Back to Dwellsee

Privacy notice

Version 1.23 · Last updated 10 October 2026

This notice explains what Dwellsee collects about you, why, where it's kept, how long for, and what you can ask us to do with it.

The short version

  • We keep the email and figures you give us so Dwellsee can show you your net worth and projections.
  • Your figures are never sold. No person or AI reads them unless you ask us for help, turn on AI diagnostics in Settings, or connect Claude yourself. Claude can change them only if you also give it write access. To fix faults and keep Dwellsee secure, we use logs and alerts that are designed not to show your figures.
  • There are no adverts, no tracking cookies and no third-party analytics. We count page visits in daily totals, without cookies or anything that identifies you.
  • If you publish a shared snapshot, anyone with that link can see the figures you chose, from anywhere, until it expires. You pick how long, and you can stop it sooner.
  • Your data is stored with Amazon Web Services in London.
  • You can download your data or delete your account at any time in Settings.

Who we are

Dwellsee is run by an individual in the UK. It isn't a company or a regulated firm. In this notice "Dwellsee", "we" and "us" mean the person who runs it, who is the data controller for your personal data.

Contact: contact@dwellsee.com. This is also the address for any privacy question or request.

Dwellsee will be registered with the Information Commissioner's Office (ICO) before public launch.

What we collect

Your account

  • Your email address, and whether you've confirmed it. We also keep a copy of your last confirmed address, so we can tell it if the address changes.
  • Your password. Amazon Cognito, the AWS sign-in service, handles it. It passes through Dwellsee to Cognito only when you use account recovery or confirm it's you before a change to your account's security; Dwellsee never stores or logs it.
  • If you turn on two-step sign-in, the secret for your authenticator app. Cognito holds this too.
  • If you make recovery codes for two-step sign-in, a keyed hash of each code (never the codes themselves) and when you made them.
  • If you ask to turn off two-step sign-in without a recovery code, a record of the request: when you asked, when the 48-hour wait ends, and a hash of the emailed link's secret (never the link itself), with a reference to your account.
  • When you confirm it's you before a change to your account's security, a record that you did, which lets you make further changes for the next five minutes without confirming again.
  • If you change your email address, the new address and a keyed hash of the code we send to it (never the code itself), until you enter the code.
  • How far you've got through the setup steps for a new account, so you can pick up where you left off.
  • If you turn on reminder emails, whether you've turned them on and when you last changed it, the month we last sent you one, and for each reminder a hash of its unsubscribe link's secret (never the link itself), with a reference to your account.
  • Whether you've turned on AI diagnostics and when you last changed it, and a record of each time your data is read for diagnostics: when, why and by whom.
  • How you found us, if you signed up during the same visit, without reloading the page: the website that linked to Dwellsee (its name only, such as news.example.org) and any campaign tags in the link you followed. See "Page statistics" below.

The figures you enter

  • Your accounts: name, category, tax wrapper, monthly contribution, annual fee, when contributions start and stop, and any notes you add.
  • The value of each account on the dates you record.
  • Your debts: the name you give each one, its type (and a student loan's plan), balance on the dates you record, and any interest rate, monthly payment, end dates, whether it's repayment or interest-only, the property it's secured on, whether and how it's in your FIRE plan, the account its payment goes into when it ends, whether its payment comes off your spending target then, and which of your Spending items includes its payment.
  • Lump sums, and your income and expenses with the names you give them.
  • Your FIRE settings and saved scenarios: date of birth, target spending, retirement and pension ages, life expectancy, State Pension details, your salary, other pensions such as defined benefit pensions, growth and inflation assumptions, asset mix, and drawdown and tax settings. Teachers' Pension details too, if you use that page.

We don't ask for bank logins, account numbers or card details, and Dwellsee never connects to your bank. Please don't put account numbers in the names you give accounts and debts, or in notes.

Feedback

If you send feedback from the app, we keep what you wrote, the type you chose (bug, idea or other), the page you were on, the app version, and whether we may contact you. It's emailed to us, and your email address is included only if you said we may contact you.

Shared snapshots

If you publish a shared snapshot, we store a copy of the figures you ticked, the link's secret address, when you made it and when it expires, and a reference to your account so you can list and stop your own links. The copy holds figures and labels only: no name, no email, no account or fund names, no employer or pension scheme name, and nothing that identifies you. The retirement summary shows your FIRE age but gives the years until then only as a range, such as 5–10 years, so a reader can't work out your exact age from it. It's made when you create the link and never updated, so later changes to your account don't reach a link you've already handed out.

