Privacy Policy

Effective date: 26 June 2026 Last updated: 2 September 2026 — adds what this policy never said about cookies and analytics. Three things run in your browser when you use BeforeMay — PostHog, Google Ads conversion tracking, and our host's page-view and page-load measurement — and section 2 now lists each one, what it is given, and that none of them is given a client document. Section 6 adds the Google Ads row that was missing from the sub-processor table. Nothing about how documents are handled has changed.

Previously, 10 August 2026 — corrected what we said about Tax File Numbers. The version before it said we did not store them. We do: your accountant needs your TFN to prepare and lodge your return, and section 2 says so plainly, along with the only two things we use it for and where it is no longer kept. That version also closed the last exception in section 7 — an unreadable page is no longer sent overseas to be read; it goes to a person here instead.

Previously, 9 August 2026 — named the Australian redaction service that sees every document; stated plainly that stripping identifiers is not de-identification; added what happens to copies our providers hold, what we do in a data breach, and how we respond to overseas legal process. Also retired Google Cloud Vision, so text recognition became entirely our own service, and added section 13 for registered tax practitioners on TPB(GS) 55/2026.

Previously, 7 August 2026 — Tax File Numbers, Medicare, passport and licence numbers are stripped before anything leaves Australia; states the one exception (recognising a page we cannot read) rather than implying there is none.

This policy explains how Outblock Pty Ltd (ABN 94 655 314 051) ("we", "us", "our") handles personal information in BeforeMay — a platform that helps Australian accounting firms know whether a client's tax documents are ready, classify uploaded documents with AI, and generate and review tax working papers. We handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

We provide the platform to accounting firms (our customers). For the personal information a firm and its clients put into the platform, the firm decides how that information is used — we process it on the firm's behalf under our agreement with them. If you are a client of a firm, contact that firm first about your information; we will support them in responding to you.

Questions or requests: privacy@beforemay.com.au.


1. Whose information we handle

2. What information we collect

Account & identity — name, email, phone number (where used for one-time passcodes), firm membership and role, and login/authentication metadata (including Apple or Google sign-in identifiers where used).

Documents & financial information — the files clients upload (receipts, statements, invoices and similar tax/accounting records) and the information AI or staff extract from them: merchant, date, amount, GST, category, document type, risk flags, and checklist matches. This can include sensitive financial information.

Tax File Numbers, Medicare numbers, passport and licence numbers. These are removed before anything leaves Australia. Every document and every instruction we send for AI processing passes through an automated redaction step first: the identifier is detected and stripped, and the document continues on without it. A page we cannot read well enough to check is not sent for AI processing at all — the step stops rather than guesses.

We do hold your Tax File Number, and this is what for. An earlier version of this policy said we did not store it. That was wrong, and correcting it is the main reason for this update. Your accountant needs your TFN to do the job you engaged them for, so we keep it against your client record for exactly two purposes:

  1. so your accountant can see, check and correct it while preparing your return — it also appears on the working paper they prepare and review; and
  2. so your return can be lodged. The ATO rejects a lodgement whose client details do not match its own record, so the number has to be right and has to be to hand. Today your accountant lodges from their own ATO-connected software; if we add lodgement to BeforeMay we will send your TFN to the ATO for that purpose and nothing else, and we will say so here first.

That is the whole list. We do not use your TFN to link you across firms, we do not use it for analytics or product measurement, we do not sell or disclose it, and — as above — it is never sent overseas. On screen it is hidden behind a click rather than shown by default.

Where it is no longer kept. Until 10 August 2026 a copy also sat in two places that had no use for it: the text our recognition service reads off a document, and the structured fields our AI extracts. Neither was ever read. Both have been cleared for existing documents and neither is written any more — where a TFN appeared in recognised text you will now see [TFN removed], and the extraction keeps only a note that one was present.

Your accountant's own copy of the source document is untouched — the removal applies to what we send onward and to what we index, not to the file they hold. That file is the record they are required to keep and the thing they check their work against.

What we take out before anything is sent for AI processing.

  • Removed entirely — Tax File Numbers, Medicare numbers, passport numbers and driver licence numbers. These do not leave Australia by any route.
  • Replaced with a code — bank account numbers and BSBs. The AI is told Account 1 and BSB 2, never the digits. Nothing in a working paper is calculated from them; all that matters is telling one account from another, and a code does that without the number ever being sent.
  • Replaced with a stand-in — email addresses and phone numbers, swapped for realistic substitutes of the same kind.
  • Sent as it appears — everything else, including the taxpayer's name, address, date of birth, ABN, employer, balances and transaction detail. The working paper has to tie back to the source document the accountant checks it against.

The document itself is sent as well as the text we extract from it, and only the first group above is taken out of the document. Building a working paper means reading the actual statement.

A page we cannot read well enough to check is not sent at all — the step stops rather than guesses.

