Skip to content
Privacy & records

Know where a record goes before entering it.

This notice describes the pilot reviewed on 5 October 2026. Private email sign-in setup is pending. The fictional demo is the available way to explore the application without entering real household records.

Reading the public guides

Reading these pages does not require a household account. Cloudflare provides the website hosting and may process connection information under its own service arrangements. No advertising or third-party analytics integration is currently included in the application.

Public guides and examples do not contain real helper payroll records. Do not place personal or payroll details in a public URL.

The fictional browser-local demo

Demo profile and financial changes are saved in this browser’s local storage. Other people using the same browser profile may be able to view them. Resetting the demo removes its saved demo record and starts again with fictional data.

Uploaded demo signed-copy file bytes are held only for the current browser session and are not retained in the demo JSON export. Demo mode is intended for fictional data; avoid real names, addresses, signatures or wage records.

The private workspace design

The private pilot is designed to store household and helper profiles, contract and compensation history, calendar events, expenses, statements, actual payments, audit entries and retained original or signed statement files in Cloudflare services. Access depends on an active household membership.

The planned passwordless email flow uses Resend to send a sign-in code to an authorized address. Email-code login is a single factor. Activation awaits verified sender and real inbox testing. Authentication codes and session tokens are stored as hashes rather than plaintext.

Keep the household record proportionate

Collect only the details needed for the stated payroll purpose and protect access to them. The PCPD principles address necessary collection, appropriate retention, security and access or correction.

  • Do not upload passports, identity documents or medical records to the statement upload.
  • Use a payment reference where it explains the payment; avoid unrelated bank details.
  • Keep signed evidence accessible only to the authorized household people who need it.

Source: PCPD: the six data protection principles

Decisions required before real household use

The operator identity, dedicated privacy contact, provider processing terms, data location, payroll retention schedule, deletion process and tested backup/restoration arrangements remain under review. No unverified retention period or contact address is promised here.

The owner export workflow is implemented, but an export is not a tested disaster-recovery process or a deletion request. These operational details must be finalized before inviting real households to store personal payroll records.

CHECK THE ORIGINAL

Sources & review dates

Official sources were checked on the dates below. Later changes and individual cases may require a fresh review.

  1. PCPD: the six data protection principlesChecked 5 October 2026
A PLACE FOR THE WHOLE MONTH

Put the plans, pay and receipts together.

Explore the fictional demo to see how the supported household workflow fits together. The pilot does not execute bank transfers or certify legal compliance.

Open the workspace