Privacy Policy

RP (Right Plan Discoverer) and Pro-Active Connect

Effective date: 3 September 2026. Supersedes the version dated 4 August 2026; what changed and why is recorded at the end of this document.

RP is a desktop application published by David A. Weilert. Pro-Active Connect is an optional hosted service published by the same developer, used only by advisory practices and only for clients who consent to it. This policy covers both, and says clearly which one each statement is about, because they handle information in completely different ways.

The short version: your financial plan never leaves your computer. The application has no account, contacts no server belonging to the developer, and collects nothing. If — and only if — an advisor arranges Pro-Active Connect and you consent to it, a separate hosted service holds read-only access to the accounts you choose, and that service is described in full in Pro-Active Connect below.

Which parts apply to you

The desktop application — everyone who installs RP, in either the individual or the advisory edition. Local-first, no account, no collection. Everything in this policy applies to you except the Pro-Active Connect section.

RP-Hub — only advisors and practice staff who have connected their own work mailbox to it, so that RP can send e-mail and manage calendar entries on their behalf. If you are a client of a practice rather than someone who works there, you have never seen its consent screen and that section describes nothing that has happened to your data.

Pro-Active Connect — only households whose advisor uses it and who have personally completed a consent flow. It is not part of the application, cannot be switched on from inside it, and does not exist for you unless you were invited to it and said yes. If you have never seen a Connect consent screen, that section describes nothing that has happened to your data.

Information we collect

The desktop application: none

The developer operates no server, no database and no analytics service that the application talks to. RP has no sign-up, no sign-in, no user account and no online activation. There is nothing to collect information with.

The application does check a licence, and it is worth being precise about how, because "licence check" usually means phoning home. This one does not. A licence is a signed file on your own device; the application verifies its signature offline, using cryptography built into your operating system. No licence check contacts the developer, and no licence check reports anything about you, your plan or your usage to anyone.

Pro-Active Connect: what a connection needs, and nothing beyond it

If you consent to a Connect connection, the service holds:

What Why it exists
An access credential for each institution you connected It is what allows read-only retrieval; it is issued by Plaid and stored encrypted, server-side only
The account inventory for those accounts — type, name, the masked last digits, balances The account list and balances your plan is compared against
Holdings and securities on investment accounts Positions, prices and cost basis for retirement and brokerage accounts
Transaction history on cash and credit accounts Cash-flow and spending signals
Liability detail — mortgages, student loans, credit cards Debt balances and terms
Connection status, institution name and timestamps So a broken or withdrawn connection can be reported rather than read as silence
An internal identifier for your household, and the email address your advisor holds for you To issue your consent invitation and to reach you about the connection

Your household is identified inside the service by an identifier the service generates. Your email address, phone number and other personal details are not used as your identifier at Plaid.

Where your data is stored

Everything you enter into the application — household details, dates of birth, income, account balances, budgets, property, insurance, notes — is stored only on your own device, in ordinary files that you choose the location of. You can copy, back up, move or delete those files like any other file on your computer.

Optional password protection encrypts a plan file on your device. The password is never transmitted anywhere and cannot be recovered by the developer; if you lose it, the file cannot be opened.

Pro-Active Connect data is held server-side by the service, separately from your plan file, and is described in its own section below. The application never holds Connect access credentials.

Analytics, telemetry and crash reporting

The application contains no analytics, no telemetry, no usage tracking, no advertising and no third-party tracking software of any kind. No crash reports are transmitted.

The application can assemble a diagnostic report to help with a support question. That report is copied to your clipboard so that you can read it and decide whether to send it to anyone. It is not transmitted by the application, and it contains no plan file contents.

Pro-Active Connect keeps operational logs — that a retrieval ran, that a connection failed, that consent was withdrawn — because a service holding financial access that cannot tell you what it did is not a safer service. Those logs deliberately exclude access credentials, passcodes and full account numbers.

When the application contacts the internet

The application works fully offline. A small number of optional features contact the internet, and each one happens only when you click a control that says so, and confirm it. None runs automatically, in the background, or at startup.

Feature What it contacts What is sent
Check for a newer version of the app GitHub Nothing but the request itself
Import updated tax or reference data GitHub Nothing but the request itself
Check whether a cited source page has changed The publisher's own website — for example the IRS, CMS, Social Security Administration, or a research organisation cited in the app Nothing but the request itself
Look up a foreign-currency exchange rate A public exchange-rate service The currency codes you selected
Check for or download optional add-on training courses GitHub Nothing but the request itself

No plan data, personal data or financial data is included in any of these requests. They only fetch published information; they do not send yours.