How much each box shares differs. "Where the money goes" is the widest: as well as your pay, tax, National Insurance and pension and savings contributions for the year, it breaks your spending down by category — Housing, Food, Entertainment and so on, with a yearly figure for each. The categories are our own list, not the names you gave your income and spending, but the amounts are yours. Under the savings, pensions and property box, "Subtract my debts" takes your debts off its total. If you tick it, the link shares your total debts and how they've changed, as the total on every date in its history, so a new mortgage can show when you took it out. It also takes any student loan repayments off your take-home pay in "Where the money goes" and the income and spending totals, and the page then says you have a student loan and names its plan. It also shows the total of the debt payments you keep outside your spending. Otherwise it never names your debts, their types or who they're with. Every box is off when you start except the retirement summary, and the page shows you exactly what a reader will see before you create the link.

Page statistics

Each time you open a page on Dwellsee, your browser tells our server which page it was (the page's name, such as /register, not the full address), the size band of your screen (small, medium, large or extra large), and, for the first page you open, the name of the website that linked to Dwellsee and the utm_source, utm_medium and utm_campaign tags if the link had them. We add these to daily totals and don't keep the individual visits. We don't store your IP address (apart from the short-lived keyed hash described under Limits on requests, which limits how many pages one address can count), browser details or anything else that could identify you or your device, and we use no cookies for this. If your browser has Global Privacy Control or Do Not Track turned on, nothing is sent.

While the page stays open, Dwellsee also remembers the linking website and campaign tags in the page's memory. Nothing is stored on your device, and they're forgotten when you reload or close the page. If you sign up during that visit, they're saved with your new account, so we can tell which sites and campaigns bring people to Dwellsee, and counted in a daily total of new accounts by source.

Connected apps

If you connect Claude, we keep a record of the connection (which app, what it may do, when you approved it and when it was last used) and the tokens that let it read your figures, or read and change them if you've given it write access. We also keep an audit record of connection events, of each request it makes (the tool used, whether it worked and how long it took, but not the answer) and of each change it saves. When Claude changes or deletes something, we also keep a copy of what was there before, with when it changed and through which connection, so you can put it back from Settings. Changes you make yourself aren't copied.

Logs

  • Request logs: a request id, the time, your user id, the kind of request, the result and how long it took. They don't include what you sent or received, or your IP address.
  • Error logs, which record what went wrong: the kind of request or task, and the type and code of the error. They're designed not to include your figures, emails or what you sent, so they leave out error messages, which can contain data.
  • Security logs of sign-ins and account changes. Each time you sign up, sign in, change or reset your password, email address or two-step sign-in, or add or remove a passkey, AWS records the time, your user id, your IP address, your browser details and whether it worked. They don't include your password, codes or figures. We use them to email you about changes to your account and to look into misuse.

Amazon Cognito and Amazon CloudFront, which deliver sign-in and the website, see your IP address and browser details when you use them, as any website does. Apart from the security logs above, we don't keep them.

Limits on requests

So that no one person or script can overload Dwellsee or run up its costs, we keep short-lived counters in our database:

  • For your account: how many requests your signed-in sessions and connected apps have made today and in the current minute, how many share links and feedback messages you've sent today, how many account recovery attempts have got past your password today, and how many attempts to confirm it's you have failed in the last 15 minutes. These hold only numbers, not what the requests were. Today's request count expires at the end of the day (UTC); the others within two days. All are then removed automatically within two days.
  • When you connect an app, use account recovery, open a shared snapshot link or open a page (for the page statistics above), a keyed hash of your IP address, kept briefly to limit repeated attempts or requests and removed automatically.

Emails

We send the emails the service needs: verification codes when you sign up, reset your password or change your email address (the code for a new address goes to that address), a confirmation when you delete your account, a security alert when an app such as Claude is connected to your account or given permission to make changes, a security notice when your password, email address or two-step sign-in changes or a passkey is added or removed, and security notices about two-step sign-in: when new recovery codes are made, the link when you ask to turn it off without a code, when that 48-hour wait starts, and when it's turned off. For a change of email address, the notice goes to the address it replaced. You can ask for a monthly reminder to update your balances, but we haven't started sending them yet (below). We don't send marketing emails.

Reminder emails, only if you turn them on. Reminder emails are off unless you turn on "Email me a monthly reminder to update my balances" in Settings, under Email reminders. We haven't started sending them yet. Once we do, while they're on, we'll email you on the 1st of each month with a link to Update balances. A reminder has no balances or figures in it: to send it we use only your email address and the fact that you asked for it. You can stop them at any time in Settings, or with the unsubscribe link in any reminder, which works without signing in. Your email app may also show an unsubscribe button, which does the same.

When someone confirms a new account, we get an email saying so, with the time, roughly how many accounts there are, and the linking website and campaign tags if we know them. It doesn't include your email address or anything else that identifies you.