Your accountant's own copy is untouched. All of this applies to what we send onward, not to the file they hold: that file is the record they are required to keep.

This is redaction. It is not de-identification, and we will not call it that. The list above says what is sent as well as what is not, so that you can see how far it goes rather than take a word for it. The substitutions are reversible by us, which is what makes them stand-ins rather than anonymisation. Everything we handle therefore remains personal information under the Privacy Act 1988 (Cth), and APP 8 applies to it in full. If you ever see us describe our processing as anonymised, de-identified or privacy-preserving, that description is wrong — tell us at privacy@beforemay.com.au and we will correct it.

Billing — invoice records and payment status. Card payments are taken through Stripe via the firm's own payment link; we do not receive or store full card numbers.

Communications — email "chase" content generated for a firm to send to its clients, email drafts and send logs, and inbound email we receive on a firm's behalf.

Technical & audit — IP address and request metadata used for rate limiting and security, and an audit trail of security-relevant actions (portal token use, document reads, signed-URL issuance, checklist updates, invoice reads, and contact confirmations).

Cookies & analytics — three things run in your browser when you use BeforeMay, and this is what each one is given:

Before any of the three is told which page you are on, the address is cut back to its route: a portal or signing link, a document id or a search term never reaches them. None of them is given a client document or anything read from one. The Privacy Act 1988 (Cth) asks us to tell you this here; it does not ask for a consent banner, and we do not show one. Blocking any of the three in your browser does not affect your use of the platform.

We collect this information directly from firm users and from clients/portal visitors who provide it, and we generate derived information (the AI extractions above) from the documents provided.

3. How we use it

We use personal information to:

We do not sell personal information, and we do not use clients' documents or extracted financial data to train our own or any third party's general AI models.

4. Multi-tenant isolation

Every firm's data is scoped to that firm. Accountant data is protected by database row-level security keyed to firm membership; client portal access is limited to a single firm and client through a bearer token stored only as a hash and validated on every request. One firm cannot read another firm's data, and a portal visitor can only reach their own files and invoices.

5. AI processing and the human-review boundary

Uploaded documents are analysed server-side by an overseas AI provider — one of those named in the sub-processor table in section 6 — to suggest the merchant, date, amount, GST, category, risk flags, TFN presence, and checklist match. For a single document, what is sent is the file's bytes (for supported types), filename, MIME type, and candidate checklist labels.

Two other steps send more, and both are covered by that same table. Text recognition runs first on our own service in Sydney — no third party reads a page for us. When a working paper is built or a whole case is analysed, the original source files and a summary of the case — including the taxpayer's name and the recognised text of their documents — are provided to the AI provider handling that step. The working paper is then reviewed by a second provider, different from the one that drafted it, before we hand it back — a draft and its reviewer should not share the same blind spots.

Which provider handles which step is a configuration decision, not something fixed in this document. Section 6 names every provider we may use and the country each processes in; section 7 says how we tell you which applies to your firm.

Before any of that, the document passes through our own identifier-removal service, hosted in Sydney (section 6). That step is mandatory and it fails closed: if the service cannot be reached, or cannot read a page well enough to check it, the document is not sent onward and the job stops with an error. We do not fall back to sending the original.

AI output is a pre-review aid only. The final category, GST treatment, checklist match, working-paper figures, and lodgement readiness remain the accountant's responsibility. We do not treat AI output as a decision and do not auto-approve when analysis fails — those documents are flagged for human review.

6. Who we share it with (sub-processors)

We use a small set of service providers to run the platform. Each acts on our instructions and is bound by confidentiality and data-protection terms:

