Privacy Policy

Private by default. Here’s exactly how.

Last Updated: July 17, 2026

Core Privacy Principles

  • Today, your plan data is stored locally in your browser. All calculations run on your device. Nothing you enter is sent to us or anyone else.
  • No user accounts or authentication. We don't collect names, emails, or any personal information.
  • 100% client-side application. There is no backend server storing or processing your data.
  • Anonymous, opt-out usage counts. We count which features are used — nothing more. No identifiers, no cookies, and none of your plan data. You can turn it off anytime in Settings.

Data Storage

Browser Local Storage

retireclarity uses your browser's localStorage to save your inputs, settings, and optimization results. This data:

  • Stays exclusively on your device
  • Is not accessible to us or any third party
  • Persists between browser sessions for your convenience
  • Can be cleared at any time using your browser's settings

What Gets Stored Locally

The following information is stored in your browser only:

  • Personal information (age, retirement age, filing status)
  • Account balances (cash, brokerage, tax-deferred, Roth)
  • Income sources (salary, Social Security, pensions)
  • Expense amounts and categories
  • Investment assumptions and Roth conversion settings
  • Optimization results and timing strategies
  • Display preferences (today's dollars vs. future dollars toggle)

Clearing Your Data

You can clear all locally stored data at any time by clearing your browser's localStorage or browsing data. Instructions vary by browser:

  • Chrome: Settings → Privacy and security → Clear browsing data → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
  • Safari: Preferences → Privacy → Manage Website Data → Remove All

Anonymous Analytics

To understand whether the tool is useful and worth improving, we count usage in one anonymous, cookie-free way. It never receives your financial inputs.

Page views & feature counts — Umami (cookieless, via our own domain)

Both are sent through our own domain (first-party) to Umami and are cookieless — we are not hiding that it is Umami; routing the counts through our domain simply keeps them from being silently dropped by ad and tracker blockers.

Anonymous page views. When you open a page we record an anonymous view of it: the page path (no query string), the referring site (for example a search engine or a link that sent you here), your browser language, a coarse screen size, and an approximate country (derived by Umami from your IP address at the moment of the request and not stored by us). There is no cookie, no unique identifier, and nothing tying one view to another or to you.

Feature counts. We also count which features get used. Each event is a plain name plus, at most, a few coarse labels chosen from a fixed list we publish below — never a number, a date, or anything you typed. There are exactly 37 of them, and this is the complete list, with every label each one can carry:

