The MVP data boundary

The current app processes return data in the browser and downloads the generated packet to the user's device. That keeps the first release away from server-side tax-return storage, which is exactly where the risk would grow fastest.

What an account layer should know

An account layer should know only the minimum metadata needed for sign-in, access records, support routing, and audit trails. It should not store Form 709 payloads, generated PDFs, SSNs, addresses, names, or gift facts.

Why address autocomplete stays local

Third-party address autocomplete can transmit donor or donee address fragments to another provider while a user types. Browser-native autofill and local state dropdowns keep the first workflow simpler and cleaner.

What is outside public preview

Paid access, e-file, professional review, and stored projects all raise the compliance bar. They are not part of the current browser-local public preview.