Last updated: May 2026
Retirement Lab is an educational Monte Carlo simulation tool for retirement planning. This privacy policy explains what personal data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.
Google identity data: When you sign in with Google, we receive your name, email address, and profile photo. We use this solely to identify your account.
Scenario data: The financial inputs you provide (income, expenses, portfolio balances, tax settings) and the simulation results generated from them.
Session data: IP addresses and timestamps associated with your sessions, used for rate limiting and security.
Advertising measurement data: Page views and coarse conversion events, such as starting a scenario, viewing scenario detail, or starting checkout. We do not send your financial scenario inputs or simulation results to advertising platforms.
We process your data to provide the simulation service, including storing your scenarios so you can access and re-run them; improve the product with analytics; and use limited advertising measurement to understand whether paid campaigns bring relevant visitors to Retirement Lab.
Service emails — account verification, sign-in, billing receipts, and legal notices — are sent whenever needed to operate your account. These are not optional and are not covered by the preference below.
Product emails are a separate, optional category covering things like methodology changes that affect a plan you saved, or a new country added near one you explored. Product emails are opt-in: we do not send them unless you turn them on, and the one-time welcome email you get after signing up does not count toward this preference.
You can turn product emails on or off at any time from the "Product email updates" toggle in your account settings, or by using the one-click unsubscribe link included in every product email — no login required. Turning a preference off is recorded immediately and blocks further product emails on that topic until you opt back in.
We process your identity and scenario data based on your consent, given when you create an account and sign in. We process analytics data based on our legitimate interest in improving the product, balanced against minimal impact on your privacy. Advertising measurement is limited to page views and coarse conversion events, not your scenario inputs or simulation results.
Authenticated accounts: Your data is retained indefinitely until you request deletion.
Guest sessions: Guest session data is retained for 7 days and then automatically deleted. Non-identifying aggregate counts, such as anonymous retention and signup conversion totals, may be retained after deletion.
Analytics events: Raw Postgres analytics events linked to a user are retained for up to 90 days and then purged. Grafana and Sentry are non-canonical operational stores with shorter retention. Account deletion removes user-attributable analytics data from Postgres while preserving a non-identifying deletion marker.
Under the GDPR, you have the right to access, rectify, erase, and port your personal data. You can exercise these rights directly in the app:
You may also contact us by email at privacy@retirementlab.app to exercise any of these rights.
We do not sell your data to third parties. Your data is processed by the following service providers, acting as data processors on our behalf:
Retirement Lab can be connected to an MCP-capable client. Connector access is never anonymous: each call runs as your signed-in Retirement Lab account and can read or change only the data that account can already access.
OAuth (primary): Connecting a client opens a browser sign-in and asks you to approve access. Access and refresh tokens are opaque and stored only as hashes. You can disconnect a client at any time from the Connected apps screen in your account menu, which stops further access from that client.
API keys (advanced fallback): An API key is shown to you in cleartext once, when you issue it; the server stores only its SHA-256 hash. Rotating or revoking a key from the same account screen invalidates the previous value immediately.
Scenario data from connector calls: Simulation inputs and results created through the connector are stored under your account like any other scenario, and follow the retention terms above.
Connector analytics: Tool calls record an internal user id, the tool name, the result status, your tier, and a coarse authentication method. They do not store raw credentials, email addresses, prompt text, or your financial payloads.
Scenario sharing is off by default. A scenario becomes reachable outside your account when you create a share link yourself, when you ask the MCP connector to create one, or through the Reddit app flow described below.
Unlisted, not private: A share link points to an unlisted page — not searchable and not linked from anywhere on Retirement Lab — but anyone holding the link can view the shared scenario and its simulation results. Treat a share link as public.
Revoking a link: Deleting the share from your scenario list revokes the link and stops further access to that shared page.
Do not send a share link to anyone who is not meant to see the financial inputs and results it contains.
Retirement Lab publishes an optional app that redditors can invoke inside subreddits where a moderator has installed and enabled it. Retirement Lab is not affiliated with, sponsored by, or endorsed by Reddit, Inc.
Reddit metadata processed: the subreddit name, the Reddit post and comment identifiers of the invocation, and a one-way HMAC hash of the invoking Reddit account id. The raw Reddit account id, username, and the text of the invoking comment (or any other comment or post) are never stored.
Scenario inputs processed: the structured values given in the invocation itself — age, retirement age, portfolio balance, annual spending, and country/state — used only to run the requested hypothetical projection.
Retention: Reddit app request records are retained for a limited, configurable window (30 days by default) after the request reaches a final state, then deleted automatically. The underlying simulation result follows the same retention as any other simulation run.
Public visibility: a Reddit app reply is posted as an ordinary public Reddit comment, visible to anyone who can see that thread. If the subreddit's moderators have turned on optional result links, a reply may include a link to an unlisted (not searchable, not otherwise linked) Retirement Lab result page that anyone with the link can view.
To report an issue with a Reddit app reply or request deletion of Reddit app-related data, contact privacy@retirementlab.app.
For questions about this privacy policy or to exercise your data rights, contact the data controller at privacy@retirementlab.app.