Privacy & security
How we protect your data
We believe your financial data belongs to you. Because we do not link directly to your bank accounts, we take extra care to secure the information you enter manually.
Core protections
-
Financial data encrypted at rest
All sensitive personal and financial information—including your account names, balances, and budget figures—is encrypted at the database level using advanced field-level encryption with split credentialing. Even in the unlikely event of database access, your financial footprint remains completely unreadable.
-
Encrypted in transit
Your connection to the Retirement Planning Center uses HTTPS, so information sent between your browser and the site is encrypted in transit.
-
Secure authentication
Your password is protected using industry-standard cryptographic salting and hashing. We never store your actual password in plaintext, meaning no one—not even our development team—can see it.
-
Data minimization
We do not link to banks or brokerages, so we never collect login credentials for your financial institutions. Account identity is lean — username, email, and a password hash. Email addresses are encrypted at rest with a separate blind index for account recovery. The plan data you enter (accounts, balances, assumptions, and scenarios) is stored so the planner can run; that data is encrypted and scoped to your signed-in account.
Also in place
Additional safeguards
- No bank connection required. You enter balances yourself. We never ask for brokerage credentials or pull live account feeds.
- Your plan stays yours. Financial rows are scoped to your signed-in account. Other users cannot access your projections or assumptions.
- Session & form protections. Signed-in requests use CSRF tokens. Login and account actions are rate-limited to slow credential stuffing and abuse.
- Password resets invalidate old sessions. After a password change, other reset tokens for your account are cleared and existing sessions are bumped so stale logins cannot linger.
-
First-party product analytics cookie.
We set a random visitor ID cookie (
rpc_vid, HttpOnly, SameSite=Lax, lasting up to one year) so we can measure whether people reach registration, complete a baseline plan, and use analysis tools. It is not your email, name, IP address, or any financial figure. After you create an account, future events may be linked to your internal user ID so we can see anonymous-to-registered conversion. We do not put account balances, income, Social Security amounts, spending, names, or emails into analytics events. Raw analytics events are retained for about 18 months, then deleted. If an account is deleted, we unlink its user ID from analytics rows (events are kept only as anonymous aggregates).
What this page is
These protections are designed to keep your entered plan data confidential and your account hard to abuse. No online service can promise absolute security. Use a unique password, keep your login private, and treat projections as educational what-ifs—not advice.