Legal

Privacy policy

FileDesk is software for tax agencies, published by Muhammad Ahsan. This policy covers two separate things: what happens when you visit this website, and what happens to data inside the FileDesk software once an agency is using it. They are governed differently and it matters which one you mean.

1. This website

This site sets no cookies, loads no third-party scripts, and runs no analytics or advertising trackers. Nothing about your visit is profiled or shared.

The only information collected is what you type into the contact form: your name, email, and optionally phone number, city, agency name, branch count, expected client records and your message. It is kept in FileDesk's own administration area and used solely to reply to you and discuss whether the software fits your practice. It is never sold, never added to a marketing list, and never passed to a third party.

Like any website, basic details of each visit (IP address, time and page requested) may be recorded for a short time, for security and to prevent abuse.

To have an enquiry deleted, email mahsan7861100@gmail.com and it will be removed.

2. The FileDesk software

When an agency uses FileDesk, the agency is the data controller for everything it enters — its clients' identities, contacts, cases, returns, financial records, documents and portal credentials. The agency decides what to collect, who may see it, and how long to keep it. Muhammad Ahsan provides and maintains the software and the service it runs on, and does not use agency or client data for any other purpose.

2.1 Client portal credentials

FileDesk stores tax-portal usernames, passwords and PINs on behalf of an agency's clients — a digital wallet for credentials the agency already holds. Every person signing in confirms that the agency has obtained each client's permission to store their portal credentials in a digital wallet for the purpose of filing on their behalf, including on branch devices where the extension is installed.

Credentials are encrypted (AES-256) before they are saved, with the username, password and PIN each locked under its own key. They are never written to FileDesk's logs and never included in the automatic update messages FileDesk sends between devices. When a credential changes, an approved extension is told only that something changed; it then fetches the credential itself, signed in and over an encrypted (HTTPS) connection. Inside the extension, credentials are encrypted again under a key that belongs to that installation and cannot be copied out of it, and they are decrypted only when the user asks FileDesk to fill a supported login form.

2.2 What else the software stores

  • Client identity: name, CNIC, NTN, filer status, contacts and notes.
  • Work records: cases, returns and a financial ledger that cannot be edited.
  • Sign-in records: which devices are signed in, registered extension installations and licences.
  • Client documents uploaded by agency staff — scans, PDFs and photos — with the title, category and tax year staff give them (section 2.3).
  • A wealth-statement register: a client's assets and liabilities, with dated events such as purchases, sales, gifts, inheritances and loans, their amounts, and optional references (for example a plot or account number), counterparties and notes. Amounts follow the same amount-visibility permission as the ledger.
  • A staff activity log (section 2.5).

2.3 Client documents

Client documents are part of the FileDesk web app only. Staff scan a paper document with the device camera or upload a PDF or photo. Scanning — finding the page edges, straightening, clean-up filters and putting pages together into a PDF — happens entirely on the user's own device. Every person signing in confirms that the agency has each client's authority to store the documents it uploads for them.

  • Encrypted before it leaves the device. Each file, and the small preview picture made from it, is encrypted on the user's device (AES-256) under a key that belongs to that one document. Only the encrypted file is uploaded.
  • Stored encrypted with Cloudflare. Encrypted files are stored with Cloudflare, our storage provider, which cannot read them. They travel directly between the user's device and Cloudflare under random names; document titles, categories and client details stay in FileDesk's own records.
  • Keys held by FileDesk, never by Cloudflare. FileDesk keeps each document's key locked under its own master key and gives it only to signed-in agency staff whose account may view documents, when they open one; every opening is recorded in the activity log. Preview pictures in the document list can be seen by staff who may view documents and are not logged one by one, and the person uploading a document receives its key so that their device can encrypt it. Because FileDesk can unlock these keys, this is not end-to-end encryption: the protection is that the storage provider never holds a key and that every key is released only after a permission check.
  • Never sent to AI. Scans and stored documents are never sent to any AI service, and no third party receives them in readable form.
  • Encrypted copies on the device. To reopen documents quickly, the web app may keep encrypted copies of preview pictures and small documents (up to 2 MB each, 50 MB in total) in the browser on the user's device. They contain no keys, opening one still asks FileDesk for the key, and they are erased at sign-out and whenever the app finds the session has ended — at once if the app is open, otherwise the next time it is opened on that device.
  • Deletion. Staff permitted to delete documents can remove one. FileDesk deletes the document's key at once, so the stored file can no longer be opened by anyone, and the document disappears from the app straight away. FileDesk then deletes the encrypted file and its preview from Cloudflare, retrying automatically until Cloudflare confirms they are gone — including a file that was still being uploaded at that moment.

2.4 Optional AI summaries

Optional AI summaries use Google's Gemini service. Staff may use them to summarise a client's wealth-statement register. They are switched on or off for the whole FileDesk service, not agency by agency: while they are on, they are available in every agency to staff permitted to see amounts, so each agency controls their use through who may see amounts, and nothing is sent until a user presses Summarise. When a user asks for a summary, FileDesk sends Google a text version of that client's register timeline: dates and tax years, asset categories (including the kind staff type for an "Other" asset) and event types, amounts and sale proceeds, the net-worth reconciliation for each tax year, and item descriptions and notes after CNIC and NTN numbers, phone numbers, e-mail addresses, IBANs and other long numbers have been removed.

FileDesk never sends the client's name or the register's reference fields (such as plot, registration or account numbers) and counterparty fields, and never sends documents, scans or portal credentials. Descriptions and notes are sent after the numbers and addresses listed above are automatically removed; names or short references that staff type into a description or note are not removed, so keep them out of descriptions and notes.

