No financial data stored. No profiling. No mining. Here's exactly how your data moves — and why you have my word that it stays that way.
I've seen the data-mining playbook up close, and I want no part of it. I wouldn't want my data turned into someone else's revenue — so I won't do it to yours.
No databases holding your financial statements. No logs of your client names or figures. When a job is done, the data is gone. These tools are calculators — they calculate, and that's the end of it. No behavioural tracking, no repurposing of what you put in, no hidden agenda. The only thing I retain is a verified email, where a tool asks for one — kept to keep bots out and to see which tools get used. Never for marketing.
I'm one person building workflow tools. There's no dashboard showing me your clients' income statements. The data passes through — I never see it.
No ad networks. No data brokers. No "anonymised aggregates" sold to third parties. Not selling your data is a deliberate commitment — and it stands even if I introduce paid tools or features in future. Your data is never the product.
Most of what Russolutions does happens entirely in your browser — parsing, formatting, table manipulation, exports. For these operations, your data never leaves your machine.
For a small number of operations — where proprietary classification, advanced parsing, or calculation logic lives — data is sent to a third-party cloud provider, processed in an isolated serverless function, and returned to you. That's the full extent of it — with one exception, Ask iRuss, which uses a third-party LLM API service and gets its own note alongside.
Think of it like a calculator you hand to someone for one step: they do the computation and hand it straight back. They don't photograph it. They don't write down the numbers.
The invitation-only preparation tools go one step further, because they hand you back a finished document. When you ask one of them for a package, the figures behind it — the computation, the schedules, the entity's name and period — are sent so the workbooks and the covering letter can be built, and then emailed to the address you signed in with. That happens in memory, for that one request. The files are not written to disk, the figures are not stored, and the request body is never logged. What is kept is a single ledger row recording that a request was made, which tool made it and for which year of assessment — no amounts, no client names.
Like all websites, my hosting provider automatically captures basic connection data — IP addresses, timestamps, browser types — for security and crash monitoring. This is standard infrastructure behaviour outside my control. The hosting provider does not log request or response body content, which means your financial data — sent in the body of a serverless function call — never appears in any infrastructure log. Your actual files and figures are never logged anywhere.
A few tools (like the GL Analyser's full report) ask you to verify an email address with a one-time code before unlocking the full output. That email is stored — via a third-party authentication provider — solely to prevent automated abuse and to understand which tools get used and how often. It is not used for marketing, and I won't email you. The ledger data you analyse is still never stored (see above).
Ask iRuss is the one tool that does not run on Russolutions' own deterministic logic. Your question — and the short conversation history kept in your tab — is sent to a third-party LLM API service, which interprets the question and drafts the answer from extracts of the official sources. That text leaves my infrastructure and is handled under the provider's own terms, which is why the app asks you, prominently, to leave out names, NRIC/FIN and UEN numbers and anything that identifies a person or client. On my side nothing changes: the conversation is never stored — it exists only in your tab — and the only record kept is a single usage ledger row (who asked, which persona, token counts), never the question text.
The Russolutions Chrome extension — R:each and the CRAFTED Prompt Tool — is a different architecture from everything above, and it has its own page: the extension's privacy policy. The short of it is that none of the flow on this page applies, because the extension has no server side at all: it makes no network requests of any kind, and what you type into it stays in your own browser's local storage on your own machine.
The data you upload stays your responsibility. You — or your firm — remain the party accountable under the PDPA and your client engagements for being authorised to process whatever you put in, and for leaving out what a job doesn't need. These tools hold nothing either way, but good data hygiene starts before the upload.
I spent four years in the cryptocurrency industry. It forces a unique perspective most people miss: relying on trust is a vulnerability. The answer is architecture—building systems where there is simply nothing to steal and nothing to leak.
I also understand what secure infrastructure actually costs — encrypted databases, access controls, audit trails, breach response. When those fail, the consequences are real. They land on real clients, real firms, real reputations. The simplest way to avoid that risk is not to hold the data in the first place — which is exactly how these tools are built.
I don't need to know who you are to process your data. You are invisible to my system—by design, not by accident. I’ve seen the corporate playbook of vacuuming up everything a user does online, and I want no part of it. I have absolutely zero interest in your digital footprint.
The simplest data security is not storing data at all. If I don't have it, it can't be breached, subpoenaed, mined, or accidentally exposed. In-browser processing isn't just a privacy choice — it's a better architecture for tools where the data is confidential by nature.
I'm not a faceless company with a legal team writing policies designed to be technically accurate but practically meaningless. I'm Russell. I'm an Accredited Tax Advisor who got tired of doing things the slow way, and decided to build something better.
I'm not trying to build a data business. I'm trying to build tools good enough that tax professionals have more time to spend with their families — including mine. That's the whole idea. That's been the whole idea from the start.
If you know me, you know that means something.
If you don't know me yet — I hope the tools earn your trust. And if they do, I hope this page helps you understand why you can extend it without hesitation.