In short
- Everything about firms and their clients is stored and processed in Australia.
- Tax file numbers are removed automatically and never stored.
- Your information is never sold, never used for advertising and never used to train AI.
- The only overseas provider is Stripe, for billing, and it sees no client information.
1.About this policy#
This policy explains how EasyFlowAI Pty Ltd (ABN 31 686 450 206), trading as PrepDesk (“PrepDesk”, “we”, “us”) collects, uses, stores and discloses personal information. It covers this website (prepdesk.com.au), the PrepDesk waitlist, and the PrepDesk service used by accounting firms (app.prepdesk.com.au).
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2.Our two roles#
We handle personal information in two different ways:
- Our own information. The details of people who visit this site, join the waitlist, write to us, or use PrepDesk as a member of a firm. We decide how this information is used, and this policy applies to it in full.
- Client information we process for firms. The documents and figures a firm gives PrepDesk about its own clients. The firm decides what is collected and why, and is responsible for telling its clients and having their consent where the law requires it. We handle this information only to provide the service to that firm, on its instructions, under our terms and our data processing agreement with the firm.
If you are a client of an accounting firm that uses PrepDesk, please contact your firm first about your information. We will help the firm respond.
3.What we collect#
When you visit this website
This site uses no analytics, advertising or tracking tools, and sets no cookies. Our hosting provider (Vercel, Sydney region) processes technical request details, such as your IP address and browser type, to deliver pages and protect the site.
When you join the waitlist
Your name, work email address and firm name; where on the site you joined, plus any campaign tag in the link you followed (the “source”); the time you joined; and the network prefix of your IP address (only its first part: the /24 for IPv4 or the /48 for IPv6, never the full address), which we use to stop abuse.
When you write to us
Your email address and anything you include in your message.
When you use PrepDesk as part of a firm
- Your name, work email address, firm and role.
- Your sign-in details: your password (stored only as a secure hash) and your authenticator-app setup.
- Sign-in records, with the network prefix of your IP address (the /24 or /48, not the full address), and a record of the edits, decisions, sign-offs and exports you make, which we keep as the firm’s audit record.
- If you are the billing contact, your billing details (see Payments, below).
- If you connect a mailbox or Xero Practice Manager, the connection’s details (see Connected services, below).
Client information, on a firm’s behalf
The documents a firm, or its clients through the firm’s upload links and email address, send to PrepDesk: for example bank and loan statements, invoices, rental statements and income statements. From them we hold the redacted pages, the text and figures read from them, and the workpapers prepared from them. This can include clients’ names, addresses, contact details, property details and financial information. Bank account numbers are kept as their last four digits only, and client contact details are stored encrypted.
4.How we collect it#
- From you directly: when you join the waitlist, write to us, or use the service.
- From your firm: for example, when an admin invites you.
- From documents sent to PrepDesk by a firm or by its clients (through the firm’s upload links or its PrepDesk email address).
- From services a firm chooses to connect: Xero Practice Manager (its client list), and Microsoft 365 or Google mailboxes (the sender of each new email, and details of emails with attachments from the firm’s known client contacts).
- From Stripe, about the status of your firm’s payments.
5.Why we use it#
- Waitlist: to email you about PrepDesk’s launch and founding-firm places, to understand demand, and to stop spam and abuse.
- The service: to provide PrepDesk to your firm, keep it secure, support you, bill your firm, and send service emails (for example security and billing notices).
- Client information: only to provide the service to the firm that gave it to us.
- The law: to meet our legal obligations and respond to lawful requests.
We don’t sell personal information, we don’t use it for advertising, and we never use client documents or figures to train AI models.
6.The waitlist and our emails#
When you join the waitlist, you agree to receive emails from us about PrepDesk’s launch and founding-firm places. We only send you those emails; we don’t share your details with anyone else for their marketing.
Every email we send identifies us and tells you how to unsubscribe. You can unsubscribe at any time using the link or instructions in any email, or by writing to malakye@prepdesk.com.au. We act on unsubscribe requests within five business days.
