Work / Chitragupt / Wiki / Surfaces
onboarding-consent
Surfacecanonicalverified 2026-08-12
SURFACE.WEB.ONBOARDING.CONSENTOnboarding — Set up your account (consent + personal)
Summary
Step 1 of 2 in onboarding. Two-column screen sized to fit one viewport with no scroll on desktop (stacks to one column, scrolling, below lg): left column is personal information (name, PAN, DOB, residential status), right column is DPDP Act 2023 consent. Backed by acceptDpdpConsent + savePhaseAProfile callables — the profile write is gated on eligibility_acknowledged_at.
Raw wireframe
- .context/designs/web/onboarding/consent.html — updated 2026-08-12 to match the two-column layout and condensed copy, see Behaviour.
Copy
Verbatim user-visible strings (must pass voice):
- Page heading: "Your data, your call"
- Eyebrow: "Required by law · DPDP Act 2023"
- Left column heading: "Tell us about you"
- Right column heading: "Required to use Chitragupt" (badge: "Always on")
- Required consents (3, all on by default):
- "Store your PAN, name, and date of birth" — "Encrypted. Kept while your account is active, plus 7 years — Indian tax law requires it."
- "Read the tax documents you upload" — "Form 16, 26AS, AIS, broker and bank statements. Encrypted. Never used to train AI."
- "Send you service emails" — "Document ready, receipts, reminders. Never marketing."
- Consent checkbox: "I'm 18+ and I agree to the above, as required by DPDP Act 2023 § 6."
- Links row: "Privacy Policy · Terms"
- Disclosure (collapsed): "Your rights under DPDP Act 2023" — See/correct/delete your data, Raise a complaint, Name a nominee, Withdraw consent
- Primary CTA: "Next · pick a plan"
Behaviour
- All three required consents are bundled into one acknowledgement — no per-consent toggles. Acceptance writes
eligibility_acknowledged_at. - Profile write (
savePhaseAProfile) is rejected until the consent timestamp exists. - No optional-consent layer at this step — analytics / marketing opt-ins live in Settings post-onboarding.
- 2026-08-12 UX pass: dropped the explanatory intro paragraph, the per-field helper captions, and the redundant "used only for tax computation" / "copy saved to audit log" footer lines — that information already lives in the required-consent points and the rights disclosure. Each required-consent body was cut to one short clause. Goal: fit the whole step above the fold on a standard laptop viewport without scrolling.
Flows that touch this surface
- new-user-to-dashboard — step 4
Entities referenced
- tier-free — the tier the user lands on after this step
Concepts referenced
- upload-only — gates what happens after consent
Sources
- .context/wiki/flows/* § "Flow 1 — New user → empty Dashboard (free tier)"
- .context/designs/web/onboarding/consent.html
Every project of mine is written down like this.
Read the résumé