Privacy Policy
The one-sentence version: PropSurvival runs entirely in your browser — your trade data, inputs, and simulation results are never transmitted to us or anyone else, because there is no server capable of receiving them. The requests that leave your device are the optional and infrastructural ones described in §3 — none of which carries your trading data.
1. What this product is, architecturally
PropSurvival is a client-side web application. The engine is a self-contained page: every calculation, every CSV parse, every chart, and every PDF report is produced by code executing on your device. We operate no application backend, no database of user data, and no account system.
2. Data we do NOT collect
- Your trade history or CSV files — parsed locally, and saved (if at all) only in your browser's own storage on your device.
- Your simulation inputs and results — same local storage, same device.
- Your name, email, or identity — the engine has no signup.
You can verify all of this yourself: open the platform, disconnect from the internet, and use it. Everything works, because nothing depends on a network.
3. The requests that do leave your device
None of the following carry your trades, inputs, or results. Each is either something you opt into or a standard part of loading any web page.
3.1 Licence activation and revalidation
If you activate a paid licence, your browser sends the licence key — and only the licence key plus a generated device label — directly to our checkout provider's licence API to confirm the key is valid. This request never touches a PropSurvival server. The result is stored on your device, in your browser's own storage. Validation repeats in the background when you open the app, if you are online — the same minimal call, carrying only the key. If you never buy a tier there is no key to activate, so this call never happens at all — and it is the only outbound call the engine itself is capable of making unprompted.
3.2 Web fonts
None are fetched from anyone. Every typeface this product uses is served from this site itself (/fonts/), so no third-party font host — Google or otherwise — receives a request, an IP address, or anything else when a page loads. Everything else, including the charting code, is bundled into the page and loads from no third party. You can confirm the whole claim in about four seconds: disconnect from the internet, then run a full analysis — every calculation, chart and PDF still resolves.
3.3 Rule-change alerts (opt-in only)
If you choose to enter your email address into the "rule-change alerts" form, three things are sent to our newsletter provider (Buttondown): that address; a one-word tag naming the firm preset selected at the moment you pressed subscribe (or general if none was), so the alerts can be about the firm you were actually reading; and a fixed value, embed=1, that Buttondown's own subscribe endpoint requires on every submission to recognize it as coming from an embedded form — a constant their API demands, not data about you or your device. Nothing else goes: no simulation data, no trade history, no balances, no results, no name. You can unsubscribe with one click in any email, and never entering an address changes nothing about the product: the engine is fully functional without it.
The pricing page carried a second form like this one until checkout opened in 2026-08, when it was deleted rather than left standing — every tier on sale there became a plain buy link. A capture returned to that page on 2026-08-04, for one card only: see §3.6.
One honest detail about the alerts form: it is submitted in a mode that returns no readable response, so the page cannot confirm delivery — and it does not pretend to. It tells you exactly that, so an address can never look accepted and be silently lost.
3.4 Outbound links on the reading pages
Some articles carry "share this" links to X and Reddit. These are ordinary links: nothing is requested from either site while you read, and no script from either site runs on our pages. A request reaches them only if you click, at which point you are on their site under their policy — and what travels is the page address and a title we compose, never anything from the engine.
3.5 Checkout (only if you buy)
Checkout is open. Clicking a buy button on the pricing page navigates you to that tier's own product page at Gumroad (propsurvival.gumroad.com), our merchant of record. That is a navigation, not a data transfer from the engine: the engine sends nothing, the link carries nothing about you, and nothing is requested from Gumroad until you click. Until then, no request reaches them at all — there is no embedded checkout script, no button pixel and no prefetch on this site. What happens once you are on their page is covered by §4 and by their own policy.
3.6 Personal Case File — corrected, 2026-08-05
The Personal Case File went on sale on 2026-08-05. Its card on the pricing page is now a buy button like every other paid tier's, covered by §3.5, not the "Tell me when it opens" email field this section used to describe: clicking it navigates you to that tier's own product page at Gumroad, and nothing is sent from this site before you click. The notify-me form is retired — it no longer exists on the page, and no address typed into a since-removed field is retained or used for anything.
