Privacy Policy

Your privacy is part of our product. We collect only the information needed to operate our services, keep your account secure, and provide support. Optional analytics are off by default. This policy explains what we collect, why we collect it, and the choices you have.

Last updated: 1 February 2026

Information we collect

We collect data you provide directly, such as name, email, phone, and the details you share when requesting a session or setting goals. We may collect usage data, like pages viewed and device type, to maintain performance and security. If you choose to enable optional analytics, we receive aggregated insights that help us improve the site. We do not collect sensitive categories unless you voluntarily provide them for support, and we recommend not sharing more than necessary.

  • Account and contact details
  • Goal and planning inputs you choose to store
  • Device, browser, and basic event data for security
  • Cookie preferences and consent status

How we use information

We use your data to provide and improve the service, respond to questions, and secure accounts. Typical uses include sending confirmations for sessions you request, recommending contribution ranges based on your inputs, troubleshooting issues, and preventing abuse. Optional analytics, when enabled, help us understand which guides are most helpful. We do not sell personal data and we avoid intrusive advertising practices.

  • Operate, maintain, and protect the service
  • Provide support and respond to requests
  • Send service messages you ask for
  • Improve content and accessibility

Legal bases under UK GDPR

We process personal data on the following legal bases, depending on context: performance of a contract when you request a session or set up a plan; legitimate interests for security, fraud prevention, and improving the site in ways that respect your privacy; consent for optional analytics and certain communications; and legal obligations where record‑keeping is required. You can withdraw consent at any time, and you may object to processing based on legitimate interests.

  • Contract: providing requested services
  • Legitimate interests: security, usability, and reliability
  • Consent: optional analytics and non‑essential emails
  • Legal obligation: compliance and record‑keeping

Data sharing and transfers

We share data with trusted providers that help us run the service, such as secure hosting and email tools. Providers must follow strict confidentiality and security standards. If data is transferred outside the UK or EEA, we use appropriate safeguards, including Standard Contractual Clauses where relevant. We do not permit partners to use your data for their own marketing.

  • Hosting and infrastructure
  • Email and customer support tools
  • Optional analytics with IP masking

Retention

We keep personal data only as long as necessary for the purposes described in this policy. Account and planning data are retained while your account is active. Support messages are generally kept for up to 24 months, unless we need them longer for legal reasons. If you request deletion, we remove or anonymize your data unless we need to keep certain records to comply with the law.

Your rights

Under UK data protection law, you have rights to access, correct, delete, and port your data, as well as to restrict or object to certain processing. You also have the right to withdraw consent where processing is based on consent. To exercise these rights, contact us using the details above. You can also lodge a complaint with the UK Information Commissioner's Office.

  • Access and portability
  • Rectification and erasure
  • Restriction and objection
  • Withdraw consent at any time

Security

We apply layered security controls such as encryption in transit and at rest, role‑based access, and continuous improvement practices. No method is perfectly secure, but we work to reduce risk and respond quickly to issues. If we identify a breach that affects your rights, we will notify you and relevant authorities as required.

abstract secure vault door indicating encryption

Cookies and similar technologies

We use essential cookies to make the site work, such as remembering your cookie choice and keeping sessions secure. Optional analytics cookies, when enabled by you, help us understand aggregate usage without identifying you. You can change your cookie preference at any time via your browser settings. Rejecting optional cookies does not limit access to our content.

  • Essential: security, load balancing, consent
  • Optional: privacy‑respecting analytics

Children's privacy

Our services are designed for adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes to this policy

We may update this policy to reflect changes to our practices or the law. We post updates here and adjust the date at the top. Significant changes may be communicated through service notices.

Questions or requests

If you would like to access, correct, or delete your data, or if you have a privacy concern, reach out and we will respond promptly. We aim to resolve most requests within 30 days.

person reviewing privacy settings on a laptop
We use essential cookies to run this site and optional analytics to improve experience. You can accept or reject optional cookies at any time in Settings.