We keep your waitlist entry until PrepDesk opens to firms generally, and for 12 months after that, then delete it. You can ask us to delete it sooner at any time. If you unsubscribe but don’t ask for deletion, we keep only what we need to make sure we don’t email you again.
Waitlist entries are stored in our database in Sydney.
7.Tax file numbers#
PrepDesk is built not to hold tax file numbers. Each page of a document is first scanned and read into text (by Amazon Textract, in Sydney). Tax file numbers are then found and removed automatically, before the redacted pages are stored and before any text goes to the AI (Claude). If removal can’t run, processing stops.
- Tax file numbers are never stored in our database, logged, exported or sent to the AI (Claude).
- The original upload, which may contain a tax file number, is kept only until its redacted pages are stored, and is then deleted. If a document can’t be processed, its original is deleted 7 days after processing stops.
- Where a tax file number appears in text people type (a note or a reason), it is replaced with “[TFN removed]”.
- When a firm connects Xero Practice Manager, the tax number field in its client records is never stored or used.
Please don’t send us tax file numbers by email.
8.AI and automated decisions#
PrepDesk uses software, including AI models run in Australia, to read the documents a firm uploads, sort them, find the figures in them and prepare draft workpapers.
- The AI model is Claude, made by Anthropic, run on Amazon Bedrock through its Australian profile (Sydney or Melbourne). Only the text of a page is sent, with tax file numbers already removed; page images are not sent.
- The software does not make decisions about anyone. It prepares suggestions. Every figure is shown with the page it came from, and a registered tax agent at the firm reviews, changes or rejects each suggestion and decides what goes into a tax return.
- Tax judgements, such as whether a cost is a repair or an improvement, are always left to a person. Tax rules and arithmetic are done by ordinary code, not AI. Nothing is lodged with the ATO by PrepDesk.
- Anything exported before a person has reviewed and signed it off is marked “DRAFT, NOT REVIEWED”.
- The AI models are never trained on your information or your clients’ information.
9.Connected services#
A firm can choose to connect other services. Each is off until someone at the firm connects it.
- Xero Practice Manager (admins only): we read the practice’s client list (names and contact details) to set up clients in PrepDesk. We read nothing else, and Xero data is never used to train AI.
- Microsoft 365 / Outlook and Google / Gmail: read-only access, used only to bring in attachments from emails the firm chooses. See the next section for how mailbox data is handled.
The access keys for these connections are stored in AWS Secrets Manager in Sydney, never in our database, and are deleted when the connection is removed.
10.Mailbox data, including Google user data#
This section explains how PrepDesk accesses, uses, stores and shares data from a Gmail or Microsoft 365 mailbox that a firm member connects.
What we access
- We ask for read-only access only: Gmail’s gmail.readonly scope, or Microsoft’s Mail.Read. PrepDesk can’t send, change, move or delete email.
- Every 5 minutes, PrepDesk checks the folders or labels you choose for new emails (looking back 14 days the first time). It reads who each new email is from, and whether it has attachments, to find emails from your firm’s known client contacts. It doesn’t read the body.
- For emails with attachments from your firm’s known client contacts, it also reads the subject and the attachments’ names and sizes, so they can be listed for you to choose from. Every other email is skipped without being stored.
- Only when a person at your firm picks an email does PrepDesk download it. It then goes through the same intake as email sent to your firm’s PrepDesk address: the sender and subject are used to match it to a client, and its attachments go through document intake (tax file numbers are removed before any text goes to the AI, Claude). If the email is a client’s reply to one of your firm’s queries, the reply’s text is recorded on that query. Nothing else in the email is used.
How we use it
- Only to provide the feature you connected: bringing in the attachments your firm chooses.
- Not for advertising, not sold, and not used to develop, improve or train AI or machine-learning models, ours or anyone else’s.
- No person at PrepDesk reads your mailbox data, unless you ask us to (for example, for support, through a time-limited access grant your firm approves), it is needed for security (such as investigating abuse), or the law requires it.