3.7 First-party UI counts (no Worker, no third party)
The app records which tabs and which named buttons were used in a session, so we can see which parts of the product people actually open. On leaving the page, the browser requests a handful of tiny files on this same site (/e/t/…, /e/b/…, /e/q/…) — one request per used control. Those files are static assets: they do not run our Worker, they do not go to Google or any other analytics company, and they do not carry your trades, inputs, results, or licence key. Names that look like a licence key are dropped before the request is made. Query names such as firm or src may be counted as present in these /e/ requests; for src and utm_* only, a short sanitized value may also ride as a v= query parameter on the same static request (so calculator landings that never hit the Worker still show which channel named them). Anything shaped like a licence or secret is still dropped. (The separate server-side page measurement described in §3.8 also records source and campaign values on Worker-served pages.) You can block it the same way you block any other request this site makes — it changes nothing about the engine.
3.8 An anonymous count of which pages open (no cookie, no profile, no way to know it's you)
So we can see which pages people find useful, and roughly where visitors arrive from, and improve the ones that matter, our own site keeps a light, anonymous count when a page opens. It sets no cookie, no tracking pixel and no identifier of any kind — so there is no profile, we cannot tell one visitor from another, and we cannot follow anyone from one visit to the next. It stays entirely on our own systems: nothing is handed to Google or to any other analytics company.
What that count can note is deliberately small: which page opened (and, if a link pointed at a particular firm or plan, which one); if you arrived through a campaign or a shared link, the plain source it names — a search engine, a newsletter, a community — and the domain, only the domain, of the site you came from; your country; and the ordinary technical details any browser sends with a request. What it never touches: your IP address, a device fingerprint, any cookie or visitor ID, and — as everywhere on this site — your trades, your inputs, your results, or your licence key. Anything shaped like a key is dropped before it is ever written down.
Because there is no identifier at all, this can only ever be a tally — "a page opened; a visit came from that source" — never a record about a person, and we could not connect it to you even if we tried. It is kept only as anonymous, aggregated counts. You can block it exactly as you block anything else this site loads, and either way it changes nothing about the engine.
4. Payments
Purchases are processed by Gumroad as merchant of record. They collect and process your payment details, billing address, and email under their own privacy policy and handle applicable VAT/sales tax. We receive the order metadata needed to support you (e.g., that a license key was issued) — never your card details.
5. Cookies and local storage
The engine uses your browser's own storage on your device — not cookies — to save your inputs, saved strategies, and license state. It may ask the browser to keep this data persistent, but the browser can decline; either way, clearing your browser storage for this site removes all of it permanently. We cannot recover it, because we never had it.
Because that storage belongs to your browser rather than to us, a few consequences follow. We would rather state them than have you discover them:
- Nothing is synced between devices. A licence covers 2 devices, but your data does not travel with it — each browser holds its own copy.
- Clearing site data, or using a private window, deletes it, and we cannot restore it.
- Safari may evict site storage after a period of inactivity under its own storage policy, which is not something we control.
- The in-app export is your backup. It writes your data to a file you keep, and it is the only safety net there is — the alternative would be us holding a copy, which is exactly what this product is built not to do.
The same commitments are stated in §7 of the Terms; if the two ever disagree, that is a defect — please tell us.
6. Your rights (GDPR / CCPA)
Access, rectification, erasure, and portability rights apply to personal data a controller holds. Our position is simple: for the engine, we hold none. For purchase records, contact our checkout provider or email us and we will assist. To erase local data, clear this site's browser storage.
7. Children
This product is intended for adults and is not directed at anyone under 18.
8. Changes
Material changes to this policy will be dated at the top of this page. The architecture commitment — computation on your device — is the product's core design; a change to that would be a different product, announced loudly, not a quiet policy edit.
9. Contact
Privacy questions: support@propsurvival.com