You're trusting us with the details of your financial life. Here's exactly how that trust is earned.
Every account's plans and figures are isolated to that account — one member's data can never be seen by another. Your plans are exportable, and deleted if you leave. There's no lock-in.
Passwords are hashed with bcrypt — the industry standard — and never stored in readable form. Password reset links are hashed in our database too, and expire after one hour.
All traffic runs over HTTPS. Your numbers travel encrypted between your browser and our servers, end to end.
Changing your password or logging out invalidates every existing session on every device — a stolen login doesn't stay stolen.
RetirePath never asks for bank logins and never touches real money. When billing launches, card payments will be handled by a PCI-compliant provider — we won't see or store card numbers.
RetirePath runs on Render with a managed PostgreSQL database — mature platforms with their own security certifications, monitoring and backups.
Login and signup endpoints are rate-limited, and our public API is restricted to the data your own account owns — verified by automated review, not just good intentions.
If you believe you've found a security issue, tell us privately via the contact page and we'll investigate promptly.
Our privacy policy explains what we collect and why, and our terms of service cover the agreement between RetirePath and you. RetirePath provides guidance and modelling — not financial advice.