Privacy notice
How Box 3 Calculator handles local calculations, optional AI processing and limited technical data.
Your manual calculation stays in this tab
Financial form values and results are calculated in your browser. Confirmed values are kept in sessionStorage for the current tab so language changes do not reset the form. Clear removes the local draft. An exported JSON file is saved on your device and can contain your financial information.
There is no account or cloud calculation history. Do not enter names, addresses, BSN, account numbers or other identifiers; amounts and financial categories are sufficient.
Optional text and voice assistant
Only after your permission, selected text or a recording is sent through our server to OpenAI for transcription or field extraction. You can edit the transcript and confirm proposed fields before calculating. We do not retain recordings, text, transcripts, extracted financial facts or results on our server.
OpenAI API data is not used for training by default. We use store:false for text responses; this is not Zero Data Retention. Provider abuse-monitoring retention can apply to text requests, normally for up to 30 days, with exceptions under its policy. Our server region does not constitute a promise of EU-only provider processing.
Essential abuse and budget controls
Assistant use creates a signed, essential session cookie. Technical Redis records contain rate-limit counters, reserved costs, request status and keyed fingerprints, never your financial payload. IP identifiers are pseudonymized with a rotating keyed hash. Short-lived counters expire; monthly budget records last through the relevant budget period.
We record operational status and accounted usage without request bodies, financial amounts or provider error bodies. These controls protect the free assistant budget and are separate from calculation storage.
Traffic and contact
Vercel Web Analytics receives only public page paths through the EXLA privacy wrapper. Query strings, fragments and custom financial events are excluded; Do Not Track and Global Privacy Control are respected. Infrastructure providers may process technical request data under their own policies.
For privacy questions or deletion of applicable technical data, contact hello@exla.dev. This notice was updated on 8 October 2026.