After the deposit
What is held, and by whom

Privacy

Last updated 14 August 2026

Your salary, your savings, your mortgage balance and everything else you type into the calculator stay in your browser. They are not sent anywhere and not seen by anyone, including us. You can use an account to keep scenarios and buy a pass — and even then what reaches us is encrypted before it leaves your device, under a passphrase we never see. The rest of this page is the detail.

The short version

  • The calculator needs no account. Every figure you enter is worked out in your own browser and never leaves it.
  • If you make an account, we hold your email address and the date your access runs to. That is all we hold about you.
  • Scenarios you save are encrypted in your browser first, including the name you gave them. What we store is a block of bytes nobody here can read.
  • No analytics, no advertising, no tracking, no third-party scripts.
  • Two cookies, and only once you sign in: one to keep you signed in, one holding the character 1 so the page can show you a link to your account without asking the server. Two other settings are kept on your device and never sent.
  • Payment is taken by Stripe. No card details reach this site.
  • The company hosting the site records ordinary web request logs. Nothing financial is in them.

Why your figures stay put

The arithmetic runs as code inside your browser. When you fill in the calculator nothing is submitted: the answer appears because your own device worked it out, and there is no version of using the calculator that sends a figure anywhere.

That is backed up rather than left to trust. The site tells your browser, in a policy it ships with every page, that it may make requests to this site's own address and to nowhere else. If a script were ever added that tried to send your figures to somebody else's server, your browser would refuse it. Forms are blocked from submitting anywhere at all by the same policy. The typefaces are served from this site rather than from a font service, for the same reason — a tool whose claim is that your salary stays in your browser cannot be quietly asking someone else's server for anything.

What that policy no longer does is stop the site talking to itself, because signing in and saving need a server. So the guard changes hands at that point: what may cross is decided by the code that seals a scenario, and the answer is bytes that have already been encrypted. Both ends refuse to accept anything else.

What is kept on your device

Two settings, both stored by your browser rather than sent to us, both containing a single word, and neither identifying anybody:

Neither is a cookie and neither is ever transmitted. Clearing your browser's site data for this site removes both, along with the sign-in cookies described below.

What is in a result link

When you reach a result, the address bar carries the whole scenario so you can bookmark it or come back to it later. Two things are worth knowing about that.

It sits in the part of the address after the # symbol — and your browser never sends that part to any server, not when it requests the page and not when you click a link away from it. So even though the address contains your figures, they do not reach our host's logs, anyone else's logs, or the site you click through to. This is the reason it is stored there rather than in the ordinary part of a web address, which would reach all of those.

But the link itself contains your figures. If you send it to someone, paste it into a chat, or leave it in a shared browser's history, whoever has the link can open your result. Share it deliberately, the way you would share anything else about your money.

If you sign in

There is no password. You type an email address, we send a link to it, and clicking the link signs you in. The link is good for 15 minutes and works once. What is stored is not the link itself but a one-way hash of it, so a copy of our database is a list of useless fingerprints rather than a set of working keys to people's accounts.

Signing in sets two cookies. The first, __Host-atd_session, holds a random value and nothing else — no name, no email, no figures — and the database holds only a hash of that value too. It lasts 30 days, is marked so that scripts cannot read it and it is only ever sent over an encrypted connection, and it is not sent to anybody else's site. It exists to keep you signed in and is used for nothing else: there is no advertising cookie here, no analytics cookie, and nothing that follows you to another site. Signing out deletes it at both ends.

The second, __Host-atd_signed_in, holds the character 1 and nothing else. The first cookie is deliberately unreadable by the page, which means the site cannot tell whether to show you a link to your account without asking the server on every single page load — including for the many people who are not signed in at all. This one answers that question on the device instead. It carries no name, no address and no credential, it cannot be used to reach anything, and it is deleted alongside the first when you sign out.

Asking for a sign-in link is limited to a few attempts an hour per address, so that nobody can use this site to send somebody else a stream of email.

What an account holds

The whole of it, listed. There is no column anywhere in it that describes a scenario — not a price, not a region, not a label:

What is not there: no card number, no payment method, no billing address, no invoice history — Stripe holds all of that and is the party regulated to hold it. No figures, no prices, no scenario names, no profile of you, and nothing derived from watching how you use the site.

Saved scenarios, and the passphrase

A scenario is encrypted on your device before it is sent, with a key worked out from a passphrase you choose. The passphrase is held in memory for as long as the tab is open and is written to no storage of any kind — not a cookie, not your browser's storage, and never to us.

That has one consequence you should know before you rely on it: if you forget the passphrase, nobody can recover your saved scenarios, and that includes us.There is no reset link, because a reset link would mean we could read them. Your figures are also still in the address bar of any result link you keep, which is the other copy and needs no passphrase.

If you buy a pass

Payment is handled by Stripe on Stripe's own pages. Your card details are typed there and never reach this site — we are told that a payment succeeded, which pass it was for, and the identifiers needed to match a future renewal to your account. Stripe holds the rest under its own privacy policy and its own regulation.

The email we send you — a sign-in link, or a receipt — goes out through an email delivery service, which necessarily sees your address and the message in order to deliver it. That is the same arrangement as any site that sends you email, and it is named here rather than left as an assumption.

How long any of it is kept

What the host sees

The site is served by Cloudflare, Inc., and like any web host it keeps request logs. Those record the address of the page requested, the time, your IP address, and what browser made the request. That happens for every website you visit and is what allows a site to be served and protected from attack. The same is true of the requests an account makes — signing in, saving, loading a saved scenario — which go to this same site and appear in the same logs as ordinary requests.

What is not in those logs is anything financial. The scenario lives in the part of the address that is never transmitted, so there is no request in which it could appear, and what a save request carries in its body is already encrypted. The tool page itself is also kept out of search engines, so a result address is not something a crawler can find and index.

Those logs are the host's, held under its own terms and retention, and we do not build anything on top of them: there is no analytics account, no dashboard, no profile of a visitor.

Why we are allowed to hold it

Under UK data protection law, the reasons for each of the above:

If you write to us

Emailing [email protected] means we hold your message and your address, in an ordinary mailbox, for as long as it takes to deal with what you wrote and a reasonable period afterwards. It is not added to a list, not used for marketing, and not passed to anyone.

Please do not send figures you would rather keep private. There is never any need to: if something looks wrong on a result, send the result link, and it opens the same screen you were looking at.

Your rights

UK data protection law gives you rights over personal data held about you: to see it, to have it corrected, to have it deleted, to get a copy of it, to object to how it is used, and to complain. Write to [email protected] from the address the account uses and we will do it.

One of those rights has an unusual answer here. We can delete your encrypted scenarios and we can hand them over, but we cannot show you what is in them, because we cannot read them — only your passphrase can, in your browser. If you have not made an account, there is nothing held to exercise any of this over apart from an email you chose to send us and the host's request logs.

If you are not satisfied with the answer, you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk.

Children

This is a tool for people buying property. It is not aimed at children, is not marketed to them, and asks nobody their age. An account exists to keep your own figures and to buy a pass, and we do not knowingly hold data about children.

Who we are

After the deposit is run from the United Kingdom, under the law of England and Wales, and is the controller of the personal data described above. The contact address is [email protected].

If this notice changes in substance, the date at the top changes with it.