  • verdict_shown — A retirement projection produced a real verdict (not an empty form).
    • Records kind — which of the three verdicts was shown. One of: on-track, funded-through, funds-short.
    • Records persona — which life stage the visitor picked. One of: working, retiring-soon, retired, unknown.
  • plan_created — A first plan was saved on the device.
    • Records persona — which life stage the visitor picked. One of: working, retiring-soon, retired, unknown.
  • plan_exported — A plan/backup file was exported.
  • progress_return — A returning visit to the Progress page (coarse cadence bucket only).
    • Records bucket — how long since the first visit. One of: first, day-1, week-1, week-2-plus, month-2-plus.
  • scenario_compare_used — The scenario-comparison feature was used.
  • multiplan_created — An additional (2nd+) plan was created.
  • report_or_export_used — A report or CSV export was generated.
    • Records surface — which surface produced it. One of: print_report, csv_export.
  • demo_viewed — The sample-household demo was shown on a tool page.
    • Records page_class — which class of page showed the sample. One of: calculator, tax_optimizer, chance_of_success, progress, landing_roth, landing_monte_carlo, landing_social_security, landing_withdrawal, landing_fire, landing_aca, other.
  • demo_persona_picked — A sample household was selected in the demo.
    • Records sample_persona — which sample household was selected. One of: couple-near-retirement, recently-widowed, sandwich-generation, fire-early-retiree, fire-accumulator, at-risk.
  • start_from_sample — The visitor started a plan from the sample household.
    • Records sample_persona — which sample household was seeded. One of: couple-near-retirement, recently-widowed, sandwich-generation, fire-early-retiree, fire-accumulator, at-risk.
  • use_own_numbers_clicked — The visitor chose to enter their own numbers from the demo.
  • roth_optimizer_run — The Roth-conversion optimizer was run.
    • Records run — first run of this browser session or a repeat. One of: first, repeat.
  • mc_run — A Monte-Carlo simulation was run by the user.
    • Records run — first run of this browser session or a repeat. One of: first, repeat.
  • ss_optimizer_run — The Social Security claiming optimizer was run.
  • mc_different_markets — A Monte-Carlo run against a different market history.
  • mc_bond_optimize — The Monte-Carlo bond-mix optimization was applied.
  • account_added — An account was added to the plan (coarse account-type bucket).
    • Records bucket — which kind of account. One of: 401k, ira, roth, brokerage, cash.
  • real_asset_added — A real asset was added to the plan (coarse asset-kind bucket).
    • Records bucket — which kind of real asset. One of: home, rental, other.
  • liability_added — A liability was added to the plan.
  • income_stream_added — An income stream was added to the plan (coarse income-kind bucket).
    • Records bucket — which kind of income. One of: salary, pension, other.
  • expense_added — An expense was added to the plan.
  • milestone_added — A custom milestone was added to the plan.
  • timing_dates_used — A month-precision timing date was set (partial-year proration).
  • chart_tab_viewed — A projection chart tab was viewed (coarse tab bucket).
    • Records bucket — which chart tab. One of: balances, cashflow, income, taxes.
  • chart_table_toggled — A projection chart was toggled between chart and table view.
  • inflation_view_toggled — The inflation (today’s-$ vs future-$) view was toggled.
    • Records bucket — which dollars view (today's or future). One of: today, future.
  • onboarding_completed — The onboarding flow completed into a real plan.
    • Records persona — which life stage the visitor picked. One of: working, retiring-soon, retired, unknown.
    • Records surface — which hero the plan was created from. One of: home-hero, calculator.
  • cta_click — A named call-to-action into the planner was clicked.
    • Records button — which call-to-action was clicked. One of: blog_calculator, guide_calculator, seo_landing_cta, hero_sample_link, hero_continue_plan, footer_scroll_to_hero.
  • plan_imported — A previously exported plan/backup file was imported.
    • Records kind — whether the file held saved plans or a full backup. One of: plans, full_backup.
  • settings_opened — The Settings modal was opened.
  • analytics_opted_out — The user turned anonymous analytics off.
  • analytics_opted_in — The user turned anonymous analytics back on.
  • waitlist_shown — The sync-waitlist ask was shown.
  • waitlist_joined — A sync-waitlist signup was submitted (never the email address).
  • waitlist_dismissed — The sync-waitlist ask was dismissed.
    • Records stage — dismissed on its first appearance or a later one. One of: first_show, repeat.
  • annuity_template_used — The annuity payments stream template was used.
  • recipe_hsa_clicked — HSA modeling-recipe link clicked from the stream picker.

What Is NEVER Collected

  • Any financial data from your inputs — balances, income, expenses, ages
  • Anything you type, and any number at all — the counts carry only an event name and labels drawn from the fixed lists above
  • Names, emails, or contact information
  • Cookies, device fingerprints, or unique user identifiers
  • Any way to tie an event back to you or to a specific plan

Your choice: anonymous usage counts are on by default and you can turn them off at any time — open Settings → General and switch off “Share anonymous usage counts.” The change takes effect immediately on your device; no further events are sent. You can verify all of this yourself: open your browser’s network tab and watch — you’ll see these anonymous counts and confirm your numbers are never in them.

Crash Reporting

On the production site we use Sentry to capture technical crash reports — the kind of error and stack trace that tells us something broke and needs fixing. It is configured to exclude your financial data.

What a crash report excludes

  • No plan data — no balances, income, expenses, ages, or anything you type. Amounts and long numbers are stripped from error text before it is sent.
  • No session recording. We do not use Sentry Session Replay or any screen recording — nothing watches or replays what is on your screen.
  • No cookies, request bodies, or identifiers. Cookies, headers, request/response contents, and URL query strings are removed from every report.

Crash reports are sent through our own domain. Many of our visitors run ad/tracker blockers that block Sentry’s address directly, so — exactly like the anonymous counts above — the report is routed first-party via retireclarity.com and forwarded on to Sentry from there. We are not hiding that it is Sentry; the routing only exists so a blocker doesn’t silently drop the crash report. The forwarding step never sees your plan data (it is already stripped in your browser before sending) and stores nothing.

Crash reporting runs on the production site only and is covered by the same usage opt-out as the anonymous analytics above: switch off “Share anonymous usage counts” in Settings → General and no crash reports are sent from your device either. Today, your financial data stays in your browser.

