← Back to the planner

Privacy Policy

Last updated August 27, 2026

Retirement Planner is a personal-finance modelling tool. This policy describes exactly what it stores and who can see it. It is deliberately specific rather than generic.

What we collect

Nothing at all until you choose to sign in. After that:

  • From your Google account: your name, email address and profile picture. We request only the standard email, profile and openid scopes. We never receive your Google password, and we cannot read your Gmail, Drive, Calendar or contacts.
  • Usage data: which pages you visit, the referring page, your browser user-agent string, and an approximate country and city derived from your IP address by our hosting provider. We do not store raw IP addresses.
  • Activity events: when you run a projection we record that it happened, along with a few high-level settings (retirement age, annual spending, conversion strategy) and the resulting success percentage.
  • Scenarios you save: if you press Save, the planning inputs for that scenario are stored against your account so you can reload them later.

What we never collect

We do not ask for and cannot receive account numbers, Social Security numbers, passwords, or credentials for any bank, brokerage or financial institution. The planner is not connected to any of your financial accounts. Every figure in it is a number you typed yourself, and it stays a number — nothing is verified against or transmitted to any institution.

Who can see your data

  • You can see everything associated with your account.
  • Other signed-in users cannot see anything of yours. Every query the application makes for saved scenarios is filtered to the account that asked for it.
  • The site owner can see the list of registered accounts and aggregate usage — who signed up, when they last visited, how many projections they ran.
  • The application never displays the contents of your saved scenarios to anyone but you. The admin dashboard reports counts and activity only. It can show that you saved three scenarios and when you last visited; there is no screen, query or export anywhere in this application that reveals what is inside them.

A correction, made honestly. Before August 27, 2026 this page said the site owner cannot see your saved scenarios, and attributed that to a database policy with no administrative exception. That was stronger than any hosted application can truthfully promise: the owner administers the database and can read any row in it directly, and that was as true of the previous setup as it is of this one. The guarantee above is the accurate one — it is a limit built into the software, not a claim about the database. If you would not put something in a spreadsheet on someone else's computer, do not put it here.

What we don't do

We do not sell your data. We do not share it with advertisers, data brokers or marketers. There are no advertising trackers, no third-party analytics scripts and no cross-site tracking pixels on this site. Cookies are used only to keep you signed in.

Where it is stored

Data is held in a Neon-hosted PostgreSQL database in the United States (AWS us-east-2), and the application is served by Vercel. Sign-in is handled by Auth.js against Google. All three act as processors on our behalf. Traffic is encrypted in transit over HTTPS.

Retention and deletion

Your data is kept until you ask us to remove it. To delete your account and everything attached to it, email kryptosubs@gmail.com from the address you signed up with. Deletion is permanent and cascades to your profile, saved scenarios and activity records. You may also revoke this app's access at any time from your Google account permissions page.

Children

This tool is intended for adults planning their own retirement and is not directed at children.

Changes and contact

If this policy changes materially, the date at the top will change. Questions go to kryptosubs@gmail.com.

See also the Terms of Service.