Privacy Policy
Effective date: June 28, 2026 — Last updated: June 28, 2026
1. Who We Are
FIREPath (“FIREPath,” “we,” “us,” or “our”) operates the website gofirepath.com and the FIREPath web application, a FIRE (Financial Independence, Retire Early) planning calculator.
Contact us for any privacy-related questions at: contact@gofirepath.com.
2. Information We Collect
2a. Account Information
When you create an account, we collect your email address and authentication credentials. Authentication is handled by Supabase (including Supabase Auth). You may also sign in via OAuth providers (such as Google), in which case we receive only the basic profile information those providers send us (typically name and email). Passwords are never stored by us in plain text; Supabase handles credential hashing.
2b. Saved Calculation Data
If you save FIRE calculations while logged in, we store the input parameters you provide (such as current savings, monthly contribution, target amount, and assumed return rates) and the resulting calculation outputs. This data is linked to your account and stored in our database (Supabase / PostgreSQL). Free accounts may save up to five calculations; premium accounts have unlimited saves.
2c. Payment and Subscription Information
If you subscribe to FIREPath Premium, payment processing is handled exclusively by Stripe. We do not store your credit card number, CVV, or full payment card details on our servers. Stripe provides us with a subscription status, a customer ID, and limited billing information (e.g., subscription plan, renewal date, last four digits of the card on file) necessary to manage your account. By subscribing, you also agree to Stripe's Privacy Policy.
2d. Usage and Analytics Data
We use Google Analytics 4 (GA4) to collect anonymized usage data, including pages visited, session duration, browser type, operating system, and approximate geographic location (country/region level). GA4 uses cookies to distinguish users. This data helps us understand how the calculator is used and improve the product. Analytics is only initialized after you give consent via the cookie banner on your first visit.
2e. Log Data
Our hosting provider (Vercel) automatically collects server logs including IP addresses, request timestamps, HTTP status codes, and referrer URLs. These logs are retained for a short period (typically 30 days) for security and debugging purposes and are not used for marketing.
2f. Locally Computed Data
All FIRE calculations you perform without saving are computed entirely in your browser. We do not transmit your unsaved calculation inputs to our servers.
3. What We Do Not Collect
- We do not collect your Social Security Number, government ID, or passport details.
- We do not collect precise geolocation.
- We do not collect sensitive financial account numbers (bank account numbers, brokerage login credentials, etc.). The numbers you enter into the FIRE calculator are assumptions you provide, not pulled from live financial accounts.
- We do not sell your personal data to third parties.
- We do not display advertising to premium (paid) subscribers. Free users may see display ads served by Google AdSense. Ad-related cookies are only loaded after you accept the cookie consent banner; if you decline, no advertising cookies are set. See Section 4c for details and opt-out options.
4. Cookies and Tracking Technologies
We use the following types of cookies and similar technologies:
4a. Strictly Necessary Cookies
These cookies are required for the site to function. They include session cookies set by Supabase to keep you authenticated. These cannot be disabled without breaking core functionality.
4b. Analytics Cookies (Non-Essential — Consent Required)
Google Analytics 4 sets first-party cookies (such as _ga and_ga_*) to measure user behavior. These are only set after you accept cookies via our consent banner. You may withdraw consent at any time by clearing your browser cookies or adjusting your preference in our cookie settings.
4c. Advertising Cookies (Non-Essential — Consent Required)
Free (non-premium) users may see display advertisements served by Google AdSense, a third-party advertising network operated by Google LLC. Google AdSense uses cookies and similar tracking technologies to serve ads that may be personalized to your interests based on your browsing activity. These cookies are set by Google, not by FIREPath.
Premium subscribers do not see ads, and no advertising cookies are loaded for their sessions.
Advertising cookies are consent-gated: they are only initialized after you accept our cookie consent banner. If you decline or have not yet responded, no advertising cookies are set during that visit.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, ad-personalization consent is additionally collected through a Google-certified Consent Management Platform (CMP) integrated with Google Consent Mode v2, consistent with Google's EU user consent policy. The CMP governs whether ads are personalized for those users, layered on top of the cookie banner that controls whether the AdSense script loads at all.
You can opt out of personalized advertising at any time:
- Google Ad Settings — control how Google uses your data to show you ads.
- www.aboutads.info/choices — opt out of interest-based advertising from participating companies.
4d. How to Manage Cookies
You can control cookies through your browser settings or by clicking “Decline” in our cookie consent banner. Note that disabling strictly necessary cookies will prevent you from signing in. For Google Analytics specifically, you may also use the Google Analytics Opt-out Browser Add-on.
