Privacy policy
Effective: 5 August 2026
The Possibility Calculator is operated by Stephen Baugh. This policy explains how we handle information when you use our public website, web application, iPhone or Android app.
The short version
- We collect what the service needs: account and security details, the planning information you choose to enter, subscription records, support messages, and limited technical analytics.
- We do not sell your personal information or use your financial entries for advertising.
- Sharing is optional and under your control. If you share a scenario group, the people you invite can see the planning information in that group. Goals and your other groups remain private.
- Your payment credentials go to the payment provider. Apple, Google Play or Stripe processes the payment; we do not receive your full card number or store password.
- You can permanently delete your account and application data. Use Settings → Delete Account or follow the account-deletion instructions.
Information we collect
- Account and contact information: email address, optional name, account country, a one-way password hash, and the information needed to verify your email or help you.
- Financial-planning information you enter: scenarios, income, expenses, debts, balances, interest rates, investments, savings, budget groups, payment-method descriptions, notes, goals and next-step tasks. We do not connect to your bank or import bank transactions.
- Sharing and invitation information: the email address you invite, the scenario group, the access level you choose, invitation and acceptance status, and records needed to change or remove access.
- Subscription records: provider, product and plan, currency and price where supplied, subscription or transaction identifiers, status, renewal or expiry date, cancellation state, and offer eligibility. These records let the same account recognise an entitlement purchased on the web, iPhone or Android.
- Security and technical records: session and authentication records, two-factor settings if enabled, IP address, request and sign-in logs, app version, operating system, and diagnostic information needed to protect and troubleshoot the service.
- Analytics, when enabled: website page views or mobile screen names, basic app and device information, approximate country or region, a Firebase app-installation identifier, and limited app-error information. Our mobile custom events do not include your email, account identifier, scenario or goal names, notes, or budget figures.
- Communications: messages and information you send when requesting support, exercising a privacy right or reporting a problem.
How we use information
- to create and secure your account, save your planning information, calculate scenarios, and provide the features you request;
- to send and manage scenario-group invitations and make shared groups available to the people you choose;
- to verify subscriptions, restore access, process plan changes, and respond to renewals, cancellations, refunds, disputes or expiry;
- to send authentication, security, account and service messages;
- to prevent abuse, investigate errors, keep the service reliable, and understand aggregate usage when analytics is enabled; and
- to meet legal, accounting, consumer-protection and store-platform obligations.
Where data-protection law requires a legal basis, we rely on performance of our contract with you, legitimate interests in security and service operation, your consent for optional analytics where required, and compliance with legal obligations.
Cookies and analytics choices
- Essential web storage: session and security cookies keep you signed in and protect forms. A remembered two-factor device may be stored for 30 days. Theme preferences are stored in your browser.
- Authenticated dashboard analytics: the main dashboard may use privacy-limited Google Analytics to count a generic dashboard view and measure technical performance. It does not send scenario or goal names, notes, budget figures, full dashboard page addresses, referrers or document titles. Google Ads and Meta advertising trackers do not load in the authenticated dashboard.
- Mobile analytics: Firebase Analytics is disabled at app startup. In the EEA, United Kingdom and Switzerland it remains off until you agree. Elsewhere it is enabled by default. Every mobile user can turn it on or off at any time under Settings → Share app analytics.
- No mobile advertising identifier: the iPhone and Android builds exclude advertising-identifier support. We do not use mobile analytics for targeted advertising or cross-app tracking.
Scenario-group sharing
The account that owns a scenario group can choose to invite another person by email and give them view-only or read/write access. Sharing is limited to the group you select.
- What the invited person can see: after accepting with the invited email address, they can see every scenario and item currently in that group, plus scenarios and items added to it later. Goals and groups you have not shared remain private.
- Read/write access: a contributor can change existing shared scenarios and items. Those changes are saved in the owner's shared group. The contributor's private groups and planning information are not automatically shared.
- Changing your mind: the owner can change the access level or remove access. Removing access stops future access, but it cannot erase information a recipient has already copied, exported or passed on.
- Share carefully: financial information can be sensitive. Share only with someone you trust and only when it feels safe; never because you feel pressured or unsafe.
Service providers and other disclosure
Apart from scenario-group sharing you choose, we disclose only the information reasonably needed to operate the service, or information required by law. Our principal providers are:
- Amazon Web Services — application and database hosting, encrypted backups, managed secrets and transactional email delivery.
- Apple — iPhone subscriptions, store transactions and related subscription notifications.
- Google — Google Play subscriptions, Firebase Analytics when enabled, fonts and website analytics services.
- Stripe — website subscription checkout, billing, refunds and payment disputes.
- Queensberry Workspace — hosting and operation of the public The Possibility Calculator website.
- Meta — consent-based measurement on the public marketing website, where enabled by your cookie choice.
We may also disclose information where reasonably necessary to comply with law, protect users or the service, investigate fraud or security incidents, or complete a business transfer subject to appropriate protection. We do not give service providers permission to use your budgeting information for their own advertising.
Security and international processing
We use HTTPS, access controls, account-scoped queries, one-way password hashing, optional two-factor authentication, rate limiting, managed secrets, and encrypted database backups. No online service can promise absolute security, but we use safeguards proportionate to the sensitivity of the information.
Our providers may process information outside your country, including in New Zealand, Australia, the United States and other locations where they operate. Where required, we rely on the provider's contractual and legal transfer safeguards.
Retention, deletion and your choices
- While your account exists: we retain account and planning information so the service works, and retain subscription records while needed to determine access and handle billing events.
- Delete it yourself: Settings → Delete Account permanently removes your sign-in details, scenarios, budget items, goals, tasks, payment-method descriptions, shared groups you own, invitations, subscription entitlements and related security records from the live application database. It cannot be undone.
- Shared-group records: deleting an invited contributor's account ends their access, but does not delete another person's group or changes already saved to that group. Deleting the owner's account removes the groups they own from the live application database and ends access for invited people.
- Request deletion outside the app: follow the public account-deletion instructions or email support@thepossibilitycalculator.com from your registered address. We will act on a verified request as quickly as practical and within one month at most.
- Subscriptions when you delete: website subscriptions managed by Stripe are cancelled before deletion. Apple App Store and Google Play subscriptions remain controlled by those stores, so cancel the store subscription before deleting if you do not want it to renew.
- Backups and logs: routine encrypted database backups may contain deleted information for up to seven days before automatic expiry and are used only for disaster recovery. Limited security and request logs may be retained for as long as reasonably needed for fraud prevention, security and troubleshooting.
- Provider records: Apple, Google Play and Stripe independently retain payment and transaction records under their policies and legal obligations. We cannot delete records they control.
Access, correction and other rights
You can view and edit most information directly in the application. You may also email support@thepossibilitycalculator.com to request access, correction, deletion, restriction, objection or portability where applicable. We may need to verify that the account belongs to you before acting.
New Zealand's Privacy Act 2020 provides rights of access and correction. Privacy laws in the UK, EEA and some other locations may provide additional rights. You may also complain to your local privacy regulator.
Changes and contact
If this policy changes, we will update the effective date and give reasonable notice of material changes where required. Questions or privacy requests can be sent to support@thepossibilitycalculator.com.
Operator: Stephen Baugh, The Possibility Calculator, New Zealand.