privacy policy

β”Œβ”€ Scope ────────────────────────────────────────┐

This policy covers the lowriskquotes website (lowriskquotes.com, all language versions), its public REST API (/api/) and its remote MCP server (/api/mcp/). Last updated 2026-10-03.

The short version: there are no accounts, we store nothing you type or send, we sell nothing, and the only third parties involved are Google Analytics and Vercel (hosting).

β”Œβ”€ No accounts ────────────────────────────────────────┐

lowriskquotes has no sign-up, login, newsletter or payment. We never ask for your name or email address. The cost estimator on the website runs entirely in your browser: your line items, uncertainty levels and results are kept in your own device's localStorage so they survive a page refresh, and are never sent to our servers. Clearing your browser storage removes them completely.

β”Œβ”€ The website: Google Analytics ────────────────────────────────────────┐

The website uses Google Analytics 4 (GA4), Google's standard, cookie-based analytics product. It tells us how many people visit, which pages they read and roughly where they come from, in aggregate. Google sets cookies in your browser for this and processes the data under its own privacy policy (policies.google.com/privacy). We do not pass GA4 any identifier of our own and do not link analytics data to any individual. You can block GA4 with a content blocker or Google's opt-out browser add-on; the site works identically without it.

β”Œβ”€ The API and MCP server: anonymous event counts only ────────────────────────────────────────┐

When an AI agent or developer calls the REST API or an MCP tool (monte_carlo_estimate, retirement_drawdown), our code may send one event to GA4 via the Measurement Protocol so that we can see how much the API is used. That event contains exactly two things:

1. the event name (which endpoint or tool was called), and
2. a random client id generated fresh for that single event.

The client id is not derived from you or your request and cannot be used to join one call to another. We do not store IP addresses, user agents, API keys (there are none) or any part of the request body. The numbers you send (cost ranges, portfolio size, annual spending, horizon, allocation, seed) exist only in memory for the milliseconds it takes to run the simulation, and are then discarded. Nothing is written to a database or log by our code.

Vercel, which hosts the serverless functions, keeps short-lived request logs for operating the platform under its own privacy policy (vercel.com/legal/privacy-policy). We do not export or analyse those logs for anything beyond debugging an outage.

β”Œβ”€ Data sources ────────────────────────────────────────┐

None. lowriskquotes does not hold a dataset about you or anyone else. Every result, on the website and through the API, is computed from the inputs the caller supplies at that moment, using published statistical methods (triangular-distribution Monte Carlo for cost estimates; a real-return, annual-step Monte Carlo for retirement drawdown). The guide pages quote typical cost ranges from public trade sources and contain no personal data. Simulation output is indicative and educational only, not financial advice.

β”Œβ”€ What we do not do ────────────────────────────────────────┐

We do not sell, rent or share personal data with anyone, because we hold none. We do not run advertising, retargeting or third-party tracking pixels. We do not profile users. The only third parties that process anything are Google (GA4) and Vercel (hosting), as described above.

β”Œβ”€ Your rights and contact ────────────────────────────────────────┐

Because we hold no personal data, there is nothing for us to access, correct or delete on request; rights over GA4 data are exercised against Google. If you believe this page is wrong, or have any question about it, open an issue on GitHub at github.com/physics-star-cat. Changes to this policy are published here with a new "last updated" date.

[ABOUT][API DOCS]