Privacy policy

Last updated 4 October 2026

calcsheet is operated by Dataraft ([email protected]). This page says what the site collects, why, and who else handles it.

Without an account

Using a calculation needs no account and sets no cookie. The server logs each request: your IP address, the page asked for (including any values carried in its address), and the time. When a calculation refuses its inputs or fails, the values entered are logged too; they are engineering inputs rather than personal data. When you download a report, the calculation's inputs and its short hash are kept, with no link to you, so that the address printed on the report keeps working; the project fields you type into a report are not kept. Logs are used to keep the service running, to find faults and to enforce rate limits. Your IP address is also held briefly in memory to rate-limit requests.

The site loads one analytics script, Umami, from a server we run ourselves. It sets no cookie and stores nothing in your browser. Each time you open a page it sends that page's path and title, any campaign tags in the address you arrived by (but none of the values you enter), the path of the page on this site that linked you to it or the address of the outside site that did, your screen size and your browser's language. It also sends the name of a few things you do: calc-run when a calculation recomputes, calc-error when it refuses a value, calc-export when you create its PDF, print it or copy its link, signup and login when you create an account or sign in, and checkout-start and checkout-complete when you open or finish a checkout. A calculation event carries the calculation's short name (the one in its address) and, for an export, how it was exported; a checkout event carries the plan chosen; the sign-in events carry nothing. None of them carries the values you enter, your project fields, your name, your email or anything that identifies your account. From the request, the analytics server works out your browser, operating system, device type and rough location (country and, where it can tell, region and city). Umami does not store your IP address; it uses it, with your browser's user agent and a salt that changes every month, to compute a hash that tells one visitor's pages from another's. The site loads no advertising scripts and no third-party fonts or libraries. The one exception is the subscribe page, which loads Paddle's checkout script from Paddle so that you can pay; it runs on that page and nowhere else.

The server also keeps anonymous tallies of page views, recomputes, report downloads and checkouts, one row per event with the calculation's name and the time, so we can see which calculations are used. They hold no address, cookie or account, and are kept beside the account data.

With an account

Signing in uses Google. Google tells us an account identifier, your email address and whether Google has verified it, and offers your name and profile picture, which we do not use or keep. We keep you signed in with one cookie, calcsheet_session, which holds that identifier and is signed so it cannot be altered. A second cookie, calcsheet_oauth, exists only for the few minutes a sign-in takes. A third, calcsheet_event, is set for one minute after you sign in and holds only the word signup or login, so that the page you land on can send that event to analytics when analytics is on; the server never reads it. None of the three is used for advertising.

The first time you sign in we create an account record on our server. It holds the account identifier, your email address and the date you first signed in, and the cases you export: their inputs and title-block fields, so that Your reports can list them and hand the report back. The email address is updated if it has changed when you next sign in. The identifier recognises you when you return; the email address lets us find your account if you write to us about it. Signing out deletes the cookie; it does not delete the account record.

Payments

Payments are handled by Paddle.com as Merchant of Record. We never see or store your card details. When you subscribe, Paddle tells us about the subscription, and we keep with your account record its Paddle customer and subscription identifiers, its status and the end of its current billing period, which is what decides whether Pro is unlocked. When you buy a single report, we keep its Paddle transaction identifier, the calculation it is for and when you paid, which is what unlocks that report for a day. Paddle's privacy policy covers what it holds.

Who else handles data

  • Cloudflare, which carries traffic to the site.
  • Google, for sign-in.
  • Paddle, for payments.

We do not sell personal data or share it for advertising.

Keeping and deleting

Server logs are kept for 30 days. Account data is kept while you have an account. To see, correct or delete what we hold about you, write to [email protected].