The application does not contact Pro-Active Connect, and Connect does not contact the application. The application never displays Plaid Link, never holds a Plaid credential, and has no consumer login. Where a practice uses Connect, the resulting summary arrives in the practice's own workspace as a file, and the application reads it from disk the way it reads any other file.

As with any request made over the internet, the operator of the site being contacted can see the connection itself — your IP address, the time, and which page was requested. That is inherent to how the internet works rather than something the application adds, and each of those organisations handles such records under its own privacy policy. The application does not identify you to them, and does not send anything that would.

The complete list of internet addresses the application is permitted to contact is fixed at build time and enforced by the application's own security configuration; it cannot reach anywhere else. You do not have to take that on trust — see How to check this policy below.


Pro-Active Connect

This section applies only if an advisor arranged Connect for you and you consented. Everything in it is about a hosted service, not about the application on your computer.

What it is

Connect keeps an advisor's picture of your accounts current, by retrieving balances, holdings, transactions and liabilities from institutions you choose, through Plaid, on a recurring basis. The purpose is retirement planning monitoring: noticing that reality has drifted from the plan.

It is operated by David A. Weilert, the publisher of RP.

It is read-only, structurally

Connect cannot move money. It cannot initiate a transfer or a payment, cannot place a trade, cannot open or close an account, and cannot change anything at your institution. It requests read-only information and nothing else.

How consent works, and what your advisor never sees

You connect an institution through Plaid Link, which is Plaid's own interface. Your bank username and password are entered into Plaid's interface and go to Plaid and your institution. They are not sent to Connect, are never stored by Connect, and are never visible to your advisor or to the developer. What Connect receives back is an access credential that permits reading the accounts you selected — never your login details.

Reaching that screen requires more than a link. You must have been invited by your own advisor, at the email address they hold for you, on a single-use invitation that expires; and you must also give a passcode that your advisor issues from their console and reads to you directly, on the call or meeting you are already in. A link on its own is not enough. The consequence is deliberate: nobody can connect an account in your name without your advisor present, and a forwarded or guessed link gets a stranger nowhere.

Your advisor is a licensed professional you have engaged, and they see the account information Connect retrieves — that is the point of the service. They do not see your credentials, and they cannot see another practice's clients or another household's connections.

Plaid

Plaid Inc. is the provider that connects to your financial institutions on Connect's behalf, and it is the only third party involved in this. Plaid handles your information under its own end user privacy policy, which you are shown during the connection flow and which is published at plaid.com/legal.

Connect requests the narrowest set of information a connection can be made with, and offers account-type choices rather than always asking for everything an institution could provide.

Sharing beyond that

Connect data is not sold, rented, brokered or shared for advertising. It is not used to build profiles, is not shared with other practices, and is not used to train anything. Beyond Plaid, disclosure happens only where the law compels it.

Retention, and what happens when you withdraw consent

You can withdraw consent at any time, and it is deliberately easier than giving it. Revocation does not require your advisor's help, does not require a passcode, and is reachable from the messages the service sends you about your connection. You do not need to be able to reach your advisor to stop a service reading your accounts.

When you withdraw consent — or when your advisor removes the connection, or the practice's use of Connect ends:

You can also ask the developer what Connect holds about you, and ask for it to be deleted, using the contact details below.

How it is protected

Access credentials are encrypted at rest, with a separate key per record. Only the service can decrypt one, and they are never exported to an advisor's workspace, never written to logs, and never included in support diagnostics. Every record is bound to a single practice, so one practice's data cannot be reached from another's. Advisor access to the console requires a password and an authenticator code. Notifications arriving from Plaid are cryptographically verified before they are acted on. Passcodes are single-use, short-lived, rate limited, and never logged.

The developer's information security policy for Connect is available on request.


RP-Hub

This section applies only if you work at a practice and have connected your own mailbox to RP-Hub. It is about a service that acts on your work e-mail and calendar, not about the application on your computer.

What it is

RP-Hub is what the RP products call when they need to reach outside: to send correspondence you have composed — a meeting follow-up, an annual review packet, a document request — or to put a meeting you have already scheduled onto your calendar. It then reports back whether the message actually went, so the practice's records reflect what happened rather than what was intended.

It is send-only, structurally

RP-Hub cannot read your mailbox. The permission it asks for — gmail.send at Google, Mail.Send at Microsoft — permits sending and nothing else. It confers no ability to list, open or search your messages, and RP-Hub requests no permission that would. Your incoming mail is not copied, indexed or stored.

Where calendar sync is switched on, RP-Hub can create, update and remove events. That permission is necessarily broader, and it is asked for separately.

