Privacy Policy
Last updated: July 16, 2026
1. The short version
Cloudbreak is a financial planning tool. The financial information you enter saves on your device and backs up automatically to your account in our cloud database, so your work survives a cleared browser and can be restored on another device. It is used to run the service for you — nothing else. We do not sell your personal information, the app carries no advertising or third-party analytics trackers, and one in-app control deletes your plan data everywhere: this device and the cloud.
This policy covers the Cloudbreak planning application and this website, and explains each of those statements in full.
2. Information you provide
Plan data. The planner stores what you enter: account balances and account types, income and savings amounts, spending and budget figures, birthdates, household details such as filing status, state of residence, and family size, planned life events, and the assumptions you set. This is sensitive financial information, and the service treats all of it as data to store for you — never as data to mine.
Everything is manual entry. The tool does not connect to banks, brokerages, or any financial institution. It never asks for credentials to outside financial accounts, for full account numbers, or for Social Security numbers, and it has no way to move money. Round numbers work as well as exact ones — what you enter is up to you.
3. Account information
Anonymous account. The first time the app runs, it creates an anonymous account automatically — a random identifier with no name, email, or profile attached — so your work can back up from the start without a signup step. There is nothing to fill in and no email is requested.
Google sign-in (optional). You can connect a Google account to make your backup recoverable on other devices. If you do, our authentication provider receives your name, email address, and profile picture from Google (the basic openid, email, and profile scopes — nothing more), and attaches them to the same account, keeping the data you already backed up. Sign-in state is kept in your browser’s local storage.
4. Information processed automatically
Like any web service, the servers that deliver the app and store backups process basic connection data — IP address, browser type, and request logs — as part of serving and securing the service.
When you first sign in, Cloudflare Turnstile may run to distinguish people from scripted abuse; it processes signals from your browser for that purpose and stays invisible unless Cloudflare decides an interaction is needed. The app contains no third-party advertising or analytics trackers, and no advertising cookies.
5. Where your data lives
The device copy. The working copy of your data lives in a database inside your browser. Calculations run there too — projections, simulations, and optimizations are computed on your machine, and the cloud is never asked to run them.
The cloud copy. As you work, the app automatically backs each plan up to your account in our cloud database, shortly after you make changes. Access rules on that database restrict every stored plan to the account that created it — they are what keeps one person’s data separate from another’s. Data travels between your browser and the database over HTTPS.
The backup exists so that a cleared cache, a failed disk, or a new computer does not mean starting over. It is a copy of your plan data, under your account, deletable by you (section 8).
6. How your information is used
Your information is used to operate the service for you: storing and restoring your plans, syncing them between your devices, signing you in, protecting the service from abuse, and diagnosing problems. That is the whole list. Your financial data is not used for advertising, is not shared with data brokers, and is not sold — we do not sell your personal information.
7. Service providers
The service runs on infrastructure operated by a small number of providers, each processing data only to provide their function:
- Supabase — hosts the cloud database that stores plan backups, and provides authentication (the anonymous accounts and Google sign-in records).
- Google— only if you choose Google sign-in; Google’s own terms govern the sign-in step itself.
- Cloudflare — provides the Turnstile bot-protection check at sign-in.
- Vercel — hosts and serves the application and this website.
No other third parties receive your data in the ordinary operation of the service. If the law compels disclosure, we would disclose only what is legally required.
8. Retention and deletion
Your data is kept for as long as you use the service. Deletion is in your hands:
- Delete all data. The in-app control (Profile → Danger zone) permanently removes every plan from this device and from cloud storage. The cloud copy is deleted first, so a later sync cannot resurrect it. This cannot be undone — export first if you want a copy.
- Account record. Deleting the sign-in identity itself is not yet self-serve; until it is, “Delete all data” removes everything the service stores about your finances, and you can request removal of the account record through the contact below.
- Abandoned anonymous backups. If you never connect a sign-in, your backup is reachable only from the browser that created it. Clearing that browser’s storage orphans the backup, and backups belonging to anonymous accounts that show no activity for an extended period may be deleted.
9. Your choices and rights
- See and correct. Everything the service stores about your finances is visible and editable inside the app — there is no hidden profile.
- Export. You can export your plan data from the app as a file you keep.
- Delete. The control described in section 8.
Depending on where you live, you may also have legal rights to access, correct, delete, or port personal data, to object to certain processing, and to complain to a data-protection regulator. The in-app controls satisfy most of these directly; for anything they do not cover, use the contact below.
10. Children
The service is a retirement-planning tool for adults and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and it will be deleted.
11. Security
Plan backups are isolated per account by database access rules; data travels over HTTPS; our providers apply their own safeguards to the infrastructure they run. No online service can promise perfect security, so two things stay in your hands: keep control of any sign-in account you connect and of the devices you use, and use the delete control whenever you want stored data gone.
12. Where the service operates
The service is operated from the United States, and our providers store and process data in the United States. If you use the service from elsewhere, your information will be transferred to and processed there.
13. Changes to this policy
This policy will change as the service does — for example, if a new provider is added or a new storage feature ships. The “Last updated” date above changes whenever the policy does, and material changes will be noted visibly on this site.
14. Contact
[ contact address for privacy questions and requests — to be published before launch ]
See also the Terms of Use and the Disclaimer.