Legal

Privacy Policy

Effective 22 September 2026. Revision 3: sections 1, 5, 6 and 10 rewritten after loading every page and recording what it actually requests. Adds Paddle Retain (ProfitWell), names the Cloudflare host the measurement script is served from, and states which third parties load on which page, the planner included. Revision 4, 22 September: corrects section 1 on what Paddle tells us, and sections 2 and 5 on where household figures can be entered — the quick calculator accepts them too, and saying otherwise understated it. Revision 5, same day: section 3 separates the paystub file, what is read off it, and the figures you apply, and says which of the three is saved. Revision 6, 23 September: section 5 describes the one request the unlocked planner makes to our own site, to download the list of withdrawn keys, and why that list is sent whole. Revision 7, 24 September: section 9 no longer says nothing is transmitted without naming that request, and section 10 stops describing the ended beta’s cookie in the present tense.

The Housing Model at thehousingmodel.com and plan.thehousingmodel.com is operated by Brooks Digital Ventures LLC, a New Jersey limited liability company. The website and the free calculator are at thehousingmodel.com; the planner application, where household figures are entered and saved plans are stored, is at plan.thehousingmodel.com. This policy covers both.

Your household inputs, calculations, saved plans, and any paystub image you select stay in your browser. We do not receive them. There is no account and no server-side database of household information. This is not a promise about how carefully we handle your data — it is a description of software that never sends it anywhere. The planner is open to anyone and needs no code. The private beta, and the record it left, are described in section 14; the code controlled who could open the planner and had nothing to do with what anyone entered once inside.

On this page

  1. The short version
  2. What you enter
  3. Paystub images
  4. Saved plans and browser storage
  5. Hosting and external assets
  6. Measurement
  7. Cookies
  8. Optional email signup
  9. Licence keys
  10. Purchases
  11. Children
  12. Your choices and requests
  13. Policy changes
  14. Private beta access

1  The short version

Four different things can be called “your data” here, and they are governed by four different answers. Conflating them is how a privacy policy ends up technically true and actually misleading, so they are kept apart throughout this document.

1. What you enter. Income, debts, childcare, balances, a paystub image, the projections computed from them, and every plan you save. This never leaves your browser. We do not receive it, we could not produce it if asked, and there is no account or server-side database that holds it. Sections 2, 3 and 4.

2. What any web request reveals. Loading a page from us means your browser connects to the companies that host and serve it, and they see your IP address and the usual connection details, as they would for any website. We do not control that and neither does any website. What those requests do not carry is category 1. Section 5 names every company involved and which page each one is on.

3. What we deliberately count. Page views, through Cloudflare Web Analytics, which sets no cookies and does not identify you. That is the entire list. While the private beta ran, we also recorded that an access code had been used; section 14 says what that record contains. Sections 6 and 14.

4. What you choose to hand over. An email address, if you submit the optional signup form. Your payment details, if you buy, which go to Paddle and never to us — though Paddle does tell us that a purchase was made and the email address you bought with, because that is how your licence key reaches you. Neither is required to use the calculator or the planner. Sections 8 and 10.

Category 1 is the one that matters most and it is the one we designed hardest around: it is not a promise to handle your figures carefully, it is software that never sends them anywhere.

2  What you enter

Household figures can be entered in two places: the quick calculator at thehousingmodel.com and the planner at plan.thehousingmodel.com. A paystub is only ever read in the planner. Both process income, debts, childcare costs, and every other input entirely within your browser. Your financial inputs and calculated projections are not sent to us, or to our hosting, font, measurement, or chart-library providers.

3  Paystub images

If you select a paycheck stub, it is read in your browser and is never uploaded to us or to an external processing service. Three things are worth keeping apart. The file itself is never written into your saved plan and is discarded when you finish with the importer. What was read off it automatically is discarded with it. The figures you review and apply become part of your plan, and are stored in your browser with it exactly as they would be had you typed them.

A text-based PDF can be read automatically. A scan or a photograph cannot, in this version: it is displayed to you and the figures are typed in by hand. Nothing is sent anywhere to read it either way.

Clearing website storage does not delete the original image file from your device. You control that file separately.

4  Saved plans and browser storage

Saved plans use localStorage in your browser on your device. Local storage is not a cookie, and it may remain after you close the page or restart the browser. It is not an account or a backup with us.

Someone with access to your browser profile may be able to open your saved plans. Take care on shared devices.