Email & the Sync Waitlist

Device sync and backup are coming. If you choose to join the waitlist, we ask for one thing — your email address — so we can tell you when it ships. This is the only personal information the product ever collects, and it is entirely opt-in.

  • Your plan data still never leaves your browser. Joining the waitlist shares your email only — no balances, income, expenses, ages, or projections are sent or linked to it.
  • Stored with our email provider, Resend. Your address is held in a single Resend audience and used for one purpose: to notify you about sync.
  • Double opt-in. After you enter your email we send one confirmation link. You are only added once you click it — so a mistyped or someone-else’s address is never signed up.
  • Unsubscribe or delete anytime. Every email carries an unsubscribe link, and you can ask us to delete your address entirely via the Feedback link in the footer. There is nothing else of yours to delete — we hold only the email.

No Backend Server

retireclarity is a 100% client-side application. This means:

  • All calculations run in your browser using JavaScript. Your financial data is processed locally on your device.
  • There is no backend server collecting, storing, or processing your retirement planning data.
  • We cannot access your inputs, balances, or projections because they never reach us.
  • Even if we wanted to, we have no technical ability to view your financial information.

The application is hosted on Vercel's content delivery network (CDN), which serves the static HTML, CSS, and JavaScript files to your browser. Once loaded, the application runs entirely on your device.

Security

HTTPS Encryption

The site is served over HTTPS, ensuring that communication between your browser and our servers is encrypted. This protects against man-in-the-middle attacks.

Client-Side Processing

Since all calculations occur in your browser, today your financial data does not travel over the internet. This eliminates the most significant security risk: data transmission.

No Authentication Required

We don't require accounts, passwords, or login credentials. This eliminates risks associated with password breaches or account compromise.

Browser Security

Your data's security depends on your device and browser. We recommend:

  • Keep your browser and operating system updated
  • Use device encryption (FileVault, BitLocker, etc.)
  • Lock your device when not in use
  • Use browser profiles or private browsing if sharing a computer

Because all financial data is stored and processed locally on your device, the security of your information depends entirely on the security of your device, browser, and network. You are solely responsible for maintaining appropriate device security, including operating system updates, access controls, and safe browsing practices.

Third-Party Services

retireclarity uses the following third-party services, none of which have access to your financial data:

  • Vercel (Hosting): Hosts and serves the application's static files. See Vercel Privacy Policy.
  • Umami (page views & feature counts): Receives the anonymous, cookie-free page views and feature-count events described above (routed through our own domain). No plan data, no identifiers, no cookies. You can opt out in Settings. See the Umami website.
  • Web3Forms (Feedback): If you submit the optional feedback form, your message and the name and email you provide are delivered via Web3Forms. See Web3Forms Privacy Policy.
  • Resend (sync waitlist): If you opt in to the sync waitlist, the email address you provide is stored with Resend and used only to notify you when sync ships. No plan data is shared. See the Resend Privacy Policy.

Feedback only involves a third party when you explicitly choose to use it, and none of these services have access to your calculator data.

Your Rights

Because we don't collect or store any personal or financial data on our servers, there is no data for us to access, correct, or delete. You have complete control:

  • Access: All your data is in your browser's localStorage and can be viewed using browser developer tools.
  • Correction: Edit your inputs directly in the calculator at any time.
  • Deletion: Clear localStorage via your browser settings to permanently delete all local data.
  • Portability: Export your projections and Monte Carlo results to CSV files for use in other tools.

Children's Privacy

retireclarity is not intended for use by children under the age of 18. We do not knowingly collect information from children. If you are under 18, please do not use this service or provide any information.

Changes to This Privacy Policy

We may update this privacy policy from time to time. Changes will be reflected by updating the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.

Material changes that affect how we handle data (such as adding new analytics services) will be noted on this page with an updated date.

Contact

If you have questions about this privacy policy, please use the Feedback link in the page footer.

Privacy Summary

Bottom line: Today, your financial information stays in your browser. We count anonymous usage — page views and a short, fixed list of feature-level events, recorded first-party through Umami — with no identifiers, no cookies, and no plan data, and you can switch it off in Settings. Your retirement planning data—balances, income, expenses, projections—stays in your browser. The only data ever sent externally that you provide is what you type into the optional feedback form.

For how this compares to server-based tools, see the privacy-first retirement planner overview.