The Almanac · LegalPrivacy policyLast updated · Sep 2026

What we keep, and what we don't.

We keep what the product needs to run. Email. A hashed password or an OAuth identity. Your TradingView username if you send one. The billing tokens Stripe sends back. Optional planner inputs if you use that part of the product. No advertising trackers. No ad pixels. No records sold.

0
advertising trackers
or ad pixels
0
records sold
or rented, ever
bcrypt
password hashing
encrypted at rest
30 days
max response to
any rights request

§ 01 · Collection

What we collect.

When you create an account, we collect your email address and a securely hashed password, or an identity token from Google or GitHub if you sign in that way. If you claim Trend Model or start the engine we also store the TradingView username you send us — that name is how access is granted. If you use the optional planner, we store the financial inputs you provide — retirement age, savings targets, income, expenses, portfolio holdings, and simulation parameters. We also record usage events, such as pages viewed and buttons clicked; the Analytics section below covers what those contain.

  • Field Notes is opt-in. We store that choice. Transactional mail (verify, reset, access granted or revoked) goes out whether you opted in or not.
  • A referral code, a plan intent, and a claim intent are stored if you arrived with them, so checkout and the free door land in the right place.
  • If a waitlist form is shown, that form collects an email address, your IP, and any UTM tags on the link you used. Cloudflare Turnstile sees a challenge token and your IP.
  • Theme preference and dashboard layout are stored on your account once you are signed in.

§ 02 · Storage

How we store your data.

All user data is stored in a PostgreSQL database with encryption at rest, hosted with the application on Railway in the United States. Passwords are hashed using bcrypt and never stored in plain text. Database access is restricted to our backend services only.

§ 03 · Retention

Data retention.

We keep what the service needs and purge the rest. Deletion on our systems is immediate and permanent — not a 30-day soft window. Some third parties keep their own copies; those are named below.

Active accounts
Your data is retained for as long as your account remains active.
Deleted accounts
When you delete your account we revoke any TradingView invite, cancel an active Stripe subscription immediately, and permanently remove your user row and the scenarios, profile, milestones, referrals, and activity attached to it. There is no 30-day soft copy on our side.
What deletion cannot erase
Stripe keeps its own billing records. PostHog keeps an analytics profile until we ask them to delete it. TradingView may retain that an invite existed. Transactional email logs stay for up to a year, then go. A waitlist row, if you joined one, is separate from your account and is removed when you unsubscribe or we delete the list.
Cached data
Temporary caches (market-data lookups, simulation results) are periodically purged for inactive accounts.
Email logs
Transactional email records (verification, password reset, access granted or revoked) are retained for up to 1 year for debugging, then permanently deleted.
Analytics events
Usage events are held in PostHog on US servers under PostHog's standard retention schedule. Ask us to delete your analytics profile at any time and we will — see Contact below.
Stripe-held records
Payment-method and billing records held by our payment processor Stripe are retained according to Stripe's own retention policy for financial compliance. RetireMe does not control Stripe's retention of these records. See Stripe's privacy policy for details.

§ 04 · Sessions

Authentication, cookies & local storage.

We use JWT tokens stored in httpOnly cookies for API authentication. These cookies cannot be accessed by client-side JavaScript, which protects against cross-site scripting. If you sign in with Google or GitHub, NextAuth also sets its own first-party session cookie, and a one-minute httpOnly cookie carries the hand-off token. We do not use third-party tracking cookies — the only cookies on this site are first-party.

Two short-lived first-party cookies are set in the browser when you start a free-model claim through OAuth: a claim flag and the TradingView username you typed, each for one day. They are not httpOnly — the OAuth return path has to read them. Your browser's local storage holds a few preferences as well: your theme choice, a referral code if you arrived through a referral link (also kept in a 30-day cookie), and interface settings such as which panels and chart overlays stay open. None of your financial inputs are kept there, and clearing your browser data removes all of it.

PostHog sets a first-party analytics cookie so that repeat visits from the same browser are counted as one visitor. It contains a random identifier — not your name or email — and it is never shared with advertisers. We set no third-party tracking cookies. The same identifier is also kept in your browser's local storage, so it survives if the cookie is cleared. Analytics requests are proxied through our own domain, and the cookie header is stripped by our server before the request reaches PostHog; sensitive URL parameters such as verification tokens and email addresses are redacted in your browser before an event is sent.

§ 05 · Analytics

Analytics & tracking.

  • We use PostHog, an analytics service hosted in the United States, to understand how the product is used — which pages get read, which buttons get clicked, where people stop reading.
  • PostHog's automatic capture of form inputs is disabled. Nothing you type — portfolio values, income, email address, TradingView username — is ever recorded as an analytics event.
  • Key account events (registration, checkout, subscription changes, refunds) are recorded server-side against your account ID so we can tell whether the product works. These events never include payment details.
  • We do not use advertising trackers or pixels, and we do not sell usage data. Anonymous visitors are not stored as identifiable profiles; a profile exists only once you create an account.

§ 06 · Market data

Market data.

Planner portfolio prices are fetched from Yahoo Finance entirely on our servers. No requests are made from your browser to Yahoo Finance or any other third-party data provider. We do not share your portfolio holdings with data providers. The Investing Engine's models run inside your TradingView account, on charts and data TradingView provides — that path does not go through our servers.

§ 07 · Payments

Payment processing.

Subscription payments are handled by Stripe. We never see or store your credit-card number. Stripe provides us with a customer ID and subscription status to manage your account access.

§ 08 · Sharing

Third-party sharing.

The short version

We do not sell, rent, or trade your personal data. Eight external services may process data on our behalf, each for one job: Stripe (payments), Resend (transactional email), PostHog (usage analytics, US-hosted), Railway (application hosting), Yahoo Finance (planner market prices — only ticker symbols are sent, never your holdings or their values), Cloudflare Turnstile (the bot check on our waitlist form, which receives a challenge token and your IP address), TradingView (the username you give us, so we can grant or revoke invite-only scripts), and your sign-in provider if you use one (Google or GitHub, which confirm your identity and return your email address and name; we send them no financial data).

§ 09 · Your rights

Your privacy rights.

EU residents · GDPR

Access, erase, port, object.

Right to access, rectification, erasure, data portability, restriction of processing, and objection. Our legal basis: contract performance (providing the service you signed up for) and legitimate interest (product improvement through pseudonymized usage analysis).

California residents · CCPA

Know, delete, opt out.

Right to know what personal information we collect, right to delete, right to opt out of the sale of personal information (we do not sell your data to anyone), and right to non-discrimination for exercising your rights.

  • How to exercise your rights: use the “Delete my account” option on your account page, or email support@retireme.app for a copy of your data or any other request.
  • Response timeline: we respond to all data-rights requests within 30 days.
  • Marketing mail: Field Notes is opt-in. You can turn it off from your account or the unsubscribe link in the email. Transactional mail is not marketing.
  • Children: RetireMe is not directed at children. We do not knowingly collect personal information from anyone under 18. If we learn we have, we delete it.
  • Where it is processed: the application, database, and analytics run in the United States. Using the product from elsewhere means your information is processed there.
  • Who holds this: RetireMe is operated by Tristan Marcus, doing business as RetireMe.

Questions about this policy?

We answer privacy mail directly — no ticket queue.

support@retireme.app