Privacy Policy
Effective Date: June 1, 2026 · Last Reviewed: July 12, 2026
1. Introduction
Retire All Over (“we,” “us,” or “our”) operates this website and the Nomad Tools application at app.retireallover.com. This Privacy Policy explains what personal information we collect, how we use and protect it, your rights regarding your data, and how to contact us with questions.
This policy is designed to comply with applicable privacy laws including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable US state and international privacy regulations.
2. Information We Collect
Information You Provide
- Account information — email address and identity verified through Clerk, our authentication provider
- Financial data — account balances, transaction records, and subscription details you enter manually or import
- Linked institution data — account metadata and balances retrieved through Plaid when you choose to connect a bank or brokerage
- Travel data — trip itineraries, border crossing dates, location information you enter, and GPS check-ins you choose to save
- Documents — files you upload to the Vault (insurance cards, vaccine records, passport scans, etc.)
Information Collected Automatically
- Usage data — pages visited and features used within the application
- Authentication data — session tokens issued by Clerk to verify your identity
- Log data — server-side request logs retained for security and operational purposes
- Traffic analytics — Cloudflare Web Analytics receives page/referrer and browser, device, and network/request metadata to provide aggregate traffic measurements
Health-related information. Some features process health data you choose to enter — medications and prescription details, vaccination records, and related country legality/requirement lookups. We process this only when you enter/upload the data or invoke the relevant feature. The app does not currently present or record a separate health-data consent checkbox; applicable legal-basis and consent requirements must be resolved before offering processing where such a control is required. You can delete health records through the app, subject to the retention limitations below.
Optional offline storage. Paid-tier users can choose to cache selected read-only travel, health, and financial pages in the browser’s Cache Storage on that device. This general PWA cache excludes Vault, settings, admin/platform, API, and public-share responses. The cache is scoped to the signed-in user and household and remains on the device until cleared in Settings, sign-out cleanup succeeds, the browser evicts it, or the app replaces that cache version. Someone with access to an unlocked device/browser profile may be able to view cached pages.
Optional encrypted offline Vault. Separately, you may
explicitly sync a read-only snapshot and files from an online, unlocked Vault
to encrypted Cache Storage on this device. A random AES-256-GCM
data-encryption key encrypts the snapshot; that key is wrapped by a key
derived from a separate offline passphrase of at least 12 characters using
PBKDF2-SHA-256 with 600,000 iterations. The passphrase and unwrapped
encryption key are never persisted. The public, prerendered
/offline-vault screen decrypts content only in memory and
presents files through temporary blob URLs. Outside the encrypted content, the
cache stores an opaque SHA-256 scope token plus non-content key-wrapper/KDF
parameters and the configuration time. Each snapshot expires after 90 days.
While online or after reconnecting, an authenticated authorization check
purges local encrypted Vaults for household memberships that were removed,
deactivated, or are no longer entitled to offline Vault access. Sign-out and
manual clearing attempt local deletion, but a browser/storage failure can
prevent it; the browser may also evict the cache earlier. An offline device
cannot receive a remote erase or revocation until it reconnects, so clear
offline Vault data before relinquishing a device.
We do not knowingly collect personal information from children under 13. We use Cloudflare Web Analytics for aggregate traffic measurement, but do not use advertising trackers or sell data to any party.
3. How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the application and its features | Performance of contract |
| Authentication and account security | Legitimate interests / contract |
| Storing and retrieving your financial and travel data | Performance of contract |
| Security monitoring and abuse prevention | Legitimate interests / legal obligation |
| Compliance with legal obligations | Legal obligation |
| Aggregate traffic analytics | Legitimate interests |
We do not sell personal information. We do not use your data for advertising or share it with third parties for their marketing purposes.
4. Sharing of Information
Within your household: Nomad Tools is built for households, not single logins. Information you add is shared with the other members of your household, who can view and (depending on the feature) edit it. The household owner manages membership. Your household’s data is never visible to other households.
We share personal information with third parties only in the following circumstances:
- Infrastructure and analytics providers — We use Cloudflare (Pages, D1, R2, KV, and Web Analytics) to operate the application and measure aggregate traffic, and Clerk to authenticate users and manage sessions.
- Financial data providers — If you connect a bank or brokerage, Plaid processes the connection and returns account information needed for balance sync. We store Plaid access tokens encrypted and use them only to sync accounts you connected.
- AI providers — When you use an AI feature (document and statement scanning, trip / visa / medication / vaccine lookups, advisories, and brief or narrative generation), the content needed for that request is sent to Anthropic (Claude). Compatible features routed through our provider-neutral wrapper may instead use OpenAI when no permitted Anthropic key is available; direct Anthropic SDK and web-search features do not fall back to OpenAI. Commercial API data is not used for model training by default unless the customer opts in. Standard API processing can retain inputs, outputs, or abuse-monitoring data for up to 30 days, with longer exceptions for safety enforcement or law; approved zero-data-retention configurations can differ. See Anthropic’s retention notice and OpenAI’s API data controls. You may supply your own AI key; your provider account’s settings and terms then apply.
