Privacy policy

5500API is operated by ClayDesk LLC, 45 Burgundy Hills Lane, Middletown, CT 06457, United States. This says what we hold, why, and for how long.

What we never store

EFAST2 signing credentials. A signer types their own User ID and PIN at the moment of signing; we use them once to sign that return and keep nothing — no database column, no log line, and the copy of the filing we keep has both of them masked. Nobody at ClayDesk can sign a return on your behalf, and we could not if asked.

What we hold, and why

WhatWhyHow long
Your name, work email and phone number To know who is acting on a filing and to reach you about one in flight While you have an account, then two years
Plan and filing data you enter To prepare, check and transmit the return Seven years, the usual retention for a filed return, unless you ask sooner
The filing as transmitted, and its acknowledgement It is the record of what was filed; our certification requires we can produce it Seven years
Sign-in codes To prove you can read your own mailbox Ten minutes, and only as a fingerprint of the code
Web server logs To keep the service running and spot abuse 30 days

Cookies

This site sets no cookies at all — no analytics, no advertising, no third-party scripts watching you read.

The application at app.5500api.com sets one cookie, named s5500. It is what keeps you signed in: it holds a signed reference to your session, nothing else, and it expires after a day. It is strictly necessary for the service to work, so there is no consent banner to click away — there is nothing optional to consent to. Signing out removes it.

Who else sees it

  • The U.S. Department of Labor, when you file — that is the point of the service.
  • Amazon Web Services, who host the service and deliver our email, in the United States.

We do not sell anything to anyone, and we use no advertising or analytics networks.

Public information

Form 5500 and 5500-SF filings are public records: the Department publishes them, and we look plans up in that public record to save you typing. Form 5500-EZ filings are not published.

Your choices

Ask us to show you what we hold, correct it, export it or delete it: 5500api@claydesk.com. Deleting an account removes your details; a filed return stays, because it is a record of something that happened.

Security

Everything travels over TLS. Data at rest is encrypted. Access is by emailed code rather than a password, so there is no password of yours for anyone to steal from us.

Last updated 18 September 2026. Questions: 5500api@claydesk.com.