Clarity for the years ahead
Privacy and local data
Interactive public calculators run locally in your browser. Their inputs live in this page’s memory: they are not sent as calculation requests, included in URLs or saved to your retirement plan. Your browser may retain this page and its inputs when restoring a tab or navigating Back; leaving the page is not a secure erase.
The optional calculation service is separate
A developer or other caller can explicitly POST the ten numeric inputs to the optional calculation service. That request sends the supplied financial numbers over the network for calculation; it does not automatically read your browser’s saved plan. The interactive website calculators do not call this service. Supply only the documented numeric fields, never names, account records, attachments or personal identifiers.
The application handler processes these inputs in memory and does not write financial payloads to application logs or persistent storage. It does not log request bodies, returned financial results or submitted values in error messages. This is an application behaviour statement, not a blanket promise of zero retention throughout the hosting infrastructure or a caller’s own systems.
Rate limiting uses short-lived in-memory counters. If a verified host connection identity is available through a trusted adapter, it can use a salted hash of that identity rather than store the raw address. Hashing does not make an identifier anonymous. The current managed function interface supplies no trusted connection IP to this handler, so callers share fallback and worker-wide buckets; it does not trust forwarded headers as identity. Default windows last 60 seconds. Expired identity entries are removed on subsequent requests, and all counters and hashes disappear when the worker restarts; this is not a guarantee of deletion exactly 60 seconds after a request.
See API inputs, errors and service limits and the shared calculation method before submitting numbers.
Your saved plan stays in your browser
The full planner uses local browser storage, without application-level encryption or a login. Demo data is stored separately. Anyone with access to your browser profile, and scripts running on the same origin, may be able to access these records. Clearing site data can erase them.
Attachments are read locally, not uploaded by the app. Backups include private records and may include attachments: store them securely. Browser extensions and device security are outside this app’s control.
Sharing is a deliberate disclosure
Shared links contain an encoded numerical snapshot in the URL fragment, not encrypted data. They include financial inputs and totals but exclude names, individual records and attachments. Anyone with the link can read or alter it; links are not authenticated, live or revocable. URL fragments are not sent in normal HTTP requests, but links can remain in browser history or be copied.
Website requests are still network traffic
Loading the website or explicitly calling the service sends requests to its host. Hosting access logs, platform diagnostics and their retention policies are separate from the application’s handling of financial payloads; they may include IP addresses, requested paths and other request metadata. No universal zero-retention claim is made. Avoid putting financial data in URLs; the API rejects query strings.
The app includes no analytics. Following an external source link uses that website’s privacy policy. Local-first does not mean anonymous or encrypted.
Manage your local data or export a private backup in the planner.