in the same order for everyone; the order comes from a fixed question graph, not from a model. If a question is unclear you can ask for it to be put differently, and a model rewrites that one question.
What is sent for this is the question, not your answers. Rephrasing changes the wording you read; it does not change what is asked, which question comes next, or what your answer does.
Answering a support question
The help assistant answers from our published help articles and from nothing else. It has no access to your return, your figures, your documents or your account. If the answer is not in the published content, it says so and offers to put you through to a person.
This is a deliberate architectural boundary, not a policy we intend to keep to: the support assistant is not connected to return data at all, so it cannot leak it.
Where AI is not used, and this is the important part
The AI never computes tax.
Every calculated figure on your return — every total, every threshold test, every bracket, every credit, every rounding — is produced by a deterministic tax engine. The engine is ordinary software: given the same inputs it returns the same outputs, every time, and every number it produces traces to a specific entry in a versioned rule table and to a test that proves that entry behaves as the Income Tax Act says.
Concretely, no model:
- computes any amount, applies any rate, or performs any arithmetic on your return;
- decides your marital status, your residency, or whether you qualify for a credit or deduction;
- chooses which form, schedule or line something goes on;
- decides whether your situation is within the scope Hypertax supports.
We record which version of the rule tables produced each return, so a figure can always be traced back to the data that produced it. A language model's output cannot be traced that way, which is the reason it is kept out of the arithmetic.
Sending your information to an AI vendor requires your consent
Your T4, your figures and the image of your slip are personal information of the most sensitive kind, and you gave them to us for one purpose: preparing your return. Sending any of it to Anthropic or OpenAI is a disclosure to a third party for a different purpose, and under PIPEDA that requires your consent — consent that is meaningful, which means you understood what was being sent, to whom, for what, and what could go wrong before you agreed.
It is also a disclosure that leaves Canada. Neither vendor has committed to us in a contract that its inference runs in any particular country, so we treat the transfer as a cross-border one and tell you so on the face of the consent rather than in a footnote. If you are in a province with its own private-sector privacy statute, that statute governs alongside PIPEDA, and Quebec's Law 25 in particular requires an assessment before personal information is communicated outside the province.
What that means for the document you are asked to sign:
- Consent to disclose and consent to use are separate documents. Sending your information to someone else and using it ourselves for something other than your return are different things, you may want one and not the other, and rolling them together would make neither of them meaningful. Neither can be folded into these terms or into a general "I agree" checkbox.
- It is opt-in only. No pre-ticked boxes, no consent by continuing to use the site.
- It is purpose-specific. You choose each purpose separately, and you are offered something narrower than handing over the whole return.
- It names the recipient, says the information may be handled outside Canada, and says in plain language what the consequences of that are.
- It is refusable and revocable. Saying no costs you nothing but typing, and you can take a consent back at any time.
- You get a copy, and we keep the record of what you agreed to and when.
Both live at /legal/consent, separate from everything here and separate from each other: the consent to disclose covers information leaving Hypertax, the consent to use covers Hypertax doing something with it other than preparing your return. You would be asked at the moment a feature needs it — not at sign-up, and never as a condition of using Hypertax.
Neither is in force. Both instruments are drafts awaiting legal review, Hypertax asks nobody to agree to them, and the software refuses the disclosure rather than assuming one. That is why the AI features are off, and it is the reason to read this page as a description of how the feature is built rather than of something happening to your data today.
Pending counsel review · CR-AI-01
Pending counsel review · CR-AI-02
If you decline, you still get a complete return
Consent is optional, and declining it is a normal way to use Hypertax rather than an error state. It is also, at the moment, everybody's experience, because the features are off.
Every AI feature has a manual equivalent that produces exactly the same return:
- Instead of uploading a T4 to be read, you type the boxes in yourself. The same fields, the same validation, the same result.
- Instead of asking for a question to be rephrased, you read the written explanation and examples we publish for it.
- Instead of asking the help assistant, you search the help centre or contact a person.
Nothing about the return differs. The computation is the same deterministic engine either way, the PDF is the same PDF, and the price is the same price. What you give up is typing time, and nothing else. You can also withdraw a consent later; withdrawing it stops future disclosures and never blocks you from finishing.
Which vendors, and what they receive
Our model vendors are Anthropic and OpenAI. Which of them handles a given feature can change; the rules on this page do not.
Neither has committed to us in a contract that its inference runs in any particular country, so we do not tell you that your information stays in Canada — we do not know it. Until that commitment exists, the consent you would be asked to sign treats the disclosure as one that crosses the border and says so on its face. That is the conservative reading, and it is the one we would rather be wrong in your favour about.
They receive only what the feature needs, and only after you have consented:
- For slip reading: the image or PDF you uploaded.
- For rephrasing: the text of the single question being rephrased.
- For support: your question and our published help articles.
They do not receive your account identity, your assembled return, or your other documents. No vendor is permitted to train on your information, and we do not use it to train, fine-tune or evaluate a model.
What can go wrong, and what we do about it
We would rather set out the failure modes than imply there are none.
- Extraction can misread a slip. Bad lighting, a fold across a box, an unusual layout. This is why every extracted value is shown to you for confirmation against the original, and why an unconfirmed value never enters the return.
- A model can be confidently wrong. A support answer can be phrased with more certainty than the underlying help article justifies. Nothing an assistant says overrides the published help content, the CRA's own instructions, or the not-tax-advice disclaimer.
- An uploaded document is untrusted input. A document can be doctored to contain text intended to manipulate a model that reads it. We treat every uploaded file as hostile: extraction models are constrained to emit a fixed structure, are given no tools, and extracted text is treated as data and never fed back into a later instruction.
- Cost and availability. AI features run under hard spending limits and can be unavailable. When they are, the manual path is still there, which is the point of having one.
AI output is not advice
Everything in the not-tax-advice disclaimer applies to every AI feature. A model explaining a rule is not a professional advising you, an extracted figure is not a verified figure until you verify it, and a support answer is not a ruling.
Changes
If we add an AI feature, change what is sent to a vendor, or change vendors, we will update this page with a new version and effective date, and — where the change widens a disclosure — we will ask for consent again rather than rely on one you gave for something narrower. Turning any of these features on at all is such a change, and we will say so here when it happens.
Change history
| Version | Date | What changed |
|---|---|---|
| 1.1.0-draft | Hypertax is now a Canada-only service. The consent requirement is restated on its Canadian basis — meaningful consent under PIPEDA, and Law 25 where information would leave the province — and the page now says plainly, at the top, that every AI feature is currently switched off pending legal review. | |
| 1.0.2-draft | Stopped stating that both model vendors process in the United States: the provider register records it as assumed and unverified. CR-AI-02 cross-referenced to the compliance and security registers so the question is asked once. | |
| 1.0.1-draft | Consent instruments published; both are now linked individually and CR-AI-01 narrowed to the wording review that remains open. | |
| 1.0.0-draft | Initial draft prepared for counsel review. Not in force. |