Privacy policy
5500API is operated by ClayDesk LLC, 45 Burgundy Hills Lane, Middletown, CT 06457, United States. This says what we hold, why, and for how long.
What we never store
EFAST2 signing credentials. A signer types their own User ID and PIN at the moment of signing; we use them once to sign that return and keep nothing — no database column, no log line, and the copy of the filing we keep has both of them masked. Nobody at ClayDesk can sign a return on your behalf, and we could not if asked.
What we hold, and why
| What | Why | How long |
|---|---|---|
| Your name, work email and phone number | To know who is acting on a filing and to reach you about one in flight | While you have an account, then two years |
| Plan and filing data you enter | To prepare, check and transmit the return | Seven years, the usual retention for a filed return, unless you ask sooner |
| The filing as transmitted, and its acknowledgement | It is the record of what was filed; our certification requires we can produce it | Seven years |
| Sign-in codes | To prove you can read your own mailbox | Ten minutes, and only as a fingerprint of the code |
| Web server logs | To keep the service running and spot abuse | 30 days |
Cookies
This site sets no cookies at all — no analytics, no advertising, no third-party scripts watching you read.
The application at app.5500api.com sets one cookie, named s5500. It is
what keeps you signed in: it holds a signed reference to your session, nothing else, and it
expires after a day. It is strictly necessary for the service to work, so there is no consent
banner to click away — there is nothing optional to consent to. Signing out removes it.
Who else sees it
- The U.S. Department of Labor, when you file — that is the point of the service.
- Amazon Web Services, who host the service and deliver our email, in the United States.
We do not sell anything to anyone, and we use no advertising or analytics networks.
Public information
Form 5500 and 5500-SF filings are public records: the Department publishes them, and we look plans up in that public record to save you typing. Form 5500-EZ filings are not published.
Your choices
Ask us to show you what we hold, correct it, export it or delete it: 5500api@claydesk.com. Deleting an account removes your details; a filed return stays, because it is a record of something that happened.
Security
Everything travels over TLS. Data at rest is encrypted. Access is by emailed code rather than a password, so there is no password of yours for anyone to steal from us.
Last updated 18 September 2026. Questions: 5500api@claydesk.com.