To delete saved plans, clear site data or local storage for plan.thehousingmodel.com in your browser settings. Browser storage is kept separately for each site, so clearing site data for thehousingmodel.com will not remove plans saved in the planner. Clearing browsing history alone may not do this. Repeat it on each device, browser, or profile where you saved plans. Clearing site data may also remove locally stored preferences, your age and Terms confirmation, or licence information, if present.

Your confirmation that you are 18 or older and accept the Terms is stored in the same way, in your own browser. It is a short record of the date you confirmed and which version of the Terms you confirmed against. It is never sent to us, it contains nothing about your household, and clearing site data removes it — after which the planner asks again.

We cannot recover or remotely delete plans we never received.

5  Hosting and external assets

Cloudflare hosts and delivers both thehousingmodel.com and plan.thehousingmodel.com, including Cloudflare’s email-obfuscation script where that appears.

Beyond that, different pages load different third parties, so they are listed page by page rather than lumped together. This list was produced by loading each page and recording every request it made, not from memory of what the code should do.

The home page at thehousingmodel.com loads fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), the Cloudflare measurement script described in section 6, and Paddle’s checkout library from cdn.paddle.com. Paddle’s library in turn loads Paddle Retain from public.profitwell.com; both are described in section 10.

The calculator page loads Google Fonts, the Cloudflare measurement script, and a charting library from cdnjs.cloudflare.com, operated by Cloudflare. It does not load Paddle or Paddle Retain.

The legal pages, including this one, load Google Fonts and the Cloudflare measurement script, and nothing else.

The planner at plan.thehousingmodel.com — the only place a paystub is ever read, and where the detailed household figures are entered — contacts exactly one third party: the Cloudflare measurement script described in section 6. Nothing else. It serves its own fonts, requests none from Google, and carries no payment code, no advertising and no other analytics of any kind.

One request the planner makes to us. If you have unlocked it with a licence key, the planner downloads a short file from our own site listing the keys that have been withdrawn — keys belonging to purchases that were refunded. It is a plain list and we send all of it, every time, to every visitor. That is deliberate: asking us “has this key been withdrawn?” would tell us which key you hold, so the planner never asks that question. It downloads the whole list and compares against it on your device. The comparison uses a one-way fingerprint of your key computed in your browser; your key itself is not in the request and never reaches us. The request carries no household figure, no plan and no paystub, and it goes to our own site rather than to a third party. If it fails for any reason — you are offline, the file is unreachable — the planner carries on working; a key is never locked out because a check could not be made.

We test this rather than assert it. Before each release the planner is driven by an automated browser with a household made of numbers nobody would type by accident, every request it makes is recorded, and every URL, header and body is searched for those numbers. The measurement request is searched along with the rest. Finding one anywhere fails the release.

Last verified: 2026-09-24, against https://plan.thehousingmodel.com/plan. 29 requests were recorded and searched for 7 household values planted in the plan; none were found in any of them. Hosts contacted: https://plan.thehousingmodel.com, https://static.cloudflareinsights.com.

These providers receive your IP address as part of the network connection, as any web request does. The requests do not transmit your household inputs, saved plans, paystub images, or calculated results.

Cloudflare’s privacy information: cloudflare.com/privacypolicy
Google’s privacy information: policies.google.com/privacy

6  Measurement

We use Cloudflare Web Analytics to count page views and see which pages people visit. It runs on every page of the website and on the planner.

It works in two parts, and both are named here because naming one and not the other would understate it. A small script is fetched from static.cloudflareinsights.com, which is a Cloudflare host and not part of this site. That script then sends the measurement to /cdn-cgi/rum on whichever of our sites you are visiting. Cloudflare inserts this at its edge rather than it being written into our pages.

It sets no cookies, does not identify you, and does not follow you across other websites. It receives no part of your household inputs, saved plans, paystub images, or calculated results. We use it only to know how many people visit and which pages they reach. We do not use advertising or advertising trackers anywhere on either site.

What it can and cannot see on the planner. The planner is a single page: every step of the plan, every result and every panel happens at one address without the page ever changing. Web analytics counts pages. So what this records on the planner is that the planner was opened — not which step you reached, not what you entered, not whether you finished, and not what the model worked out. There is no mechanism here by which it could record those, and we have not added one.

7  Cookies

The website sets no first-party cookies, and neither does the planner. During the private beta, which has ended, the planner set exactly one: it recorded that you had entered a valid access code so you were not asked again on every page. That cookie held the code’s label and a signature proving the label had not been edited; it contained no household figures, no identifier for you, and nothing readable by any other site. Nothing now asks for a code, and nothing now sets a cookie.

