For Australian tax practitioners

Frequently asked questions

Last updated 2 September 2026.

The answers about data and AI are the ones we get asked hardest, so they come first. If something here is unclear or reads as evasive, email support@beforemay.com.au and we will fix the wording.

Two documents sit behind this page and both are public: the Privacy Policy is the authority on who processes your clients' data and where, and the Terms are the contract. Where this page and the Privacy Policy disagree, the Privacy Policy is correct.

23 answers

01

AI and your clients' data

Where does my clients' data actually go?#

Storage and processing are different questions, so here is each step and where it happens.

StepWho does itWhere
Storing documents, figures, case and client recordsSupabaseAustralia
Removing identifiers before anything is sent onwardOur own serviceAustralia (Sydney)
Reading text off a scanned documentOur own serviceAustralia (Sydney)
Building the working paperOur own serviceAustralia (Sydney)
The AI analysis and reviewOverseas AI providers — each one named, with the country it processes in, in the sub-processor tableOverseas

Everything we send for AI processing passes through an Australian redaction step first, where Tax File Numbers, Medicare, passport and licence numbers are found and stripped. A document we cannot check is not sent at all.

Everything we run ourselves is in Australia — storage, identifier removal, recognition, and the container the working paper is actually built in. What leaves is what the AI model reads: the rest of the document, plus a case summary including the taxpayer's name, goes to the AI provider handling that step. That is a cross-border disclosure under APP 8 and the Privacy Policy says so — naming every provider and the country it processes in — rather than rounding it to "your data stays in Australia".

Payments, email and analytics have their own providers and locations, all listed in the sub-processor table.

Is my clients' data used to train AI models?#

No. Our AI providers are contractually prohibited from using it to train general models, and we do not use it to train anything of our own. We also do not sell personal information.

Do you strip out personal information before sending it to the AI?#

Some of it, and we can be exact about which.

Stripped, in Australia, before anything is sent. Tax File Numbers, Medicare numbers, passport numbers and licence numbers. Every document and every instruction passes through an automated redaction step on our own Australian service first, on every path — not just the main one. A document we cannot check is not sent at all.

Not stripped: the taxpayer's name, their address, dates, account numbers and the amounts. Those are the references that make your working paper checkable against the source document. Alter them and the figures stop reconciling with the statement in front of you, which trades a privacy question for an accuracy one — a worse trade for you and for your client.

So the honest summary is: the identifiers with their own legislation attached are removed; the accounting substance is not.

What contains the rest of the exposure:

  • Purpose. Information is sent only to prepare and review that client's own working paper. Nothing is pooled across clients or firms.
  • No training. Our providers are contractually prohibited from using it to train general AI models, and we don't train anything on it either.
  • No profile kept. We don't store TFNs as a field, and we don't build a profile of a taxpayer out of what the AI reads.
  • Named providers. Every processor is listed with its location in the Privacy Policy, so a client's question has a specific answer rather than a reassuring one.

One word we still avoid: de-identified. Stripping identifiers is not de-identification. Because the name and address remain, what we send is still personal information under the Privacy Act 1988 (Cth), and APP 8 applies in full. Partial masking is sometimes marketed as de-identification; if you repeat that word to a client, it should be one that holds up.

My clients' documents contain TFNs. What happens to them?#

They are removed before the document leaves Australia. A payment summary or ATO notice that prints a TFN goes through our Australian redaction service first; the number is detected and stripped, and the document continues on without it.

A TFN is also never stored as a field, never indexed, and never used as a key. Where one is detected we keep only a note that it was present, and route the document for human review.

Your own copy of the document is untouched — the removal applies to what we send onward, not to what your firm holds. Please don't type TFNs into free-text notes, where they would be stored as text rather than sitting in a document the redaction step reads.

The one exception is a page we cannot read. To remove an identifier we have to know where it is, and on a scan the only way to know is to read it — so a page our own recognition cannot read is sent to be read, one page at a time, with no surrounding case information.

TPB(GS) 55/2026 notes at paragraph 26 that where client information involves TFNs, additional obligations under the Privacy (Tax File Number) Rule 2015 apply to you.

What does TPB(GS) 55/2026 mean for me?#

The Tax Practitioners Board issued TPB(GS) 55/2026 on 22 July 2026. Two parts of it bear on using any AI tool, including ours.

You need your client's permission. Code item 6 says you must not disclose information relating to a client's affairs to a third party without the client's permission unless you have a legal duty to. The guidance treats any entity other than you and your client as a third party, and says that entering client information into AI tools can be such a disclosure, "depending on how these tools are configured and used" (para 23). We are a third party, and on our configuration your clients' information is disclosed to us and our sub-processors.

Your review is your own. You remain responsible for the accuracy of the work, must apply your own professional judgement, and must not treat AI output as a substitute for your own analysis.

Isn't this your obligation, not mine?#

The permission sits between you and your client. We are not a party to that engagement and cannot obtain consent on your behalf. What we can do — and what this page is — is state accurately what happens to the data, so that what you tell your client is right.

We ask an authorised person at your firm to confirm they have read this once, during setup. Not per client.

Can I get evidence that I reviewed the AI's work?#

Yes, and this is the part most firms underestimate.

Paragraph 16 of the guidance says you should verify and review AI-generated content throughout the workflow, and that each of these steps should be documented to support ss 30 and 40 of the Tax Agent Services (Code of Professional Conduct) Determination 2024 — record-keeping, and a documented system of quality management.

The platform keeps that record as a by-product of how the work gets done:

  • every point the AI raised, and what you did with each one
  • who changed what, and when, actor-stamped
  • every version of the working paper, with restore
  • the reasoning behind each flagged item, so you can contest it

The review is still yours to perform. What you don't have to do is assemble the evidence that you performed it.

