We couldn't load region settings for US, so amounts and retirement rules on this page are showing US defaults.

Our Privacy Promise

Your financial data is personal. We treat it that way.

"We don't need your sensitive data. We explicitly tell you: don't enter SSNs, account numbers, or bank passwords. Broad strokes are all the math requires. We'll never ask for more because we don't need more."

"No ad network. No third-party analytics. No data brokers. We do count whether setup actually works — on our own servers, with no outside company involved. Your trust is what sustains us."

"Your data is always exportable. If we ever shut down, you leave with everything."

What we store

Only what is necessary to make Enuf work for you:

  • Email address (for login and account recovery)
  • Hashed password (we never see your actual password)
  • Financial-plan inputs (approximate balances, income, spending, goals, and assumptions)
  • Simulation results and plan checkpoints
  • Chat history (your conversations with the AI advisor)
  • Monthly check-ins and streak
  • Subscription status and account preferences
  • Which setup steps you reached, and browser errors (see “How we measure whether Enuf works” below)

What we DON'T store

We go out of our way to avoid collecting things we don't need:

  • Your real name — we never ask for it
  • Financial account numbers or transaction history
  • Social Security numbers or government IDs
  • Bank or brokerage passwords
  • Third-party analytics, advertising or cross-site tracking of any kind
  • The pages you visit anywhere else on the web
  • Data from any external financial account

How we measure whether Enuf works

We need to know whether people can actually finish setting up a plan, and whether the app is breaking in anyone's browser. So we count a short list of steps: the site opened, the setup sentence was started, it was submitted, the dashboard loaded, a result came back, an account was created, a plan was saved. We also record browser errors, so a blank screen reaches us instead of nobody.

These events go to our own servers and nowhere else — no Google Analytics, no PostHog, no Sentry, no advertising or cross-site tracking, and no cookies for any of it. The one exception is Cloudflare Web Analytics, which counts page views and page speed; Cloudflare already serves every page of this site, so no new company sees your visit, and it sets no cookies either.

What is never included: anything you typed, any of your figures, the page addresses you visit (we keep the section of Enuf you were in, never the full link), and any page you visit anywhere else. Timings are stored as ranges like “1–3 seconds”, not exact numbers. Error messages are stripped of anything that looks like an email address or a long number before they are saved.

Events carry a random identifier your browser generates for itself. If you are signed in, they also carry a one-way keyed hash of your account id — not your email, and not the account id itself. It is a different hash from the one used for plan storage, so the two cannot be matched up against each other.

We keep these events for 180 days and then delete them automatically, and they are erased with everything else if you delete your account. If your browser sends “Do Not Track” or Global Privacy Control, we send nothing at all — those are not binding on us everywhere, and we honour them anyway.

Third-party services

We use a small set of infrastructure services. Each has a narrow, specific purpose:

Cloudflare

Website, private simulation storage, page counts

Serves the web application and stores full simulation snapshots in a private R2 bucket. Snapshot keys use a one-way owner hash rather than your email. Cloudflare Web Analytics also counts page views, referrers and page-speed measurements — it sets no cookies, does no fingerprinting, and is not loaded at all if your browser sends Do Not Track or Global Privacy Control.

Fly.io

API and database hosting

Runs the Enuf API and private PostgreSQL database used for accounts, plans, chats, and check-ins.

SendGrid

Transactional email only

Used for account verification and password reset emails. We send only what you request – no marketing emails unless you opt in.

AI providers (Anthropic / OpenAI)

Chat intelligence only

When you use the chat, we send your messages and the plan figures they refer to (things like savings rate, target age and allocation) to the AI provider so it can reply. Your email and account identifiers are never attached. Please don’t type anything into the chat you wouldn’t want sent to a third party — whatever you write is forwarded as you wrote it. Conversations are not used to train models.

Account deletion

A couple of clicks in Settings. No emails to confirm and nothing to wait for — your account closes there and then, and you are signed out everywhere.

We then keep it recoverable for 30 days, so that a deletion you regret within the hour is not final; contact us inside that window and we can bring it back. After 30 days we erase your email, financial plans, simulations, check-ins, chat history and all associated data for good, and nothing can restore it. Before deleting, you can export everything in JSON format so you leave with your data.

Legal compliance

The human promise comes first, but we also meet the legal bar:

  • GDPR – Right to access, rectify, and erase your data. Data export available anytime.
  • CCPA – We do not sell personal information. Period. California residents can request full data disclosure at any time.
  • No data brokers – We have zero relationships with data aggregators, advertisers, or information resellers.

Questions about our privacy practices? Contact us at privacy@enuf.ai