Legal / Privacy
Privacy Policy
How the Filing Harbor demo at ngallodev-software.uk/filingharbor handles the limited personal data involved in signing in with Google.
Last updated: 7 October 2026
Summary
The Filing Harbor demo is a hosted preview of The Tax Machine, a personal tax workflow. It does not collect tax returns, documents, or filings from visitors. It is a read-only demonstration of the application's interface and access model.
The only personal data the demo receives is the basic profile information Google returns when you sign in: your email address, your display name, and (if present) your avatar image and Google Workspace domain. This information is held in the running process only, for the life of your session, and is discarded when the process restarts.
What we collect
Sign-in identity: when you authenticate with Google, we receive your email address, display name, avatar image URL, and — for Google Workspace accounts — the hosted domain (the hd claim). We use this only to establish your session and to check it against the demo's access allowlist.
Session data: a single session cookie identifies your signed-in session. In production this cookie is set with the __Host- prefix (Secure, path scoped to the site, no Domain attribute) and is not readable by client-side scripts.
Access-control records: the demo keeps a short-lived, in-memory record that your identity was accepted or denied. Denied sign-ins are recorded with a reason code only — no email address, subject identifier, or token is stored with the denial.
What we do not collect
We do not collect tax documents, returns, household data, or any content you might enter into a real tax workflow, because the demo does not expose those features.
The demo application runs no analytics, advertising, or tracking scripts of its own.
We do not sell, rent, or share your personal data with third parties.
How your data is stored and retained
The demo runs in a browser-ephemeral profile. OAuth sign-in state and live sessions are held in bounded process memory, not in a database, and are lost when the process restarts. Session lifetime is bounded by an absolute timeout and an idle timeout.
Identity records are capped at a small number above the session capacity so that switching accounts can stage a new identity. Unreferenced identity records expire automatically. When capacity is reached, the oldest unreferenced record is evicted first; active sessions are never evicted.
Because nothing is written to durable storage, there is no long-term retention of your sign-in identity and no data to export or delete on request beyond ending your session.
Cookies
The demo sets one essential session cookie to keep you signed in. It is required for authentication and is not used for advertising or analytics. Signing out clears your session. You can also clear the cookie through your browser settings, which ends your session immediately.
Third parties
Authentication is provided by Google. When you sign in, Google processes your credentials and returns your basic profile information under its own privacy policy. We encourage you to review Google's privacy policy for how Google handles your account data.
The site is served through Cloudflare, which provides transport security and content delivery and processes standard request metadata (such as IP address and user agent) as a network provider.
Access policy
The demo is restricted to explicitly allowlisted accounts or domains. If your account is not permitted, your sign-in is denied and no personal data is retained beyond the denial reason code.
Your choices
You can sign out at any time, which ends your session and clears the session cookie. Nothing is written to durable storage. The session ends immediately; the associated identity record is retained only briefly in process memory and is removed automatically by a short retention window (and sooner under memory pressure).
You can decline to sign in; the public parts of the site remain available without it.
Changes to this policy
This policy may be updated as the demo changes. Material changes will be reflected in the 'Last updated' date above.
Contact
Questions about this policy can be raised through the contact links on the Work Atlas home page (GitHub or LinkedIn).