The MVP data boundary
The current app processes return data in the browser and downloads the generated packet to the user's device. That keeps the first release away from server-side tax-return storage, which is exactly where the risk would grow fastest.
What an account layer should know
An account layer should know only the minimum metadata needed for sign-in, access records, support routing, and audit trails. It should not store Form 709 payloads, generated PDFs, SSNs, addresses, names, or gift facts.
Why address autocomplete stays local
Third-party address autocomplete can transmit donor or donee address fragments to another provider while a user types. Browser-native autofill and local state dropdowns keep the first workflow simpler and cleaner.
What is outside public preview
Paid access, e-file, professional review, and stored projects all raise the compliance bar. They are not part of the current browser-local public preview.