Who can see it, and sharing
- A member’s own mailbox is visible only to that member. A shared mailbox can be connected only by a firm admin and is visible to the firm.
- We don’t transfer mailbox data to anyone, except as needed to provide the feature (the chosen attachments are processed by our providers in Australia, as described in this policy), to comply with the law, or as part of a merger or sale of our business with the same protections.
How long we keep it
- Emails listed but not picked are forgotten after 30 days.
- Attachments brought in become the firm’s documents and follow the firm’s retention setting (see How long we keep information).
- When you disconnect, the access keys are deleted and emails not brought in are forgotten. For Google, we also revoke PrepDesk’s access. For Microsoft, remove PrepDesk at myapps.microsoft.com.
11.Where information is stored, and overseas disclosure#
Everything the service holds about firms, their users and their clients is stored and processed in Australia:
| Provider | What it does | Where |
|---|---|---|
| Amazon Web Services | Files, background processing, email, reading documents (OCR), keys and secrets | Sydney |
| Amazon Bedrock (Claude, by Anthropic) | The AI that reads document text | Sydney or Melbourne |
| Neon | The database, including waitlist entries | Sydney (on AWS) |
| Vercel | This website and the web app | Sydney region |
The one exception is billing. Payments are handled by Stripe. Stripe receives your firm’s name, its billing email address, a PrepDesk reference for the firm, the card or bank account details you enter directly with Stripe (PrepDesk never sees full card numbers), your invoices, and the number of workpapers billed. Stripe receives no client information and no documents. Stripe may store and process this information outside Australia, including in the United States.
When a firm connects Xero Practice Manager, Microsoft 365 or Google, PrepDesk reads information the firm already holds with that provider, wherever that provider keeps it. PrepDesk doesn’t send client information to them.
12.How we protect information#
Two-step sign-in for everyone; each firm’s records kept apart in our code and in the database itself; files encrypted with a key for each firm; encryption in transit and at rest; download links that expire within minutes; and an audit record that can be added to but never changed. Our staff can see a firm’s data only through a read-only access grant the firm approves, for at most 72 hours, with every view recorded.
The details are on our Security page.
13.How long we keep information#
- Waitlist: until PrepDesk opens to firms generally, plus 12 months, or sooner if you ask.
- Source documents: for the period each firm chooses, from 90 days to 7 years after sign-off (12 months by default), then permanently deleted.
- Workpapers, their history and user accounts: while the firm is a customer.
- When a firm leaves: its access ends at the end of its paid period. It then has 30 days to export everything. After that, the firm’s data is permanently deleted, backup copies expire within 35 days, and the firm’s admins get an email confirming it.
- After closure: we keep the one-way hashes needed to apply our sign-up rules, and the billing records the law requires us to keep.
14.Data breaches#
We have a written incident plan. If a breach affects a firm’s data, we tell the firm within 72 hours of confirming it, explain what happened, and help it meet its own obligations. We assess and notify eligible data breaches under the Notifiable Data Breaches scheme.
15.Access and correction#
You can ask for access to the personal information we hold about you, or ask us to correct it. Write to malakye@prepdesk.com.au. We may need to confirm who you are. We respond within 30 days, and there is no charge.
If we can’t give you access or make a correction, we’ll tell you why in writing, as the law allows.
If your request is about client information a firm holds in PrepDesk, we’ll pass it to that firm, which decides how to respond, and help it do so.
16.Complaints#
If you think we have mishandled your personal information, write to malakye@prepdesk.com.au and tell us what happened. We’ll acknowledge your complaint within one business day and aim to resolve it within 30 days.
If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
17.Changes to this policy#
We’ll update this page when our practices change and show the date at the top. If a change materially affects how we handle firms’ information, we’ll email firm admins before it takes effect.
18.Contact#
Questions about this policy, a privacy request or a complaint: malakye@prepdesk.com.au.
EasyFlowAI Pty Ltd (ABN 31 686 450 206), trading as PrepDesk. Australia.