Legal
Privacy policy
FileDesk is software for tax agencies, published by Muhammad Ahsan. This policy covers two separate things: what happens when you visit this website, and what happens to data inside the FileDesk software once an agency is using it. They are governed differently and it matters which one you mean.
1. This website
This site sets no cookies, loads no third-party scripts, and runs no analytics or advertising trackers. Nothing about your visit is profiled or shared.
The only information collected is what you type into the contact form: your name, email, and optionally phone number, city, agency name, branch count, expected client records and your message. It is stored in FileDesk's own owner panel on our server and used solely to reply to you and discuss whether the software fits your practice. It is never sold, never added to a marketing list, and never passed to a third party.
Standard web server logs (IP address, request time, page requested) are retained briefly for security and abuse prevention.
To have an enquiry deleted, email mahsan7861100@gmail.com and it will be removed.
2. The FileDesk software
When an agency uses FileDesk, the agency is the data controller for everything it enters — its clients' identities, contacts, cases, returns, financial records and portal credentials. The agency decides what to collect, who may see it, and how long to keep it. Muhammad Ahsan provides and maintains the software and its hosting, and does not use agency or client data for any other purpose.
2.1 Client portal credentials
FileDesk stores tax-portal usernames, passwords and PINs on behalf of an agency's clients — a digital wallet for credentials the agency already holds. Every person signing in confirms that the agency has obtained each client's permission to store their portal credentials in a digital wallet for the purpose of filing on their behalf, including on branch devices where the extension is installed.
Those values are encrypted with AES-256-GCM before they reach the database, using a separate key per field and a unique initialisation vector per record. They are never written to logs, never included in synchronisation events, and never transmitted to any third party. Inside the browser extension they are re-encrypted under a key belonging to that installation and decrypted only at the instant a login form is filled.
2.2 What else the software stores
- Client identity: name, CNIC, NTN, filer status, contacts and notes.
- Work records: cases, returns and an immutable financial ledger.
- Access records: sign-in sessions, registered extension installations and licences.
Tax calculations run entirely in the browser and are never transmitted or stored. Invoices and receipts are generated locally on the user's own machine and saved to a folder they choose — they are never uploaded.
2.3 Access
Branch users see only what their agency owner permits. The software owner can administer agencies, licences and platform settings, but the owner panel provides no route to read client portal credentials. Each account holds one live session per surface, and an agency owner can end any branch session at any time.
2.4 Retention and removal
Clients are deactivated rather than deleted so financial history stays intact. Stored credentials can be removed at any time from the client's profile without affecting that history. Synchronisation events are retained only as long as offline devices need them to catch up. Encrypted backups are produced on a schedule and retained by the agency.
3. Security
Passwords are hashed with Argon2id. All traffic is served over HTTPS. Data is held on a server controlled by the operator of that FileDesk installation, not in a shared multi-customer environment. See Security for detail.
4. Contact
Muhammad Ahsan · mahsan7861100@gmail.com · 0317 7880059