Privacy by design
Your finances are not content.
The calculator and verdict run locally. Your answers are not uploaded merely because you use it or change an assumption.
Public sharing
Only the derived fields you select are sent: for example, verdict, cost per use, or life-hours. Raw salary, savings, spending, debt and goal contributions are rejected by the server’s public-share validator.
Private sharing
The complete decision is encrypted in your browser with AES-256-GCM. The server stores ciphertext, never the decryption key. The key appears after the # in the link, a URL fragment browsers do not send in HTTP requests.
Expiry and deletion
Shared decisions expire automatically after 30 days. A separate high-entropy deletion token is retained in your browser so the share can be revoked without an account.
Analytics boundary
MadeLogical records five anonymous funnel events so we can understand whether people start, finish and share the experience. A random identifier lasts only for the current browser tab; it is not an account, advertising identifier or cross-site cookie. Analytics records expire after 90 days.
- Only the event name, timestamp, per-tab identifier, public/private mode and selected public metric keys can be stored
- No item names, verdicts, exact financial values, share IDs or page URLs
- No encrypted keys, URL fragments, keystroke recording or session replay