Skip to content
ThonRetire

What leaves your browser, named key by key

You can read this site without an account, and most of what it remembers about you never goes anywhere. Rather than describe categories of data, this page names every storage key we set. Open your browser’s developer tools and you can check the list against reality in about thirty seconds, which is the point of writing it this way.

The seven keys

KeyWhereWhat it holdsDoes it reach our server?
tfrThemelocalStorageLight or dark.Never.
tfrStagelocalStorageWhich life stage you picked — traditional, early or still-earning.Sent with usage events so we know which board is actually used.
tfrAgelocalStorageThe age you set on the ranking board. It changes the ranking, and it decides which insurance band is highlighted for you.Sent with usage events as a number. Not a birth date.
tfrMoneylocalStoragePension, assets, age and household size, if you use the money model.Never. See below — this one matters more than the rest put together.
tfrShortlistlocalStorageCountries you saved.Only if you sign in, and then only so the list follows you between devices.
tfrSidsessionStorageA random string generated in your browser, so a sequence of page views can be read as one visit.Yes, attached to usage events. It is not derived from anything about you and it dies when you close the tab.
tv_tokencookie + localStorageYour sign-in token, only if you have an account.Yes — it is what proves to the server that you are signed in.

No third-party analytics, no advertising network, no social-media pixels, no session recording. The usage events go to our own server and nowhere else. That is also why the list above is short enough to print in full.

Your retirement figures never leave your browser

If you use the money model, the pension and assets you type in are computed entirely in your browser and stored only in tfrMoney on your own device. They are not transmitted, not logged, and not visible to us — we could not produce them if asked, because we never receive them.

This is a deliberate architectural choice rather than a policy promise, and the difference matters: a promise can be quietly broken by a future release, whereas moving this calculation to a server would be a visible change to how the page works. If that ever happens, this paragraph changes first.

When you choose to send us something

Three features ask you for information, and all three are opt-in. If you tell us what you actually pay as a resident, or report that one of our figures is wrong, we keep what you submit and may publish it in aggregated form — never your email, and never anything that identifies you. If you subscribe to alerts for a country, we keep your email address for that purpose only, and it is deleted when you unsubscribe. If you create an account, we keep your email and what you have saved.

We do not sell any of it, we do not share it with insurers or any other commercial partner, and outbound links to third parties carry no identifying information about you — see paid links for how those work.

Asking us to delete it

Everything held in your browser is yours to clear at any time from your browser settings, and doing so removes it completely because there is no server-side copy. For anything you sent us — an account, an alert subscription, a resident contribution — write to us and we will delete it. Wherever the GDPR, the UK GDPR or a comparable law applies to you, the rights it gives you over that data are yours regardless of anything written on this page.

Related: paid links · how we treat AI crawlers · who makes this