Privacy Notice

This notice explains how Runway Plan processes personal information in Runway Retirement Planner.

Information we process

Guest quick-check inputs are calculated in your browser. If you choose to create an account, a pending scenario may remain in local storage for up to 24 hours while you confirm your address. We then process your name, email, password hash, security/session information, email-delivery status and the retirement scenario you choose to save.

Why we process it

We use this information to authenticate you, deliver transactional account email, calculate and restore your scenario, protect the service, respond to support requests and meet legal obligations. We do not sell personal information or use it for advertising.

Storage and processors

Account data is stored in PostgreSQL hosted in Google Cloud SQL in Johannesburg. Scenarios are additionally encrypted by the application with AES-256-GCM. Resend delivers transactional email. Google Cloud Logging and Error Reporting receive scrubbed technical errors without request headers, query strings, bodies, cookies, account email, passwords or scenario inputs.

Retention

Unverified accounts are removed after 24 hours. Verified account data remains until you delete it. Email-delivery events are retained for 30 days. Deletion removes live data immediately; encrypted operational backups expire under the documented backup schedule.

Your choices and rights

The account page lets you export or delete your data. You may also request access, correction, objection or deletion, or raise a privacy concern by emailing privacy@runwayplan.app. You may lodge a complaint with South Africa’s Information Regulator.

Security and incidents

We apply access controls, encryption, rate limits, secure sessions, monitoring and tested backups. No internet service can guarantee absolute security. Where required, affected people and the Information Regulator will be notified of a security compromise.

Contact

Service support: support@runwayplan.app.