Legal
Privacy Policy
Last updated: April 15, 2026
Overview
STWLTH LLC ("we", "our", "us") operates stwlth.com. We take your privacy seriously — it's not a feature, it's the foundation of how we build. This policy explains what data we collect, what we don't, and how we protect it.
What We Collect
- Account information: Email address and authentication data when you create an account. Managed by Clerk (clerk.dev). We support email/password and OAuth sign-in.
- Subscription data: Your subscription tier (Free, Premium, or Ultimate) and Stripe customer ID. Payment and billing information is processed entirely by Stripe — we never see or store your card details.
- Saved scenarios: Calculator inputs you explicitly choose to save. These are stored in our database (Supabase, PostgreSQL) and are accessible only to you via row-level security policies. We cannot see other users' scenarios.
- Analytics: We use cookieless, privacy-respecting analytics to understand how the product is used (page views, tool popularity). No personal data is collected, no tracking cookies are set, and no data is shared with advertising platforms.
What We Don't Collect
This is the part we care most about. We will never:
- Access your bank accounts or brokerage. There is no Plaid integration, no account linking, no screen scraping. We don't want your credentials and we don't need them. You type in your own numbers — we do the math.
- Sell or share your data. We don't sell your data to third parties. We don't share it for advertising. We don't use it for marketing profiles. Our only revenue is subscriptions.
- Track you with cookies. We don't use tracking cookies, advertising cookies, or third-party marketing pixels. Our analytics are cookieless by design.
- Store calculator inputs you don't save. If you use a calculator without saving, your inputs exist only in your browser and are discarded when you leave the page. Nothing is sent to our servers unless you click "Save."
Cookies
We use only strictly necessary cookies for authentication — keeping you signed in across page loads. These are session cookies managed by Clerk and are required for the app to function.
We do not use:
- Tracking cookies
- Advertising or retargeting cookies
- Third-party marketing pixels (Facebook, Google, etc.)
- Cross-site tracking of any kind
Because we only use strictly necessary cookies, no cookie consent banner is required under GDPR or ePrivacy regulations.
Third-Party Services
We use the following services to operate STWLTH:
- Clerk — authentication and user management. Privacy policy
- Stripe — payment processing. Handles all card details directly — we never see them. Privacy policy
- Supabase — database hosting (PostgreSQL with row-level security). Privacy policy
- Vercel — application hosting and CDN. Privacy policy
We do not use any advertising networks, data brokers, or analytics services that track individual users.
Data Security
- All data is encrypted in transit (TLS/HTTPS).
- Database access uses row-level security — you can only access your own data.
- Subscription management uses Stripe's admin client with the service role key, which bypasses RLS only for webhook-driven updates. Users cannot modify their own subscription status.
- We use the principle of least privilege for all service integrations.
- Authentication tokens are short-lived and managed by Clerk.
Data Retention
- Account data: Retained as long as your account is active. Deleted upon account deletion request.
- Saved scenarios: Retained until you delete them or request account deletion. You can delete individual scenarios at any time from within the app.
- Subscription events: Retained as an audit log for billing disputes. Deleted upon account deletion request.
- Unsaved calculator inputs: Never stored. Exist only in your browser session.
Your Rights
You can:
- Delete your saved scenarios at any time from within the app.
- Cancel your subscription via the Settings page (Stripe Customer Portal).
- Export your data by contacting us.
- Request complete deletion of your account and all associated data by contacting us.
We aim to fulfill all deletion and export requests within 30 days.
Children's Privacy
STWLTH is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We will not reduce your rights under this policy without your explicit consent.
Contact
Questions about this policy? Email us at privacy@stwlth.com