Privacy Notice

How Virtus Professional Services LLC handles information when you use Virtus.

Effective September 25, 2026

  • We use your information to run the research service for you and your firm.
  • We do not sell personal information, use advertising or targeting cookies, or use your content to train AI.
  • Our count of site visits sets no cookies, stores no IP address, and skips browsers that send Global Privacy Control.
  • Highlights and notes you make on documents stay in your browser unless you save them to your workspace.
  • You can ask your workspace administrator, or write to admin@virtusprofessionalservices.com, to access, correct, export, or delete your information.

This summary is for convenience. The full text below controls.

Scope

This notice describes how Virtus Professional Services LLC, referred to here as Virtus, collects, uses, discloses, and retains information when you use the Virtus tax research service and website. For the content of a firm’s workspace, we act on behalf of that firm, and the firm’s own policies and agreement with us also apply. For account, billing, and website information, we decide how information is used as described here.

Information we handle

  • Account and workspace information: your name, email address, organization membership, role, license, authentication records, and active sign-in sessions. If a sign-in option such as Google or company sign-in is enabled and you choose it, the sign-in flow supplies the identifiers needed to sign you in.
  • Research and workspace activity: search requests needed to return results, research folders you create, documents you save, and related workspace activity. Raw research query text is not retained by default. If a workspace expressly approves and consents to retention, the maximum period is 30 days.
  • Highlights, notes, and downloads: highlights and notes you add to a document are kept in your browser on that device. Annotated copies you download are created in your browser and are not sent to us.
  • Service records: operational, security, application, administrator, and audit events needed to run and protect the service.
  • Commercial records: seat, entitlement, billing, tax, contract, and deletion-receipt information when those records apply to your organization. Card details are collected and stored by our payment processor, not by us; we receive limited details such as the card brand and last four digits.
  • Messages you send us: the contents of emails and support requests.
  • Demo requests: what you enter on the Book a demo page is emailed to our team so we can reply. It is not stored in the product.
  • Site visit counts: when a page of the site loads, the page address without any search terms or other query text, the website that referred you (its domain only), your country as determined from your connection, and whether you are on a phone, tablet, or computer. No cookie is set and no IP address is stored. The Cookie Policy explains how visits are counted.
  • Workspace usage for administrators: daily counts of searches, documents opened, and seats in use for this workspace only. Those counts do not include the words you searched or any document text, and they are not used to train shared AI.

How we use information

We use this information to:

  • authenticate users and enforce workspace roles and access;
  • provide search, document, folder, citation, and research-assistance features;
  • maintain sessions, service reliability, security, and audit records;
  • support workspace administration and respond to requests;
  • manage applicable subscriptions, entitlements, contracts, and legal duties; and
  • send service, security, and billing messages.

We do not use your workspace content, questions, or annotations to train AI, and we do not sell personal information or share it for targeted advertising.

Public source documents

The research library currently contains public IRS rulings. Virtus may add materials from other approved United States government sources in the future. Public source documents are separate from your account, workspace, and research activity. A question you ask or a research folder you create does not become part of a public source document. Government documents can contain names or other details that the publishing agency chose to release; we display them as published.

AI and transcription features

If an AI-assisted or transcription feature is enabled, it may process the current request and retrieved public source evidence to produce a research aid. If another company helps deliver that feature, it processes the information for us under agreements that do not allow it to use your requests to train its AI. Processing of public source documents alone, which contain no information about you, may be kept by those companies for quality review. Generated answers, summaries, and transcribed text are not official source text and may contain errors.

Cookies and browser storage

  • Virtus uses a necessary sign-in cookie. It expires after 30 minutes and never lasts more than 12 hours; signing out ends it sooner. Short-lived cookies also protect a sign-in with Google, Microsoft, or company sign-in and a two-step verification check while it is in progress.
  • Browser local storage remembers the theme, navigation rail, and document-view preferences. Some features also keep device-local research folders, update state, and document highlights there. Clearing site data in your browser resets those preferences and removes any data stored only on that device.
  • Site visits are counted without cookies or any identifier stored in your browser. To count unique visitors, we combine your IP address and browser details with a random value that changes every day and is then deleted, and keep only the resulting one-way code, so it cannot be used to identify you or to link your visits across days. Browsers that send Global Privacy Control are not counted. Your research query text is never included.

