Device-only use is the default
The Wealth Level works without an account. Assessment answers, planning assumptions, calculator progress, and Cockpit checkpoints are saved in this browser so you can return without starting over. Device-only data is not synchronized to The Wealth Level and will not appear on another device.
Optional Cockpit accounts
If you choose to create an account, we collect your email address and use a one-time email code to authenticate you. Finishing sign-in turns on optional sync, and the account may store your Wealth Level assessment answers, planning assumptions, tool progress, and recorded Cockpit checkpoints so those items can continue across your devices.
Do not enter bank-login credentials, financial-account numbers, or Social Security numbers. The Cockpit does not request or need them, and they are not categories the sync feature is designed to collect.
Contact information
We collect information you voluntarily provide through email or the contact form, including your name, email address, subject, and message. Contact submissions are separate from Cockpit account data.
How information is used
Device-only information restores progress and carries relevant numbers between tools in this browser. Optional account information authenticates you, saves the Cockpit copy you choose, synchronizes later changes when My Cockpit is opened on a signed-in device, responds to account requests, and helps protect and operate the service. Contact information is used to respond to messages and send delivery confirmations. Limited pageview and product-event counts help evaluate whether the status check, My Cockpit, and pilot-retirement guides are useful and reliable.
Service providers
Vercel provides website hosting, server functions, and Web Analytics. Supabase provides optional account authentication and database storage. Resend delivers one-time sign-in codes and other required service emails. These providers may process the account, Cockpit, contact, analytics, and technical request information needed to perform those services under their own security, retention, and privacy practices.
Essential storage, logs, and analytics
The site uses browser storage and, when you sign in, essential authentication credentials to keep the service working. Across the status check, My Cockpit, and airline-pilot retirement guides, Vercel Web Analytics measures pageviews and seven tightly scoped product events: status-check completion, whether Cockpit opened with a verified status, the ordinal position of a Flight Plan move opened, a newly recorded checkpoint, a coarse pilot-guide distribution channel from a fixed allowlist, movement from a pilot guide into a calculator or core planning tool, and a yes-or-not-yet usefulness response. The analytics client removes URL query strings and fragments. A pilot-guide channel event sends only an allowlisted category—not the query string or a person-level code. Analytics does not send assessment answers, Wealth Level, constraints, calculator values, balances, income, age, email addresses, free text, exported data, or sync payloads. Vercel and other infrastructure providers may still process limited technical request information, such as request time, browser information, and network address. The Wealth Level does not run advertising trackers or sell data for advertising.
Retention
Device-only data remains until you clear it, clear browser storage, or lose access to that browser or device. Synced Cockpit data and the account email remain while the account is active and are deleted when account deletion completes, subject to limited provider backup, security-log, fraud-prevention, or legal retention periods. Analytics and technical logs may be retained for limited periods under the relevant provider's practices. Contact messages may be retained as reasonably needed to respond, maintain records, and address legal or security issues.
Your choices and deletion
You may use the site without an account, block analytics requests through browser controls without disabling the core tools, download an unencrypted copy of Cockpit data, clear saved browser data, sign out, or delete the account and synced data from My Cockpit. Signing out hides the account workspace on that browser and returns to any device-only work saved before sign-in; the synced account copy remains. Clearing saved browser data removes local work, cached account work, and local sign-in access, but it does not delete the synced account copy. Deleting the account removes the login and synced Cockpit data after the request succeeds and keeps the current Cockpit as a device-only copy; it does not delete contact messages or provider analytics records. Account deletion is not reversible.
Data security
Reasonable administrative, technical, and service-provider safeguards are used. No browser, email system, database, transmission, or internet service can guarantee absolute security. Use an email account and devices you control, protect one-time codes, and avoid entering sensitive identifiers the Cockpit does not request.
Updates
This policy may be updated as the platform adds features. The effective date will change when material revisions are made.