<!-- ONE CLAUSE PER PURPOSE, and the reason is the one #305 gave for cutting the three-column table out of section 7: a privacy policy tells someone what happens to their information, and APP 5 asks for the countries, not the pipeline. This table had grown the same way and was not reached by that trim — the Fly.io row restated section 7's redaction promise in full, and the Fireworks and DeepSeek rows each restated its "same openly published model" paragraph. Every one of those sentences still exists, once, in section 7, which is the section that owns them. THE COST OF THE DUPLICATE IS NOT LENGTH. Section 7 had gone stale in exactly this way before — it described a stand-in scheme that had been replaced by codes a day earlier — because a fact written twice is a fact that gets updated once. A cell here that promises something is a second place to forget. IT IS NOT ABOUT KEEPING THE STACK SECRET. Supabase, Vercel, Stripe, Resend and PostHog are the default answers to their questions and give a competitor nothing; Fly.io in Sydney is a thing we actively want known. The commercial core is skills/ — the packs, the cell maps, the delivery gates — and no provider list gets anyone closer to it. Naming providers is a sales asset: a registered tax agent has to tell their own client which countries are involved, and this table is what they rely on. WHAT MUST NOT BE TRIMMED is a purpose that appears nowhere else. PostHog's row lists the fields that actually reach an EU processor, and that list lives only here. Cut a duplicate; never cut the only copy. -->
ProviderPurposeWhere processed
SupabaseDatabase, file storage, authenticationAustralia
Fly.ioOur own services: identifier removal, text recognition, and building the working paperAustralia (Sydney)
Anthropic (Claude)Server-side AI document analysis and working-paper assistanceUnited States
Fireworks AIServer-side AI analysis of document text and building the working paperUnited States
DeepSeekServer-side AI analysis of document text and building the working paperChina
ZAI (Z.AI / Zhipu AI)Server-side AI analysis of document text and building the working paperChina
PostHogProduct analytics and error reporting for the app itself — your user id and email address, your firm's id and name, the pages you visit, and the text of any error the app hits. Never client documents or their contentsEuropean Union
StripeCard payment processing via firm payment linksAustralia / United States
ResendSending and provisioning firm emailUnited States
Google (Sign-In / Drive drive.file)Optional sign-in and per-file Drive access the user grantsUnited States
Google AdsConversion tracking on the website and app — the page you are on and Google's own click id, nothing else (section 2)United States
VercelApplication hosting and delivery, and anonymous page-view counts and page-load timing (section 2)United States / global edge

We share information with these providers only as needed to deliver the service, and otherwise disclose personal information only where you or the firm direct us, or where we are required or authorised by law.

7. Cross-border disclosure (APP 8)

Documents and account data are stored at rest in Australia, and everything we run ourselves — identifier removal, text recognition, and building the working paper — runs in Australia too.

The AI steps in preparing a working paper leave the country, for the purposes set out in the table above, to the AI providers named there and in the countries recorded beside them. Other sub-processors (including Stripe, Resend, Google, Vercel and PostHog) also process information overseas, in the United States and the European Union.

Several of those providers run openly published models on their own computers, and which of them applies to your firm is a decision we make per firm. Fireworks AI and DeepSeek each host the same model themselves, and Z.AI hosts its own; the table above records the country each one processes in. We do not treat one overseas country as inherently safer than another — every provider in that table is bound by the same confidentiality and data-protection terms, and every one of them is subject to the same rule below about identifiers. We tell a firm which providers handle its documents, and we tell it before that changes; ask at any time and we will confirm it in writing.

We name the countries rather than saying "overseas", so that a firm can tell its own clients which countries are involved and not just that some are. Our obligations to you are the same wherever information goes: we remain accountable for how an overseas recipient handles it.

Tax File Numbers, Medicare numbers, passport and licence numbers do not leave Australia. Everything we send for AI processing — documents and instructions alike — passes through an automated redaction step first, and a document we cannot check is not sent. This applies to every path, not only the main one.

Bank details, email addresses and phone numbers are handled differently, and are not on that list. Section 2 sets out what happens to each: the AI is given a code rather than an account number or BSB, and a substitute rather than a real email address or phone number — but the source document is sent as well, and those are not taken out of it.

The one exception used to be recognition. It is closed. To remove an identifier from a page we have to know where it is, and on a scanned page the only way to know is to read it — so a page our own Australian recognition could not read was sent to Anthropic as an image to be read. Since 10 August 2026 it is not. A document we cannot read here goes to a person here: we tell your accountant it needs manual review rather than sending the page overseas.

We are describing this rather than deleting the paragraph, for the reason the paragraph itself gave when the step still existed: a policy that quietly stops mentioning where an unreadable page goes reads as though it never went anywhere. It did. Now it doesn't.

What we found when we closed it is worth telling you, because it changes what the old wording was worth. That step was written to fire when a page could not be read — but in practice it fired whenever our recognition service failed to answer for any reason, including being briefly unavailable. It had never actually fired: across every document then held, not one had taken that path. So nothing was disclosed through it, and it would have applied to far more than unreadable pages the first time that service had an outage. We closed it before that happened.

Overseas legal process. Some of these providers are subject to the laws of the countries they operate in, including laws that can compel disclosure to a foreign government or law-enforcement agency. Contractual protections do not override that, and no provider can promise otherwise. We do not volunteer client information to any authority. Where we receive a request ourselves we require valid legal process, disclose no more than that process requires, and tell the affected firm unless we are prohibited from doing so.

We take reasonable steps to ensure these providers handle information consistently with the APPs, including through written data-protection terms and a contractual prohibition on using client information to train general AI models.

What we do not rely on. Your use of the platform is not, by itself, the consent a firm needs from its own clients. A registered tax practitioner has an obligation to their client to obtain permission before client information is disclosed to a third party — and for that purpose, we are the third party. That permission sits between the firm and its client; we are not a party to it and cannot obtain it on the firm's behalf. What we can do, and what this section is for, is describe accurately what the firm is asking permission for.

