Privacy Policy
What this site collects, what it does not, and what happens to it. Effective September 20, 2026.
1. The free app collects nothing
The calculator runs entirely in your browser. There is no account, no server doing the arithmetic, and no request carrying your figures anywhere. Everything you type is written to your own browser's local storage and stays on that device.
We cannot see it. Not in aggregate, not anonymised, not for debugging. If you email us about a wrong number, we have no way to look at your plan unless you describe it or send it to us.
The practical consequence runs both ways. Nobody can take this data from us, because we do not have it. But nobody can restore it for you either: clearing your browsing data, using private browsing, or switching device or browser will lose it. Export anything you would mind losing.
What is in your browser, key by key
| Local storage key | What it holds |
|---|---|
retirementModelInputs | Ages, retirement ages, spending target, return and inflation assumptions, tax rates, Social Security figures. |
retirementPortfolio | The accounts you added: nickname, type, balance, contribution, interest rate, and any pension or rental details. |
retirementActivePlan | The savings plan currently driving the Optimized Path. |
retirementSavedPlans | Any named plans you saved. |
retirementOnboarding | Answers part-way through guided setup, so a refresh resumes where you left off. |
retirementUiPrefs | Display preferences, such as which view a tab was last showing. |
retirementConsent | Your analytics choice and when you made it. |
ui-theme | Which colour theme you picked: light, dark, or follow the system. Shared with the blog, so you are not asked twice. |
retirementAuth | Only if you sign in: your refresh token and basic profile. The access token is held in memory and never written to storage. |
Clearing site data for this domain in your browser settings removes all of it.
The planner is designed so it never needs identifying details, and you should not give it any. Balances and nicknames are enough. There is no field asking for an account number, a Social Security number or a login for any financial institution, and no feature that would use one.
2. Analytics, only if you agree
We use Google Analytics to see which features get used, so effort goes where people actually are. It is the only third-party script on the site, and it is off until you consent.
- Nothing loads before you click OK. The Google tag is not injected, and no analytics cookie is set, while the banner is unanswered. Ignoring the banner forever is a valid answer and leaves analytics off.
- You can withdraw it. The cookie settings control in the app and in the blog footer clears the
_gacookies and stops collection. - No financial values, ever. Events carry short text labels such as which tab was opened. Balances, contributions, ages, spending targets and plan names are never sent, and the code that sends events accepts only strings.
- What Google receives is the usual web analytics set: a page path, a truncated IP address, approximate location from it, device and browser type, and a random identifier in a cookie. Google is the processor for that data under its own terms.
The blog at /blog shares this decision rather than asking twice, which is possible because it is served from the same origin as the app and can read the same stored choice.
3. What hosting sees
The site is served by GitHub Pages. Like any web host, it processes the requests your browser makes, which includes your IP address, for the purpose of serving pages and protecting the service. That is GitHub's processing under GitHub's privacy statement, and we do not receive those logs or have access to them.
Fonts are served from this site rather than from a font CDN, deliberately, so reading a page does not disclose your IP address to a third party before you have agreed to anything.
4. If you create an account
An account exists for one purpose: to sync the same figures between your devices. Everything in this section applies only if you chose that.
What we store
| Data | Why |
|---|---|
| Email address | To identify the account, verify it, and send account email such as password resets. |
| Password | Stored only as a salted hash through ASP.NET Core Identity. We never hold the password itself and cannot read it. |
| Display name, if you set one | Shown in the app. Optional, and a nickname is fine. |
| Your plan snapshot | One document holding the same figures the free app keeps locally: assumptions, accounts, balances, contributions and saved plans. This is the thing being synced. |
| Session tokens | Refresh tokens are stored only as a SHA-256 hash, rotate on every use, and a reused one revokes the whole family as theft detection. |
| Subscription status | Kept in step with Stripe by webhook, to know whether sync is active. No card details. |
The snapshot is financial information about you, and it is treated that way: it is reachable only with your own credentials, over HTTPS, and it is not sold, shared, rented, mined or used to build a profile of you. It is not training data for anything. We do not read individual snapshots.
Where it lives
On a managed PostgreSQL database and an application server run by DigitalOcean, in the United States. Payment processing is Stripe, and card numbers go directly to Stripe and never reach our servers. Account email is delivered by an SMTP provider. Each of those is a processor acting on our instructions under its own terms.
Sign in with Google
If Google sign-in is offered and you use it, Google tells us your email address and basic profile so the account can be created. We do not receive your Google password and get no access to anything else in your Google account.
5. How long anything is kept
- Local data: until you clear it. It is on your device and under your control, and nothing expires it.
- An active account: for as long as the account exists.
- After a subscription is cancelled: the cloud snapshot stays readable and exportable for 90 days, then it is deleted automatically. You get a warning email a week before that happens and a confirmation when it does. The copy in your own browser is never touched, and the app keeps working free.
- When you delete your account: the account record, the snapshot, the session tokens and the subscription record are removed together, and any active Stripe subscription is cancelled first so you are not billed for a deleted account. Stripe keeps its own payment records, as payment processors are required to.
- Analytics: retained by Google for the window configured on the property, which is measured in months, not years.
6. Your choices
Most of what a privacy policy usually has to promise is, here, just a button:
- See your data. It is on screen. The free app shows you everything it holds, because that is all it is.
- Take it with you. Export from inside the app, at any time, account or not.
- Delete it. Clear site data in your browser for the local copy. Delete your account from the account page for the cloud copy.
- Correct it. Every figure is editable, and account details can be changed on the account page.
- Change your mind about analytics. The cookie settings control, any time.
Depending on where you live, you may also have statutory rights to access, correct, delete or port your personal information, to know whether it is sold or shared (it is not, and never has been), and not to be discriminated against for exercising them. Write to crsavage0630@gmail.com and we will honour a request of that kind. We may need to confirm you control the account's email address first, which is the only way we can tell it is you.
7. Security, honestly stated
Passwords are hashed, tokens are hashed and rotated, access tokens are never written to disk, everything travels over HTTPS, and payment details never touch our servers at all.
No system is perfectly secure, and this one is run by one person rather than a security team. That is a reason to keep the free, local mode the default and to ask for as little as possible: the smallest amount of data we could be holding is none, which is what an account-free visit involves. If a breach ever affected your data, we would tell you, promptly and in plain language.
8. Children
This is a retirement planner for adults. It is not directed at children, accounts require you to be 18 or older, and we do not knowingly collect personal information from anyone under 13. If you believe a child has created an account, write to crsavage0630@gmail.com and it will be deleted.
9. Changes to this policy
The current version always lives at retirementmodeler.com/privacy/ and carries the date it took effect. If a change materially affects how your information is handled, account holders get notice before it takes effect. Nothing you have already given us will be used for a materially different purpose without asking you first.
10. Contact
Privacy questions, data requests and complaints all go to crsavage0630@gmail.com. A person reads it.
The agreement covering use of the site is the Terms of Use.
Effective September 20, 2026.
This page is the current version of the policy. Terms of Use · Open the app · Read the blog