MVP privacy policy

Privacy policy for early TaxBridge AI validation.

This policy is intentionally practical and conservative. It explains the MVP data boundary while acknowledging that a full legal review is needed before broader commercial launch.

Current status: This is an MVP policy, not a substitute for lawyer-reviewed GDPR documentation. It improves transparency before beta testing and product review.

1. Purpose

This MVP privacy policy explains how TaxBridge AI may collect and use information during early product validation. It is intended for beta-review transparency and should be reviewed by a qualified privacy professional before wider commercial launch.

2. Information we may collect

TaxBridge AI may collect profile information, checker answers, report metadata, beta feedback, waitlist details, document-readiness status, and operational metadata needed for authentication, access control, product validation, and support.

3. Sensitive information boundary

During early beta, users should not upload or paste passports, bank statements, tax certificates, payroll files, private client records, immigration documents, or confidential contracts. Secure document storage is a future roadmap item, not the current public-beta scope.

4. How information is used

Information may be used to generate preparation reports, manage beta feedback, improve product workflows, support adviser handoff, maintain account access, troubleshoot issues, and document MVP validation.

5. Professional-advice boundary

TaxBridge AI provides preparation and information-organization support only. It does not provide final tax, legal, accounting, immigration, or official filing advice.

6. Storage and access

The MVP may use backend database storage and browser session storage for report preview workflows. Admin and private workflows should remain access-controlled. Sensitive document vault features are not enabled in the public MVP.

7. Deletion and export requests

A full deletion/export workflow should be added before wider public onboarding. During MVP validation, users may request removal of submitted beta/waitlist information through the project owner or support channel once provided.

8. Future GDPR upgrades

Future upgrades should include full data-controller details, processor list, retention schedule, lawful-basis mapping, consent logs, cookie policy, deletion/export automation, and secure document-processing terms.