- Outbound email — Resend delivers transactional email (alerts, invitations, reminders, and review notifications) and receives the recipient address and outbound message content.
- Inbound email — Cloudflare Email Routing and Workers receive forwarded trip and receipt sender/message content and process it to create reviewable crossings and expenses.
- Maps — Google Maps powers the neighborhood map and location-history import; your map interactions and any imported location data are processed by Google.
- Optional current-location lookup — if you choose “use current location” for Date Ideas, your browser sends your exact latitude and longitude directly to BigDataCloud to obtain a city/region label. Nomad Tools does not add those exact coordinates to your household records through this feature.
- Loyalty programs — if you connect AwardWallet, it returns your airline / hotel / credit-card loyalty balances for the Rewards tracker.
- Visa requirements — visa lookups send a passport country and destination country to a third-party visa-requirements service (via RapidAPI); no personal identifiers are sent.
- Payments — if and when paid plans launch, a payment processor (such as Stripe) will process your billing details; we never store full card numbers. This policy will be updated before paid billing begins.
- Legal requirements — We disclose information when required by law, court order, or regulatory authority, or to protect the rights and safety of users.
- Business transfers — In the event of a merger or acquisition, affected users will be notified before data becomes subject to a different privacy policy.
5. International Data Transfers
Your data is stored and processed on Cloudflare’s global infrastructure. Where a transfer outside the European Economic Area (EEA) or United Kingdom requires a transfer mechanism, we rely on the mechanism applicable to the provider and processing, such as an adequacy decision, provider contractual safeguards, or another legally recognized mechanism. Cloudflare documents its mechanisms at cloudflare.com/trust-hub/gdpr.
6. Data Retention
Active household content is retained while your household is active, unless you delete a record sooner. An owner who schedules household deletion has a 30-day cancellable grace period. After that period, the purge attempts each covered active-database deletion and referenced Vault/file-object deletion. Individual database or storage failures are currently fail-soft and may leave orphaned data requiring operational verification/remediation; completion alone is not proof of complete erasure.
Limited operational audit events, AI usage/cost records, and aggregate platform rollups are retained after the household-content purge for security, abuse investigation, deletion evidence, service accounting, and operational integrity. They do not contain customer-entered account content, but audit records may contain household IDs, email/user identifiers, IP addresses, and event metadata. Weekly database backups expire after 84 days and monthly backups after 180 days; they are not selectively rewritten when a household is deleted. Other records may be retained where a legal hold or specific recordkeeping obligation applies.
Each encrypted offline Vault copy expires after 90 days and may be evicted earlier. Sign-out and manual clearing attempt local deletion, although browser/storage failure is possible. While online or on reconnect, an authenticated authorization check purges local copies for removed, deactivated, or no-longer-entitled household memberships. Deleting server-side records, revoking access, or deleting a household cannot remotely erase or revoke a copy while its device remains offline; the device must reconnect, reach expiry, or have its local cache successfully cleared.
7. Your Privacy Rights
All Users
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request deletion of your personal data, subject to the operational, backup, and legal exceptions described above
- Portability — receive your data in a structured, machine-readable format
The in-product JSON export is an automated convenience. Household AI keys and Plaid access tokens are redacted, bearer calendar/share tokens remain, and Vault objects are listed by key rather than file bytes. A failed covered-table query currently appears as an empty export section. For a formal access or portability request, contact us so completeness and secure delivery can be verified.
EU / UK Residents (GDPR / UK GDPR)
All rights above apply. You may also restrict processing while a dispute is resolved, withdraw consent at any time where processing is consent-based, and lodge a complaint with your national data protection authority.
California Residents (CCPA/CPRA)
You have the right to know what personal information is collected, delete it, correct inaccuracies, and opt out of its sale (we do not sell personal information). You will not be discriminated against for exercising these rights.
To exercise any of these rights, contact us at privacy@retireallover.com. We will respond within the timeframes required by applicable law (generally 30–45 days).
8. Security
We implement technical and organizational measures to protect personal information, including encryption in transit (TLS 1.2+) and at rest, access controls, and regular security reviews. In the event of a data breach affecting your rights and freedoms, we will notify you and applicable regulators as required by law.
9. Cookies and Tracking
Nomad Tools uses cookies for authentication, security, and essential functionality. Cloudflare Web Analytics measures aggregate traffic without advertising cookies. We do not use tracking cookies for advertising.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or prominent notice within the application at least 30 days before taking effect. Continued use of our services after changes take effect constitutes acceptance of the revised policy.
11. Contact
For questions, requests, or complaints regarding this policy or our data practices:
Email:
privacy@retireallover.com
Website:
retireallover.com