FileDesk uses Gemini under Google's paid-service terms, under which Google does not use the request to improve its products; Google may keep requests for a limited period to detect abuse and meet legal obligations. The summary is shown to the user who asked for it and is not stored by FileDesk; the activity log records only that a summary was generated. Summaries are an aid, can be wrong, and are not tax advice.

2.5 Staff activity log

FileDesk keeps an activity log for each agency that is only ever added to. It records which staff account — the agency owner or a named branch — uploaded, opened, edited or deleted a client document; added, edited or deleted a wealth-register entry; or generated an AI summary, and when. FileDesk never adds amounts, portal credentials, CNIC or NTN values, or file contents to entries; an entry repeats the title or description staff gave the document or item. A client's log is visible to staff who can open that client; the agency-wide log is visible to the agency owner. The software does not edit or delete log entries.

2.6 Calculations, invoices and receipts

Tax calculations run entirely in the browser and are never transmitted or stored. Invoices and receipts are generated locally on the user's own machine and saved to a folder they choose — they are never uploaded.

2.7 What the Chrome extension keeps on the device

So that an operator can search and fill without waiting on the internet for every keystroke, the FileDesk Chrome extension keeps a synchronized copy of the agency's client records in the browser's own storage on that device. This copy holds the searchable client fields listed above and, for clients that have them, the saved portal credentials.

  • Portal credentials in that local copy are encrypted (AES-256) under a key created on that installation that cannot be copied out of it.
  • The copy belongs to one registered installation. Signing out, resetting the installation, or having it revoked erases it.
  • The extension sends this data only to FileDesk's own service. Its one other use is the disclosed purpose in 2.1: on the operator's instruction it types the selected client's credentials into that client's login form on a supported FBR page, which the operator then submits (or, if the operator has turned on automatic submit, which the extension submits). It requests no access to browsing history or other sites.
  • The extension does not access client documents, Cloudflare, the wealth-statement register, the activity log or any AI service. Those exist only in the FileDesk web app, and the extension's data handling is unchanged by them.

2.8 Access, devices and sessions

An agency and its authorized branch accounts work with the agency's shared client list. Configurable permissions — including whether a branch may upload, view or delete documents and whether it sees amounts — govern relevant operational and financial features; they do not create separate branch client lists. The software owner can administer agencies, licences and platform settings, but the owner panel provides no way to read client portal credentials or open client documents.

An ordinary agency or branch account can stay signed in to the FileDesk web app on up to two devices at once — for example a phone and a desktop computer. Signing in on a third device ends the session on whichever of the other two was used least recently. Each ordinary account may have one active Chrome extension installation; moving the extension to another installation requires the old one to be revoked and a replacement approved. An agency owner can revoke an installation or end a branch's web sessions. A synthetic, isolated review account may have a higher extension-installation limit solely for Chrome Web Store testing.

2.9 Service providers

FileDesk relies on three companies, each only for the purpose stated:

  • DigitalOcean, our hosting company, keeps FileDesk's records, including the encrypted credentials and the locked document keys.
  • Cloudflare, our storage provider, stores the encrypted documents and preview pictures and cannot read them; because devices send and fetch them directly, it also sees ordinary connection details such as IP addresses, and it never receives a document key.
  • Google's Gemini service receives the redacted wealth-register timeline described in 2.4, only while AI summaries are switched on for the FileDesk service and a user asks for one.

Client data is not sold, and it is not shared with any provider for that provider's own purposes.

2.10 Retention, backups and removal

Clients are deactivated rather than deleted so financial history stays intact. Stored credentials can be removed at any time from the client's profile without affecting that history. Documents and wealth-register entries can be deleted by permitted staff; the activity log keeps a record that this happened. The update messages FileDesk sends between devices are kept only as long as authorized installations need them to catch up.

We make encrypted backups of FileDesk's records, which can be opened only with recovery material kept separately. Backups never contain document files. A backup taken before a document was deleted may still hold that document's record and its locked key, but not the file: once Cloudflare has confirmed the deletion, the file itself is gone, so a deleted document cannot be brought back from a backup. An agency can ask for an export of its data, including its documents.

A client who wants their documents or other data removed should ask their agency, which controls that data and can delete documents itself or ask us to help.

3. Security

Account passwords are stored only in a scrambled, one-way form that cannot be turned back into the password. Everything travels over encrypted HTTPS connections. Documents are encrypted on the user's device before they are stored, and each agency's data is kept separate from every other agency's. See Security for more.

4. Chrome Web Store Limited Use

FileDesk's use and transfer of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Information handled by the FileDesk extension is used only to provide and improve its disclosed, user-facing purpose: synchronized agency client search and authorized credential filling on supported FBR authentication pages. Apart from filling the selected client's credentials into a supported FBR login form at the operator's request, the extension sends data only to FileDesk's own service — never to Cloudflare, Google's Gemini or any other AI service. Personal or sensitive data is not sold and is not used for personalized, retargeted, or interest-based advertising.

Data is transferred only as needed to provide FileDesk, protect the service and its users, comply with law, or for another transfer permitted by Chrome Web Store policy. Human access to personal or sensitive client data is restricted to cases where the user gives explicit support consent, access is required for a security investigation or legal obligation, or the data has been properly aggregated or anonymized for internal operations.

FileDesk is not affiliated with, endorsed by, or operated by the Federal Board of Revenue (FBR).

5. Changes to this policy

When this policy changes, the date at the top changes. After a material change, the FileDesk Chrome extension asks each user to review the current policy and confirm again before it can be used.

6. Contact

Muhammad Ahsan · mahsan7861100@gmail.com · 0317 7880059