Virtus counts site visits to understand how the site is used and improve its reliability. It does not use advertising or targeting cookies, sell your personal information, or track you across other websites. The Cookie Policy lists each cookie and storage item and how to control them.

When information is disclosed

  • Authorized workspace administrators and members can access workspace information according to their assigned roles.
  • Companies that help us provide hosting and security, sign-in, email, payments, and assisted research process information on our behalf, limited to what their task needs. A current list is available on request.
  • We may disclose information when required by law or when reasonably necessary to protect users, the service, or the rights and safety of others.
  • If Virtus Professional Services LLC is involved in a merger, acquisition, or sale of assets, information may transfer to the successor under this notice.

Virtus does not make one customer’s research available to another customer.

Retention

We keep information only as long as needed for the purposes above. Our current standard periods, where a record type applies, are:

  • Active and archived account and workspace data: for the account or contract life.
  • Scheduled deletion: a 30-day soft-deletion period followed by a 7-day final hold before deletion from active systems.
  • Account export artifacts: 7 days.
  • Raw research query text: disabled by default; if expressly approved and consented to, no more than 30 days.
  • Operational logs: 30 days.
  • Site visit records, which contain no IP address: about 13 months.
  • Application, security, and administrator audit records: 24 months.
  • Transactional email outbox records: 30 days.
  • Email delivery metadata: 90 days.
  • Billing, tax, contract, and deletion receipts: 7 years.
  • Rolling encrypted backups: 35 days.

We may keep information longer when the law requires it, to resolve disputes, or under a legal hold. Deletion is not instantaneous. Encrypted backup copies expire through the rolling backup cycle. If an external integration is enabled, its retention and deletion rules also apply; a deletion request does not promise immediate removal from every supporting company’s records.

Security

Virtus uses administrative and technical safeguards intended to protect account and workspace information, including authenticated sessions and role-based access. No online service can guarantee absolute security. Tell your workspace administrator, or write to admin@virtusprofessionalservices.com, if you suspect unauthorized access or find a security issue.

Your choices and requests

  • You can sign out to end the current session.
  • You can clear browser site data to remove device-local preferences and records.
  • If your browser sends Global Privacy Control, we honor it: your visits are not counted, and it is treated as a request to opt out of any sale or sharing of personal information. We do not sell or share personal information for advertising in any case.
  • Ask your workspace administrator to correct membership details or manage your workspace access.
  • To request access, correction, export, or deletion, contact your workspace administrator. Requests are evaluated under applicable law, workspace authority, and contractual requirements.

Depending on where you live, you may have rights to know, access, correct, delete, or port your personal information, and to opt out of certain uses. You can make a request through your administrator or by writing to admin@virtusprofessionalservices.com. We verify requests before acting on them and will not treat you differently for making one. If we deny a request, you can appeal by replying to our decision.

Where information is processed

Virtus is operated from the United States. Information is processed in the United States and in other countries where the companies that help us operate, with safeguards required by applicable law.

Professional use only

Virtus is a service for professionals and businesses. It is not directed to children or to individuals acting in a personal capacity, and we do not knowingly collect information from anyone under 18.

Changes to this notice

We may update this notice when the service or applicable requirements change. The notice will show its effective date so you can identify the current version, and we will notify workspace administrators of material changes.

Contact

Direct privacy questions or requests through your workspace administrator.

You can also write to Virtus Professional Services LLC. Send privacy and data requests to admin@virtusprofessionalservices.com. For everything else, use the address that matches your request:

Product help and account access
support@virtusprofessionalservices.com
Legal notices, arbitration notices, privacy and data requests, and security reports
admin@virtusprofessionalservices.com
Invoices, payments, billing disputes, and seat changes
billing@virtusprofessionalservices.com
Accounts receivable and remittance
ar@virtusprofessionalservices.com

This notice is part of our Terms of Use. See also the Cookie Policy.