LifeInRealTerms

SECURITY

How your saved plan is protected

Figures entered in the free calculator stay in your browser. Saved plans are encrypted on your device before uploading. The server does not receive your account password or the private key needed to open the stored copy during normal use. Optional bank and broker connections work differently: reports you request pass through the server before reaching your browser.

The free calculator

The calculator on the home page works without an account. The amounts you enter are calculated on your device and are not sent to Life in Real Terms.

What happens when you save a plan

  1. Your browser creates a random private encryption key for your plan.
  2. The plan is encrypted before it is uploaded for storage.
  3. Your password protects the private key. The password itself is not sent to the server.
  4. The server stores your encrypted plan, an encrypted copy of its private key and the information needed to check a sign-in attempt.

When you log in, your browser uses your password to open the private key and then reads the plan on your device. The readable plan and its key remain in that browser tab while you use the account. Signing out removes the key from the tab after pending changes have been saved. The site also hides the information after 15 minutes without activity and asks for your password again. If there are unsaved changes, the browser keeps an encrypted copy in that tab so you can continue after signing in again. A failed connection does not leave the plan visible.

If you forget your password

Account creation does not ask you to download anything or save an extra code. After entering the plan, you can choose in Settings whether to create an emergency recovery code. This is optional and can be copied into a password manager.

If you create one, anyone who has the code and knows the account email could reset the password and open the financial plan, so do not share it. If you do not create one and later forget your password, Life in Real Terms cannot reopen the encrypted financial information. A normal email reset alone cannot decrypt it because the server does not hold the private encryption key.

Email verification in the current beta

The account created during installation is the single initial private beta account. Its email address is not verified because public registration and automated email are not active. Registration closes after that initial account is created. Before registration is opened to the public, new users will have to confirm that they control their email address. Email verification will confirm the address only; it will not give the server access to the financial plan.

What the server can see

The server necessarily sees the account email address, beta access status, account creation and access dates, the IP address used for a request, and the approximate size and update time of the encrypted plan. Hosting systems may record ordinary request information. If you use the optional market-data feature, the server also receives the ticker, ISIN or investment name used as a search term, plus the exchange identifier, confirmed quote unit, listing currency and main currency needed for that request. Automatic company-country identification receives the public company name, ticker or ISIN. It first checks a bundled GLEIF directory and reviewed issuer references on the server, and may send unresolved public identifiers to Wikidata. Automatic fund geography uses public fund identifiers and listing details to read supported issuer data from iShares/BlackRock, State Street or Vanguard. It keeps a shared cache of public listing, closing-price and geographic-reference data that is not linked to a user, quantity, institution or portfolio. If subscriptions are introduced later, the service will also need to store subscription and payment-status metadata.

Optional bank and broker connections

If you request an IB Flex report, the server receives your reporting token and Query ID, contacts Interactive Brokers, and passes the returned account report to your browser. Where bank connections are activated, Enable Banking handles authorization with your selected bank. The server exchanges the authorization response and retrieves the permitted bank account information. These reports can contain readable account identifiers, balances, holdings and transactions. You review imported financial changes before saving them in your encrypted plan.

Connection requests require a signed-in account. The connection code does not write plaintext access credentials or raw reports to the server database, server files or application logs. A remembered IB token is saved only with your explicit choice, inside the encrypted plan. Bank connection references are protected, bound to your account and saved inside that plan. Readable exports omit these credentials; password-protected backups can include them. Locking the plan or closing a connection dialog stops further polling and prevents an outstanding report from opening its review.

The connections request account information only. They do not collect your bank or broker password, place trades or initiate payments. Bank authentication happens with the bank and authorization provider. Their handling of your information is separate from the encryption of the plan saved here.

What stays encrypted on the server

Saving, synchronizing or opening a plan does not send its readable contents to the server. Its stored balances, quantities, purchase costs, transactions, debts, assumptions and scenarios remain encrypted in the database. Separate market lookups and reports requested through bank or broker connections expose the information described above while those requests are processed. The server does not need the plan's encryption key to retrieve a report you authorize.

Technical details

The important limitation

No conventional website can truthfully promise that its operator could never obtain readable data in every possible circumstance. Whoever controls the server also controls the JavaScript sent to the browser. A malicious or compromised future version of that code could capture a password or read a plan after the user opens it.

The current design protects financial information stored in the database and normal hosting backups. It does not protect an already open plan on an unlocked device, or against malware, a malicious browser extension, an undiscovered scripting flaw, deletion by the hosting operator or deliberately altered future code. Strong protection from the website operator itself would require an independently distributed and signed application, not only a web page.

Other safeguards

What you should do

Use a long, unique password and keep your browser and device updated. Account creation does not ask you to download or save anything extra. Settings later offers optional recovery and backup tools for people who want them; they are not part of the normal sign-up process. Treat any readable export as sensitive. External files linked from another service keep that service's own permissions and are not encrypted by Life in Real Terms.

Current status

The free calculator is available without an account. Saved plans are an invitation-only beta, and payment is not active. This page will be updated whenever the security model changes. Beta testers should keep an independent export.