Privacy Policy
Last updated: 4 September 2026
Manage Your Means is a personal-finance planning tool operated by Manage Your Means LLC. This policy explains what data the site holds, why it holds it, and what is done with it. In short: your financial data is yours, it is stored encrypted, it is never sold, and it is never shared with advertisers.
Trying the site without an account
You can explore the entire application in demo mode without registering. Demo mode
loads a fictional sample persona and stores everything in your own browser's localStorage.
That data never leaves your device and is never sent to the server. Turning demo mode off, or signing
in, clears it. The standalone calculators on the Tools page and the education pages likewise work
without an account and send nothing to the server.
What is collected when you have an account
- Account details — your email address and password (stored only as a salted hash, never in readable form), plus optional profile settings such as an alias, birth year, retirement age goal, risk profile, preferred currency, and notification preferences.
- Financial data you enter — income, expenses, liquid assets, investments, debts, savings goals, and the quarterly snapshots generated from them. This exists solely to produce the budgets, reports, and projections you asked for.
- Feedback you submit — the name or alias, subject, comments, optional email address, and the IP address the submission came from (kept to deter abuse of the form). All of it is encrypted at rest, and it is deleted after 12 months — see Retention and deletion below.
- Server logs — ordinary application logs for diagnosing errors and keeping the site running.
- Anonymous diagnostics — script errors and page-load performance from your browser, described in its own section below.
There is no advertising on this site and no third-party analytics or tracking. Nothing here is shared with an ad network, a data broker or an analytics company, and no cross-site tracking or profiling scripts of any kind load.
Diagnostics and performance data
So that broken pages and slow loads can be found and fixed, the site collects a small amount of anonymous, first-party diagnostic data in your browser and sends it to its own server — the same origin everything else talks to. None of it goes to a third party.
- Script errors — when something fails in the browser, the error message, a stack trace and your browser's user-agent string. Anything that looks like an email address or a long number is removed before it is sent, and again on the server; page addresses are reduced to the page name, with any query string dropped.
- A short trail of what led to an error — attached to a script error only, this is a list of the last few page names you moved between, the kind of element you clicked (its tag, such as "button", and its identifier in the page's code), and any request that failed, by address and status code. It records no text from the screen, no amounts and nothing you typed. There is no screen recording or session replay on this site, and none is planned.
- Page-load performance — standard web-performance measurements (how quickly the main content appears, how much the layout shifts, how responsive the page is) and a count of which pages are visited, by page name only.
No identifiers are attached, the request carries no cookies, and none of it can be tied back to you or your account. If your browser sends a Do Not Track or Global Privacy Control signal, the performance and page-visit measurements are switched off, along with the navigation and click part of the trail described above; genuine script errors are still reported, with failed requests still listed, because they carry no information about you and are what keeps the site working.
Script errors and their trails live in the site's operational monitoring for about 90 days and are then deleted. The performance measurements are kept longer — up to about 13 months — but only as counts: how many page loads fell into each speed range, per page name and day. Nothing in that record is about a person, and no individual measurement is kept.
Signing in with Microsoft
Signing in with a Microsoft account is optional. If you do, Manage Your Means just receives your email address and links it to your Manage Your Means account.
How your data is protected
- Sensitive fields — account names, balances, amounts, and similar values — are encrypted at rest in the database. The encryption keys are held in Azure Key Vault, separately from the data itself.
- All traffic to and from the site is encrypted in transit over HTTPS.
- Signing in sets a single, essential authentication cookie so the site knows who you are between requests. It is not used for tracking, and there are no advertising cookies. The anonymous diagnostics described above are sent without it.
- The site is hosted on Microsoft Azure. Microsoft processes data on the operator's behalf as the hosting provider.
What is never done with your data
- It is never sold, rented, or traded.
- It is never shared with advertisers or data brokers.
- It is not used to build a profile of you or to train any model.
Data may be disclosed only where the law genuinely requires it, or where it is strictly necessary to investigate abuse of the service.
Retention and deletion
Your data is kept for as long as your account exists. You can edit or delete any individual record from within the application at any time. A deleted record is hidden immediately and permanently removed from the database 30 days later — that window exists so an accidental deletion can still be recovered on request.
You can close your account yourself, at any time, from Preferences → Security settings → Delete account. Doing so erases your entire financial model — income, expenses, debts, investments, liquid assets, savings goals, Social Security entries, payment history and snapshots — along with any household sharing you had set up in either direction, any feedback you submitted from that email address, and the sign-in itself. That deletion is immediate and permanent: it does not wait for the 30-day window above, and there is no backup copy to restore from. Export your data first if you want to keep it.
Feedback submitted through the site is kept for 12 months and then deleted, whether or not anyone replied to it. If it is removed sooner from the admin view, it is erased from the database 30 days after that, the same window as any other deleted record. Feedback has no account attached to it — the form works without signing in — so this window is what bounds it. Closing your account also erases, immediately, any feedback you submitted from that account's email address.
Security and audit log entries are the one exception. They record actions — who signed in, who was granted access to whose data, when an account was closed — using account identifiers only, never amounts, names or descriptions, and they are retained separately from your financial data because one side of that record can belong to somebody else.
If anything above doesn't work for you, or you would like a copy of what is held about you, email support@manageyourmeans.com from your registered address.
Children
This site is not intended for use by children under 13, and accounts are not knowingly created for them.
Changes to this policy
If this policy changes materially, the date above will be updated. Continuing to use the site after a change means you accept the revised policy.
Contact
Questions about privacy, or a request to delete your data: support@manageyourmeans.com.
Manage Your Means LLC6545 Market Ave. North, Ste 100, Canton, Ohio 44721
See also the Terms of Use and the Disclaimer.