Saved plans use local storage, as described in section 4, which is a different mechanism and is not affected by clearing that cookie.

This does not mean external providers never use cookies. The email signup service described below has its own practices, set out in its own notice.

8  Optional email signup

If you submit the optional signup form, your email address is sent to FormSubmit at formsubmit.co, which forwards it to our inbox. The email address is the only form field sent. The submission does not include household inputs, plans, or a paystub. As with any internet request, the receiving service also sees connection information such as an IP address.

We use a signup address to send educational housing content and product updates about The Housing Model. Signing up is optional, is not required to use the calculator or the planner, and gives us no access to your saved plans.

We keep a signup address until you ask us to stop. To unsubscribe, use the unsubscribe link in any message we send, or email hello@thehousingmodel.com and we will remove you. When you unsubscribe we remove the address from the active list and keep only a minimal record that you asked not to be emailed, used to honour that choice and for nothing else.

FormSubmit’s privacy notice: formsubmit.co/privacy.pdf

9  Licence keys

Licence keys are cryptographically signed and the signature is checked inside your browser. Your key is never transmitted to us or to anyone else, and neither is anything about your household. There is one related request, described in section 5: while you are online, the planner downloads the whole public list of withdrawn-key fingerprints and compares against it on your device. It asks us nothing about your key — it takes the entire list and does the checking here — so that request reveals neither which key you hold nor whether you hold one.

10  Purchases

Checkout is handled by Paddle, acting as the merchant of record for your purchase. Paddle collects the information it needs to process the payment and any applicable tax, under its own privacy notice. We do not receive or store your card details. Paddle tells us that a purchase was made and the email address you bought with, so that we can send you your licence key; the exact contracting Paddle entity is named on your receipt.

Paddle’s checkout library loads on the home page from the moment you open it, not at the moment you click to buy. Its purpose is to open the payment window when you ask for it. Until you do, it takes no payment details, and it has no access to anything you have entered anywhere — the planner is a different site, and your figures are not on the home page to begin with.

Paddle Retain (ProfitWell). Paddle’s library automatically loads a second Paddle service from public.profitwell.com. It is Paddle’s subscription-analytics and payment-recovery product, included in Paddle’s checkout by default rather than something we added or configured. It is covered by Paddle’s privacy notice, linked above. We disclose it because your browser requests it whether or not we chose it, and a policy that listed Paddle but not this would be describing our intentions instead of your browser’s behaviour.

Neither Paddle’s checkout nor Paddle Retain is loaded on the calculator page, on these legal pages, or on the planner at plan.thehousingmodel.com. No page that holds your household figures or a paystub carries payment code of any kind.

11  Children

The Housing Model is intended for adults aged 18 and over. It is not directed to children under 13, and we do not knowingly collect signup email addresses from children under 13.

If you believe a child under 13 submitted an address, contact hello@thehousingmodel.com so we can investigate and remove information we hold. We cannot identify or retrieve information entered only into a visitor’s own browser.

12  Your choices and requests

You can use the calculator and the planner without joining the email list and without selecting a paystub. You can delete locally saved plans through your browser settings, and you can ask us to remove signup information we hold, subject to the minimal do-not-email record described above.

Deleting browser storage does not delete an email address you already submitted through signup. Asking us to delete an email address does not clear the plans in your browser. Please do not send paystubs or household financial details with a privacy request — we do not need them, and we would rather not receive them.

We will handle requests about information we hold as applicable law requires.

13  Policy changes

We will update this policy when our practices change and show a new effective date. For materially different uses of personal information we will give appropriate notice, and obtain consent where it is required, before beginning the new use.

14  Private beta access

The private beta ended on 23 September 2026 and the planner is now open to anyone. While it ran, opening the planner required an access code that we handed out individually. Each code carried a short label so we could tell them apart — a first name, or a number.

When a code is used we record three things against that label: the first time it was used, the most recent time, and how many times. That is the whole record. We do not record your IP address, your browser, the page you came from, or anything at all about what you enter in the planner. The record exists so we know which invitations have been taken up.

Nothing in section 2, 3 or 4 changed during the beta. Household figures, saved plans and paystub images stayed in the browser exactly as described there, and the access code gave us no way to see them. What the record does show is that a labelled code was used, and how often. Because we handed each code to a particular person, we may be able to associate its label with that person. It tells us nothing whatever about their plan.

When the beta ends the codes stop working and the record is deleted. If you would like the entry for your code removed sooner, ask us at the address below.

Contact

Brooks Digital Ventures LLC — hello@thehousingmodel.com