Why we use it, and our lawful basis

  • To provide Dwellsee to you (contract): creating your account, signing you in, storing your figures, working out your projections, sending service emails, answering requests from apps you connect, publishing a shared snapshot when you ask for one, and helping when you ask us to.
  • To keep Dwellsee secure and working (legitimate interests): logs, rate limits and audit records help us spot abuse, protect accounts and fix faults. We keep them for a short time, and they're designed not to include your figures.
  • To improve Dwellsee (legitimate interests): reading and replying to feedback you send, and page statistics and how new accounts found us, so we know which pages are used and where people come from. To opt out of page statistics, turn on Global Privacy Control or Do Not Track in your browser.
  • Reminder emails, only if you turn them on (consent): see "Emails" above. You can turn them off at any time in Settings, under Email reminders, or with the link in any reminder.
  • AI diagnostics, only if you turn it on (consent): see "Who else handles it" below. You can turn it off at any time in Settings, under Privacy and AI.
  • To meet legal obligations (legal obligation), if the law requires us to keep or disclose something.

You need to give us an email address to have an account. Everything else is optional, but projections need your figures.

We don't sell your data, show adverts, or use your data to make decisions about you. Your projections are calculations you ask for, shown only to you.

Who else handles it

Amazon Web Services (AWS) runs Dwellsee for us under its data processing terms. Your account, figures, backups and logs are stored in AWS's London region (eu-west-2), encrypted at rest. Emails are sent through Amazon SES in Ireland (eu-west-1). The website's files are delivered through Amazon CloudFront, which serves them from the location nearest you, which may be outside the UK. AWS's terms include the UK's approved safeguards for transfers outside the UK.

Email. Feedback and messages to contact@dwellsee.com arrive in an Apple iCloud Mail mailbox. Apple may store and process mail in the US, under Apple's safeguards for international data transfers.

By default, no AI reads your financial data. We use Claude, an AI assistant made by Anthropic, a US company, to help build and run Dwellsee: writing code, managing the infrastructure, and looking at totals and logs that are designed not to include your financial figures. Anthropic handles that work for us as a processor.

AI diagnostics, only if you turn it on. AI diagnostics is off unless you turn on "Allow AI diagnostics" in Settings, under Privacy and AI. While it's on, we may use AI tools, including Claude, to read the data stored in your account (your accounts and their values, lump sums, income, expenses, FIRE settings and scenarios, and the records kept with them, such as feedback, connected apps and setup progress) to investigate a problem you've reported or to check that your calculations are accurate. That data is sent to Anthropic in the US. For that transfer we rely on Anthropic's commercial terms and data processing addendum, including the standard contractual clauses and the UK International Data Transfer Addendum. We record each time we read your data this way, and Settings shows when it last happened. You can turn it off at any time, and it takes effect straight away. Turning it off doesn't undo a reading that has already happened.

Any future AI feature, such as an AI adviser, will ask for your permission separately.

Anthropic, if you connect Claude. Claude can read your figures when you ask it a question. It can also change them (record account values, add, change or delete income and expenses, add or change debts and record what you owe on them, set an account's monthly contribution, and rename an account or change its notes and fee), but only if you give it write access. That's a separate permission with its own approval page, which you normally see the first time Claude asks to change something rather than when you first connect: it needs two-step sign-in turned on for your account, and we email you when it's granted. Before anything is saved, Dwellsee sends Claude a preview of the change and asks it to check with you, and the change is saved only if Claude then confirms it. If a change wasn't what you wanted, you can undo it for 30 days under Recently changed by Claude in Settings. What Claude reads, and the previews it's sent, go to Anthropic and are handled under your own agreement with Anthropic and its privacy policy, not this notice. Anthropic is based in the US, so connecting Claude sends the figures it reads outside the UK. You choose to do this, and you can disconnect at any time in Settings, under Connected apps. Claude's access stops straight away.

Anyone you give a share link to. A shared snapshot is published: whoever holds the link can open the page, with no account and from anywhere in the world, and there is no way for us to know or limit who that is. The link's address is the only thing keeping it private, so treat it as you would the figures themselves — once you've posted it somewhere public, anyone who has seen it may have kept a copy, and expiring the link can't take that back. We ask search engines not to index these pages, and the preview that sites such as Reddit, Slack and WhatsApp show for the link carries no figures, only the Dwellsee name. You choose what each link includes, how long it lasts (24 hours, 7 days or 30 days — there is no permanent option) and when to stop it, all under Settings, under Shared snapshots.

We don't share your data with anyone else unless the law requires it.