5. How We Use Your Information
- To provide and maintain the FIREPath service and your account.
- To save and retrieve your FIRE calculations on your behalf.
- To process subscription payments and manage your premium access via Stripe.
- To analyze aggregate usage patterns (via GA4, with consent) to improve the calculator and user experience.
- To display advertisements to free users via Google AdSense (with your consent, and only for non-premium accounts).
- To respond to your support inquiries and communications.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
6. Affiliate Links Disclosure
FIREPath may include affiliate links to third-party financial products, services, or tools. If you click an affiliate link and make a purchase or open an account, we may receive a commission at no additional cost to you. Affiliate relationships do not influence the objectivity of our educational content or calculator methodology. We only link to services we believe are relevant to FIRE planning.
7. Important Financial Disclaimer
FIREPath is a financial planning tool for educational and informational purposes only. The calculations, projections, and estimates it provides are based on simplified mathematical models and assumptions you enter. They do not constitute financial advice, investment advice, tax advice, or legal advice. Results are not guarantees of future performance. Past market performance does not predict future results. Real investment returns vary and may be lower or higher than the rates you assume. Always consult a qualified financial advisor, tax professional, or attorney before making significant financial decisions.
8. Sharing Your Information
We share your personal data only in the following circumstances:
- Supabase: Our database and authentication provider. Supabase processes your email and stored calculations on our behalf under a data processing agreement.
- Stripe:Our payment processor for premium subscriptions. Stripe processes payment data under Stripe's own privacy policy.
- Google Analytics: Anonymous usage statistics, sent only with your consent.
- Google AdSense:Third-party display advertising for free users only. Google may set advertising cookies and receive page-level data (such as the page URL and a pseudonymous identifier) to serve and measure ads. This occurs only after you accept our cookie consent banner. Premium subscribers are excluded. Google's use of data is governed by Google's Privacy Policy.
- Vercel: Our hosting provider, which processes server request data necessary to deliver the service.
- Legal requirements: We may disclose information if required by applicable law, court order, or government authority.
- Business transfer: If FIREPath is acquired or merges with another entity, your data may transfer as part of that transaction, subject to the same privacy protections.
We do not sell, rent, or trade your personal information to third parties for money. When advertising is enabled, our use of Google AdSense to serve personalized ads may qualify as "sharing" for cross-context behavioral advertising under California law (see Section 10b); you can opt out by declining cookies in our consent banner. We never share the financial figures you enter into the calculator, or your saved calculations, with advertisers.
9. Data Retention
- Account data: Retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.
- Saved calculations: Retained while your account is active and deleted with your account.
- Billing records: Retained for up to 7 years as required for tax and accounting compliance.
- Server logs: Typically retained for 30 days.
- Analytics data:Subject to Google Analytics' retention settings, which we configure for 14 months.
10. Your Rights
10a. GDPR Rights (EEA and UK Residents)
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Restriction: Request that we restrict processing of your data.
- Data portability: Receive your data in a structured, machine-readable format.
- Object: Object to processing based on legitimate interests.
- Withdraw consent: If processing is based on consent (e.g., analytics or advertising cookies), you may withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: You have the right to complain to your local data protection authority.
Our legal basis for processing your data: account data is processed for contract performance; analytics and advertising cookies are processed on the basis of consent; server logs are processed for legitimate interests (security and abuse prevention).
10b. CCPA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing:We do not sell personal information for money. Free users who have accepted cookies may have data shared with Google AdSense for interest-based advertising, which may constitute “sharing” for cross-context behavioral advertising under the CPRA. You may opt out via Google Ad Settings or www.aboutads.info/choices, or by declining the cookie consent banner (which prevents the AdSense script from loading). Premium subscribers are never shown ads.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise any of these rights, contact us at contact@gofirepath.com. We will respond within 45 days.
11. Children's Privacy
FIREPath is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe we have inadvertently collected information from a child, please contact us at contact@gofirepath.com and we will promptly delete it.
12. Security
We implement industry-standard security measures including HTTPS encryption for all data in transit, row-level security policies in our database, and authentication managed by Supabase. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
13. International Data Transfers
Your data may be processed in the United States and other countries where our service providers (Supabase, Stripe, Google, Vercel) operate. If you are located in the EEA or UK, we rely on our service providers' Standard Contractual Clauses or other approved transfer mechanisms to ensure your data is protected.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date. For material changes, we will notify registered users via email. Your continued use of FIREPath after the effective date constitutes acceptance of the revised policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
FIREPath
Email: contact@gofirepath.com
Website: gofirepath.com
See also: Terms of Service