privacy

Short, because there is little to confess.

Effective July 2026. If this policy changes, the date changes with it.

What this site collects

The calculator runs in your browser. The role, level, location, and money figures you type are used on your device to compute your results. Your money figures never leave your browser at all: not when you save your plan, not ever. Only the results they produced do.

If you ask us to send your plan, we store: your email address, the role, level, and location you entered, and the year your calculation produced. That record lives with Resend, our email provider and a sub-processor listed below. There is no other copy and no separate marketing database.

We use that record to send you the plan you asked for. If you tick the follow-up box, it also gives us your permission to email you a short series about growing income; leave it unticked and we send the plan and nothing else. The box is unticked by default, and nothing is inferred from your silence.

Basic, aggregate usage measurement (page views, approximate region) may be collected without building an advertising profile of you.

What this site never does

We do not sell your data to advertisers or share it with them, and we do not run advertising trackers on a page that asks you about your finances. If the business itself ever changes hands, the Terms of Service (Data, research, and business changes) say exactly what carries over and what a successor is bound to.

We never put your financial details or profile data in a URL or query string. (Sign-in and unsubscribe links carry a single-use token, which is how passwordless login works.)

We never ask for bank credentials, account numbers, or a linked account. Nothing here links to your bank. The product is manual by design.

Deletion

Your plan email carries a link that deletes the record we hold. It opens a page with one button; pressing it removes the record from our email provider. Deletion is real: the record is removed, not flagged, and not archived for a win-back campaign. Nothing survives it, because there was only ever the one record.

You can also write to privacy@ascenza.app and ask, and we will do the same thing by hand.

The app

This policy covers both this site and the Ascenza app at app.ascenza.app, including the numbers you enter there. The promise is the same in both places: your numbers are yours, nothing links to your accounts, and honesty is the strategy.

Questions and requests

Privacy questions, or a request about your data: privacy@ascenza.app. If this policy materially changes, we will notify you by email before the change takes effect, and the effective date above changes with it.

Sub-processors

Ascenza (the "controller") uses the third-party service providers below (our "sub-processors") to operate the app. Each processes personal data only on our instructions and under a data-processing agreement. We notify users of material changes to this list before a new sub-processor begins processing their data.

  • Supabase (hosted on AWS)

    Service: Primary database, authentication, storage
    Personal data: Account identity, career/financial profile, PII vault, consent records, coach memory, the full user record
    Region: US (AWS us-east-1)
    Their terms: supabase.com/privacy · supabase.com/legal/dpa
  • Anthropic

    Service: AI coach ("Coach Cal") responses
    Personal data: Coach conversation content, plus the financial context sent as prompt context. Not used to train models (commercial API default).
    Region: US
    Their terms: anthropic.com/legal/data-processing-addendum
  • Vercel

    Service: Application hosting / edge delivery
    Personal data: Request metadata, IP address, server logs
    Region: US / global edge
    Their terms: vercel.com/legal/privacy-policy · vercel.com/legal/dpa
  • Stripe

    Service: Payment processing + subscription billing
    Personal data: Name, email, payment card details, billing address, subscription status
    Region: US
    Their terms: stripe.com/privacy · stripe.com/legal/dpa
  • Sentry

    Service: Error and performance monitoring
    Personal data: Diagnostic/error data, IP address, limited session context
    Region: US
    Their terms: sentry.io/privacy · sentry.io/legal/dpa
  • PostHog

    Service: Product analytics
    Personal data: Product usage events, device/browser info, IP address
    Region: US Cloud
    Their terms: posthog.com/privacy · posthog.com/dpa
  • Resend

    Service: Transactional and notification email delivery (plan emails, weekly check-ins, ebook delivery), and the contact record behind the calculator plan email
    Personal data: Email address, email content, and for calculator leads the role, level and location you entered plus the year your calculation produced
    Region: US
    Their terms: resend.com/legal · resend.com/legal/dpa

Not a sub-processor (noted for diligence): Adzuna and the public grounding sources (BLS OEWS, O*NET, Census) are inbound-only public data feeds. Ascenza receives published salary/occupation data from them and sends them no user personal data, so they are data sources, not sub-processors.

Also not a sub-processor (noted for diligence): if you turn on browser push notifications, delivery runs through your browser vendor's push service (for example Apple, Google, or Mozilla). We hand that service an encrypted payload it cannot read, addressed to your own browser, so it acts as an encrypted relay: it can see that an encrypted message is being routed to your browser, but not what the message says. Because it cannot read the content and processes only routing data under its own terms, we treat it as a conduit rather than a sub-processor.