How long we keep it

  • Your account and figures: for as long as you have an account.
  • When you delete your account, your data is removed from the live database straight away. Copies can remain in backups, held by AWS in London, for up to 35 days, after which they're gone.
  • Shared snapshots: until the link expires, at most 30 days. The page stops working the moment it expires, and the stored copy is deleted automatically shortly afterwards — usually within minutes, and within 48 hours at the latest. Stopping a link yourself, or deleting your account, deletes the copy straight away.
  • Confirming it's you: five minutes. A change of email address waiting for its code: until you enter the code, for at most an hour, or until five wrong codes. Both are then removed automatically within two days, and deleting your account removes them straight away.
  • Recovery codes: until you use one, make a new set, or delete your account. A request to turn off two-step sign-in without a code: until it's finished or cancelled, or its link expires (24 hours if it isn't opened; otherwise a week after the 48-hour wait ends), then removed automatically within two days. Using a recovery code, making new codes or deleting your account removes it straight away.
  • Reminder emails: whether you've turned them on and when you last changed it, and the month we last sent you one, until you delete your account. Each reminder's unsubscribe link works for 60 days, then it's removed automatically within two days. Deleting your account removes it straight away.
  • Request and error logs: 30 days. Logs for connected apps: 90 days.
  • Security logs of sign-ins and account changes: 30 days, then deleted automatically. Deleting your account doesn't remove them sooner.
  • Limits on requests: your account's request counters expire within two days, and a keyed hash of an IP address after about an hour. Both are then removed automatically within two days.
  • Audit records for connected apps, and records of AI diagnostics access: about 90 days, removed automatically, or when you delete your account if that's sooner.
  • Copies of what Claude changed or deleted: 30 days, then removed automatically within two days, or when you delete your account if that's sooner. Restoring one doesn't remove it sooner.
  • Feedback: deleted with your account. Feedback emails: kept for up to 12 months, then deleted.
  • Page statistics: daily totals, kept for about 13 months, then removed automatically. How you found us: deleted with your account.

Your rights

You have the right to:

  • get a copy of your data, including in a format you can take elsewhere;
  • correct it;
  • have it deleted;
  • restrict how we use it, or object to uses based on our legitimate interests.

You can do most of this yourself. You can edit your figures in the app. In Settings, under Your data, you can:

  • download your data: everything you've entered, including feedback, connected apps, how you found us, your AI diagnostics and reminder email settings, what Claude changed in the last 30 days and your live share links with what each one shows, as JSON or CSV;
  • delete your account and everything in it (you'll need to have signed in within the last 5 minutes);
  • sign out of all devices.

Under Shared snapshots in the same place, you can see every link you've published and stop any of them, which takes the page down at once.

The download doesn't include logs or security records. For those, or anything else, email contact@dwellsee.com from the address on your account. We'll reply within one month.

If you're unhappy with how we've handled your data, please tell us first. You can also complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.

Cookies and browser storage

Dwellsee uses no third-party analytics, no advertising and no third-party cookies. Its page statistics store nothing in your browser. Its fonts are served from Dwellsee itself, not from Google or another font service. It keeps only what it needs to work in your browser:

  • Sign-in tokens (local storage, names starting CognitoIdentityServiceProvider): keep you signed in. Removed when you sign out.
  • Sign-in in progress (session storage, names starting CognitoSignInState): holds your email and sign-in step while you enter a code. It stops working after 3 minutes and is cleared when you finish signing in or close the tab.
  • Theme (local storage, dwellsee-theme): remembers Light or Dark if you choose one.
  • Security reminder (local storage, dwellsee-mfa-nudge-snoozed-until): remembers when you've snoozed the two-step sign-in reminder.
  • Setup reminder (local storage, names starting dwellsee-setup-banner-dismissed): remembers that you've hidden the reminder to finish setting up, for your account on this browser.
  • Last activity (local storage, fintrack.lastActivity): the time you last used Dwellsee in any tab, so it can sign you out after 30 minutes without activity.
  • Cash flow view (local storage, dwellsee-cash-flow-period): remembers whether Cash flow shows monthly or annual figures.
  • Update reload (session storage, dwellsee-preload-reload): stops the app reloading more than once after an update. Cleared when you close the tab.
  • Page reload (session storage, names starting fintrack:chunk-reload:, then the part of the app): if part of a page fails to load after an update, lets the page reload once to fetch it, and stops it reloading again. Cleared once it loads, or when you close the tab.
  • Connecting an app: a secure cookie for up to 10 minutes while you approve the connection, and the cookies AWS's sign-in page needs to sign you in.

These are strictly necessary for the service, so they don't need your consent.

Keeping it safe

Everything is sent over HTTPS and stored encrypted. In Settings you can add an authenticator app for two-step sign-in, and sign out of all devices if you think someone else has access. If we learn of a breach that puts you at risk, we'll tell you and, where required, the ICO.

Children

Dwellsee isn't for anyone under 18. If you think someone under 18 has an account, email contact@dwellsee.com and we'll delete it.

Changes to this notice

If we change this notice in a way that matters, we'll tell you by email or in the app before the change takes effect. The version and date at the top show which one you're reading. See also our terms of use.