Why not keep everything in Australia?#

Almost all of it now is.

Storage, identifier removal, text recognition and building the working paper all run on our own infrastructure in Sydney. They used to run offshore; they were moved deliberately, and the sub-processor table is the record of it rather than a promise.

The one step that still crosses the border is the AI model itself. The working paper is built inside our own Sydney container; what that container sends out is the model call — the redacted document text the model reads and the answers it writes back — to whichever provider handles that step, in the country the Privacy Policy names for it.

Running the model in an Australian region is possible for some providers and costs materially more per working paper, so we do not do it today. If onshore-only processing is a hard requirement for your practice, tell us — we track that, and enough of it changes the decision.

Where can I read the detail?#

The Privacy Policy is the authority. Section 5 covers AI processing and the human-review boundary, section 6 lists every sub-processor with its location, section 7 covers cross-border disclosure, and section 12 is written specifically for registered tax practitioners.

02

The working paper

Do you lodge to the ATO?#

No. We prepare the working paper; you review every figure and lodge through your existing software. Nothing is sent to the ATO automatically, ever.

What do I actually get?#

A real .xlsx workbook with live formulas — not a PDF, not a locked file, not a macro-enabled workbook. File it in your document management like any working paper you'd prepare by hand.

Why not just do this in ChatGPT or Copilot?#

You can get a general AI assistant to talk about a return. Four things it will not do, and each of them is the part that takes the time.

  • Read the client's actual paperwork. Not a pasted excerpt — the whole bank statement, the photographed receipts, the trial balance. Recognition runs before analysis, so a scan is read rather than described.
  • Tie every figure to where it came from. Each number in the workbook traces back to the page of the source document it was read off, so a bad read is visible in one click instead of argued about.
  • Check itself before it hands you the file. The build runs its own validation and a blind review pass before you see the workbook, and what it cannot fix it flags rather than shipping quietly. A chat window has no notion of failing.
  • Leave the record. The evidence that you reviewed it is assembled as a by-product of the work. A chat transcript is not that record.

There is also the part that is yours either way: whatever you paste into ChatGPT or Copilot, you have made that cross-border disclosure yourself, to whichever provider sits behind it. Here, identifiers are stripped in Australia first and every provider is named with the country it processes in.

What happens when the AI gets something wrong?#

It gets flagged, not lodged. Low-confidence extractions go to Needs review and are never auto-approved. Every figure traces back to its source document, so a bad read is visible in one click. You sign off before anything leaves the platform.

Can it handle company and trust returns?#

They are available by invitation while we work on them, and we say so rather than burying it in fine print. Individual and sole-trader returns are where the output is strongest today; company and trust working papers are earlier and need more of your review. If you want access, ask.

Which documents can I upload?#

Receipts, invoices, bank and brokerage statements, trial balances and general ledgers, as PDF or image, up to 25MB each. Scanned documents are read by our recognition pipeline before analysis.

Does it work with my existing templates?#

The workbook is ours today. Firm-template output is on the roadmap, not shipped. If your practice has a house template you cannot deviate from, tell us before you sign up rather than after.

03

Security and access

Who at BeforeMay can see my clients' files?#

Nobody browses them. Documents are isolated per firm by database row-level security keyed to firm membership, storage is private with short-lived signed URLs issued only after we verify membership, and access is logged. Support access to diagnose a problem happens with your knowledge.

What about the client portal?#

A portal invitation is bound to one email address and has to be explicitly accepted — visiting a link is not consent, and there is no anonymous upload path. Clients upload from their own signed-in account.

Is there two-factor authentication?#

Yes, and we recommend turning it on during setup.

04

Pricing and commitment

What does it cost?#

Pricing is on the home page. You get free cases to judge the output on your own files before paying anything.

Am I locked in?#

No lock-in contract. Your data is yours; the deliverable is a standard Excel file you already have a copy of.

05

Where these rules come from

Every rule named on this page, linked to its primary source. Read them yourself rather than taking our summary for it — and if you think we have characterised one wrongly, tell us and we will correct the page.

The TPB guidance on AITPB(GS) 55/2026, The use of Artificial Intelligence and the Code of Professional Conduct, issued 22 July 2026. The paragraphs referred to above are 6, 9, 16, 21, 23, 24, 25 and 26.

Offshore processingTPB(GS) 31/2018, Outsourcing and offshoring of tax services. This is the guidance that deals with sending client information overseas. TPB(GS) 55/2026 does not address it at all, so anyone citing the AI guidance at you on an offshore question has the wrong document. If you knew this one as TPB(PN) 2/2018, that is the same guidance under its former name — the TPB renamed its Practice Notes to Guidance Statements on 30 April 2026 and archived the old number.

Privacy

Your own obligationsTax Agent Services (Code of Professional Conduct) Determination 2024, s 30 (records of the tax agent services you provide) and s 40 (a documented system of quality management).

06

Free calculators

The same rate book that fills a working paper also drives a few free tools, with no sign-up and nothing stored:

  • Work from home deduction — hours at the ATO fixed rate, and what that rate already covers.
  • Cents per km — the car deduction, and the 5,000 km cap that decides when a logbook is worth more.
  • HELP / HECS repayment — including the marginal system that replaced a flat rate on the whole income from FY2025-26.

Each publishes a page per financial year, because the rates move and a figure from the wrong year is just a wrong figure.

07

Still have a question?

support@beforemay.com.au — a person reads it.

If your question is one another firm would ask, we will add it here.