Our promise
- Your clients’ documents and data are stored and processed only in Australia.
- We automatically remove tax file numbers and never store them.
- No other firm can ever see your data, and our own staff can see it only when you approve, for a set time, with a record kept.
- Your data is never used to train AI models.
- You choose how long source documents are kept, and deleted means permanently deleted.
- If something goes wrong, we tell you quickly and help you meet your own obligations.
Where is my data?#
In Australia. Documents, workpapers and every record are stored in Sydney: files and background processing on Amazon Web Services (ap-southeast-2), the database on Neon in Sydney, and the web app on Vercel’s Sydney region.
The AI that reads documents runs in Australia too, in Sydney or Melbourne. Nothing about your clients is processed overseas.
What about tax file numbers?#
Each page is first scanned and read into text (by Amazon Textract, in Sydney). Tax file numbers are then found and removed automatically, before the redacted pages are stored and before any text goes to the AI (Claude). If removal can’t run, processing stops. We never store, log or export them. Your tax software already has them; we don’t need them.
The original upload is deleted as soon as its redacted pages are stored. Tax file numbers typed into a note are replaced with “[TFN removed]”, and the tax number field in Xero Practice Manager is never stored or used.
Can anyone else see my clients?#
No. Every firm’s data is walled off twice: in our code, and in the database itself, which refuses to return another firm’s rows. Files are encrypted with a key tied to your firm.
Our team can look at your data only if an admin at your firm grants access for a specific reason and time: read only, for at most 72 hours. Every view is recorded and shown to your firm.
Inside your firm, only admins manage billing, members, retention and support access. A mailbox a member connects is visible only to them.
Is my data used to train AI?#
No. Your documents and figures are never used to train AI models, and neither is data from Xero or a connected mailbox.
PrepDesk uses Claude, by Anthropic, on Amazon Bedrock through its Australian profile. Our code refuses any model that isn’t on that Australian list. Only the text of a page is sent, with tax file numbers already removed; page images are not sent. Document text is treated as data, never as instructions, and the AI’s answers must match a fixed structure before they’re used.
Tax rules and arithmetic are ordinary code, not AI, and every figure records the model and prompt version that produced it.
Who is responsible for the return?#
You are. We prepare workpapers for your review; every figure is a suggestion until a person reviews it. Your registered tax agent reviews, decides and lodges. PrepDesk doesn’t give tax advice, and client emails never do. Anything exported without review is clearly marked “DRAFT, NOT REVIEWED”.
How long do you keep documents?#
You decide: from 90 days to 7 years after sign-off (12 months by default). Then they’re permanently deleted. The original upload is deleted as soon as its redacted pages are stored, and files quarantined by the malware scan expire after 30 days.
If you leave, you get 30 days to export everything. Then we delete it all, backup copies expire within 35 days, and we confirm it in writing.
How do you protect logins?#
- Two-step verification with an authenticator app for everyone, with no exceptions. We don’t offer text-message or email codes, or “trust this device”.
- Automatic sign-out after 30 minutes of inactivity, and after 12 hours at most.
- Download links that expire within minutes. Client upload links are limited to their own request, and query reply links work once.
- Rate limits on sign-in, uploads, client links and every other action.
What happens to uploaded files?#
Every file is checked by its content, not its name (PDF, JPEG, PNG and TIFF, up to 50 MB) and scanned for malware before anything reads it. PrepDesk never follows links or fetches web addresses found in documents or emails.
What’s on the record?#
Every edit, decision, sign-off and export goes into an audit trail that can’t be changed afterwards, with who did it, when, and the reason they gave. Entries can be added, never edited or removed. Our application logs hold IDs, never document content.
What if something goes wrong?#
We have a written incident plan. If your data is affected, we tell you within 72 hours of confirming it, explain what happened, and help you meet your own obligations, including under the Notifiable Data Breaches scheme.
Providers that touch data#
Every provider that touches data: what it does, what it sees, and where.
| Provider | What it does | Data it sees | Where |
|---|---|---|---|
| Amazon Web Services | Files, background processing, email, reading documents (OCR), keys, secrets | Client documents and figures | Sydney |
| Anthropic (through Amazon Bedrock) | Claude models | Document text only, tax file numbers removed first; processed within AWS in Australia | Sydney or Melbourne |
| Neon | Database | All records | Sydney (on AWS) |
| Vercel | The web app and this website | Screens and requests in transit | Sydney region |
| Stripe | Subscriptions and payments | Firm name, billing contact, payment details; no client data | Outside Australia |
| Microsoft | Outlook mailbox connection (only if your firm connects one) | PrepDesk reads who sent each new email and whether it has attachments; the subject and attachment names only for emails with attachments from known client contacts; the whole email only when a person picks it | Your mailbox’s own hosting |
| Gmail mailbox connection (only if your firm connects one) | PrepDesk reads who sent each new email and whether it has attachments; the subject and attachment names only for emails with attachments from known client contacts; the whole email only when a person picks it | Your mailbox’s own hosting | |
| Xero | Xero Practice Manager client list (only if your firm connects it) | Client names and contacts your firm already holds in Xero | Xero’s own hosting |
Mailbox and Xero connections are read-only and are off until someone at your firm connects them. PrepDesk reads from those services; it doesn’t send your clients’ information to them.
What we don’t claim#
PrepDesk doesn’t hold security certifications such as ISO 27001 or SOC 2 yet, and we won’t show a badge we haven’t earned. If you need more detail for your own due diligence, write to us and a person will answer.
Contact#
Questions about your clients’ data, a privacy request or a complaint? Write to us at malakye@prepdesk.com.au.
Found a security problem? Please email us the details and give us a chance to fix it before telling anyone else. Don’t access, change or delete data that isn’t yours while testing.
How we handle personal information is in our Privacy policy.