8. How long we keep it

We keep information for as long as the relevant firm's account or client is active, then under the rules below. A daily job enforces the automated items.

DataRetention
Uploaded documents & extracted fieldsWhile the client/job is active, plus the firm's retention policy; deleted on firm-admin deletion or account closure
Tax File Number (on the client record)While your accountant needs it to prepare and lodge for you — see section 2. Deleted with the client record, and you can ask them to clear it at any time
Email drafts / send logs7 years unless the firm chooses a shorter pilot retention
Portal tokensUntil their expiry date, or immediately on revoke / client request
Firm invites7 days active; accept/revoke audit metadata kept up to 1 year
Audit eventsAt least 1 year (automated purge after 18 months)
Rate-limit events7 days
Account / member recordsWhile the user belongs to the firm

Some financial records may be retained longer where law or a firm's professional obligations require it.

Copies held by our providers. The table above describes our own systems. To do the work they are engaged for, some providers necessarily hold a copy for a period — most significantly, a document sent for AI analysis is stored by that provider so the analysis can run against it. Those copies are held under our written agreement with the provider, are not used for any other purpose, and are not used to train general AI models. Deleting a firm's data from our systems does not by itself delete a provider's copy; provider-side deletion follows that provider's own retention terms. We are working to shorten this by deleting each uploaded file as soon as the job that needed it finishes, and will update this section when that is in place rather than before.

9. Security

The receipts storage bucket is private; we store object paths, not links, and issue short-lived signed URLs only after verifying firm membership or a valid portal token. Provider secrets and privileged keys live only server-side, never in the browser. Every privileged server function verifies the caller before acting, and security-relevant actions are logged. No system is perfectly secure, but we take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access.

10. If something goes wrong (data breaches)

If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information held in the platform, we will:

The Notifiable Data Breaches scheme applies to us in respect of Tax File Number information regardless of our size, and we apply the same process to all client data rather than run two standards.

Where a breach occurs at one of our providers, we will pass on what that provider tells us. Report a suspected security or privacy incident to privacy@beforemay.com.au.

11. Your rights

Under the APPs you may ask to access or correct your personal information, or raise a privacy complaint.

We will acknowledge a request or complaint within 7 days and respond substantively within 30 days. If you are not satisfied with how we handle a complaint, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12. Children

The platform is a professional tool for accounting firms and is not directed to children. We do not knowingly collect children's information except where it appears within a firm's tax records, in which case it is handled as the firm's client data.

13. If you are a registered tax practitioner

This section is for our customers, not their clients. It is information, not legal advice — get your own.

The Tax Practitioners Board issued TPB(GS) 55/2026, The use of Artificial Intelligence and the Code of Professional Conduct, on 22 July 2026. Two points in it bear directly on using this platform.

Client permission. Code item 6 says that unless you have a legal duty to do so, you must not disclose information relating to a client's affairs to a third party without the client's permission. The guidance treats any entity other than you and your client as a third party, and says that entering client information into AI models and tools can be such a disclosure, "depending on how these tools are configured and used" (para 23). We are a third party. Sections 2 and 5 to 7 describe our configuration exactly — what is stripped before anything leaves Australia, what is not, and the one case where a page does leave to be read. You need your client's permission before you put their information into this platform.

The guidance lists the forms that permission can take (para 24): a signed letter of engagement, a signed consent, another communication such as a relevant "fact find" and consent, or a general authority consenting to disclosure to third parties. Many standard engagement letters already contain such an authority. It also recommends — as good practice rather than a requirement — that you tell the client to whom and where the disclosure will be made, where data will be stored, and whether AI tools may be used. Sections 6 and 7 are written so you can answer those four questions, and we publish a clause you may adapt for your own engagement letters.

Where the information includes a TFN, the guidance notes at paragraph 26 that additional obligations under the Privacy (Tax File Number) Rule 2015 apply. We strip TFNs before a document leaves the country (section 2), but that reduces the exposure — it does not move the obligation off you.

Your review is your own. The guidance is explicit that you remain responsible for the accuracy of the work, must apply your own professional judgement, and must not treat AI output as a substitute for your own analysis. It also says the steps you take to verify and review AI-generated content should be documented, to support ss 30 and 40 of the Tax Agent Services (Code of Professional Conduct) Determination 2024. The platform records the AI's findings, your responses to them, who changed what and when, and each version of the working paper, and that record is exportable — but the review itself is yours.

14. Changes

We may update this policy. We will change the effective date above and, for material changes, notify firms through the platform or by email.

Changes to the sub-processor list in section 6 are material changes. Adding a provider that will handle client data, or moving one to a different country, is notified to firms before it takes effect, so a firm has the chance to review it against what it has told its own clients.


Outblock Pty Ltd · ABN 94 655 314 051 · Oatley NSW 2223, Australia · privacy@beforemay.com.au