Clearer controls on phones and desktops
- Help and account actions are grouped into focused menus without removing existing functions.
- The vault screen uses clearer account-help and Help Center placement.
- Plain text fields have a per-field clear control, while money and payroll line items keep their existing safeguards.
- Employer and worker state codes are normalized to uppercase before document output.
- All redesigned control labels and accessibility text are available in English and Spanish.
Secure web support
- The optional prompt at startup and the prompt after successful document creation now offer fixed $5, $10, $20, and $50 Stripe-hosted choices on the web.
- Android and iOS continue using their native one-time store products.
- Stripe handles web payment status and receipts; no payroll data is included with a tip.
- A checkout return notice never claims a payment completed, and support never unlocks features or changes access to a generated pay stub.
Safer sharing
- Share pay stub uses the finished document and is clearly separated from public referral sharing.
- Share StubSafe sends only the public website description and link—never the generated document or payroll data.
- Android and iOS use the native share sheet when available; web sharing falls back safely.
Private product measurements
- StubSafe counts successful document generations, support-button intent, referral shares, and export actions only on the current device.
- The counters contain no payroll, identity, location, document, purchase, or completed-payment information.
- Nothing is uploaded, and every counter can be reviewed and reset from System status.
Optional AutoSecureLogin account beta
- Sign in is optional and the initial enrollment is invite-only.
- The web, Android, and iOS flows use Authorization Code with PKCE, state, nonce, exact callbacks, and signed-token verification.
- Account tokens stay in the current session and are not saved in the encrypted payroll vault.
Accounts and vaults remain separate
- Signing in never unlocks, uploads, merges, synchronizes, recovers, or resets a local vault.
- Payroll entries, employer and worker information, logos, documents, vault passphrases, and encryption keys are excluded from account sign-in.
- Local pay-stub creation, private sessions, vaults, and exports continue to work without an account.
Clear guidance in English and Spanish
- Account status and actions are visible in the header, workspace, and vault entry screen.
- The Help Center explains account boundaries, session storage, offline behavior, and each account button in both languages.
- The privacy policy now describes the limited identity information used only when a user chooses to sign in.
PWA, source, and discovery hardening
- Update checks run after reconnecting and returning to the app, while private sessions receive a warning before reload.
- The service worker keeps a versioned offline shell and uses network-first configuration updates with safe fallback.
- The quarterly rules monitor uses a transparent browser-compatible identity for official sources that reject generic automation clients.
- New English and Spanish guides link directly to federal and selected state record sources, collection dates, and independent-review reminders.
- Version 5.7.2 and native build 15 identifiers are synchronized.
Synchronization is not included yet
This account-only beta deliberately does not add encrypted cloud synchronization. Any future synchronization layer requires a separate security review, recovery policy, conflict model, and explicit user consent before it can be enabled.