How consent works

You connect your own account through Google's or Microsoft's own consent screen. The grant is delegated: it covers your mailbox, granted by you, and it is yours to withdraw. We do not ask for the tenant-wide kind of permission that would let the software send as anyone in your organisation.

Signing in to an RP product with Google or Microsoft does not by itself grant any mailbox access. Connecting a mailbox is a separate, deliberate act, and the two are recorded separately.

What is stored, and for how long

To send a message reliably, and to retry when a provider is briefly unavailable, RP-Hub has to hold that message until it is accepted. So it does store the subject, recipients and body of what it is asked to send. It does not keep them indefinitely.

What Kept for
The body of a message Erased seven days after it is sent or finally fails.
Subject, recipients, delivery outcome, timestamps Ninety days, so a practice can show whether correspondence was delivered.
Calendar subject, location and attendees Erased seven days after the event is synced.
The authorisation your provider issued Until you disconnect it, or revoke it with the provider.

The authorisation itself is encrypted before it is stored, under a key kept outside the database. It is never returned to the RP products, never written to logs, and never shared.

RP-Hub also records that an operation happened — which product asked, which account, which provider, whether it worked — for ninety days, to support troubleshooting and audit. Those records deliberately hold counts and lengths rather than contents: not the recipients, not the subject line, not the body.

When support needs more than that to explain a fault, an operator can switch on a short diagnostic capture. It is limited to four hours, strips sensitive fields before anything is written down, deletes itself, and every time one is enabled, read or exported it is recorded against the person who did it.

Google user data

RP-Hub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the features you connected your account for; is not transferred to others except as needed to provide those features, to comply with the law, or in a merger or acquisition; is not used for advertising; and is not used to develop, improve or train generalised artificial intelligence or machine learning models. No human reads it, except with your explicit consent for a specific support issue, where security or the law requires it, or where it has been aggregated and anonymised.

Withdrawing access

Disconnect the mailbox from inside the RP product and the stored authorisation is destroyed immediately. You can also revoke it directly with your provider, which takes effect whatever the product does: Google or Microsoft.


Sharing

The application collects nothing, so there is nothing it can share. There is no advertising, no data broker relationship and no third-party analytics partner in either the application or Connect. Connect's only third-party provider is Plaid, described above.

Retention

The application retains nothing, because it collects nothing. Data you create stays on your device until you delete it.

Connect retains the information listed above for as long as the connection is live, and applies the deletion rules above when consent is withdrawn or the connection is removed.

Your choices

Because your plan data never leaves your device, you remain in complete control of it. Deleting a plan file deletes that plan. Uninstalling the application, and deleting any plan files you created, removes everything.

For the application there is no request to make of the developer to access, export or delete your data, because the developer never has it.

For Connect there is, and you are entitled to make it: you can withdraw consent yourself at any time, and you can ask what is held and ask for it to be deleted.

Children

RP is a financial planning tool intended for adults. It is not directed at children and collects no information from anyone, including children.

How to check this policy

RP is commercial software, licensed by annual subscription under the End User License Agreement that ships with it. It is neither open source nor source-available, and its repository is private.

That changes how this policy can be checked, so it is worth being direct about it. Until 2026-08-16 this section said every claim could be verified by reading the source, and pointed at a public repository. Both halves of that stopped being true, and a privacy policy resting its credibility on a link that no longer resolves is worse than one that never made the offer.

What remains checkable is the part that always mattered most, and it does not require our cooperation: the application is a desktop program on your own machine, and you can watch what it does on the network with any traffic monitor your operating system provides — Little Snitch, a firewall log, tcpdump. Every claim above about what the application does and does not transmit is falsifiable that way, by you, without trusting this document. In particular you can confirm for yourself that it never contacts Connect. Plan files are ordinary files in a folder you chose, and you can open them and read them.

The Connect claims are not checkable that way, because Connect is a service rather than something running on your machine. What is offered instead is this document, the security policy available on request, and your own ability to revoke at any moment and see retrieval stop.

Changes to this policy

If the application or Connect changes in a way that affects this policy, this document will be updated and its effective date changed. Material changes are described in the application's release notes as well.

What changed on 3 September 2026. The previous version said the developer operated no server of any kind, collected nothing under any circumstances, and that transmission of personal data was not planned. That was accurate for the application, and it remains accurate for the application. It stopped being a complete description of the developer's products once Pro-Active Connect existed, and a policy that denies the existence of a service the developer operates is worse than no policy at all — so the scope is now stated explicitly rather than implied, and Connect is described in full. Nothing about how the desktop application handles your data changed on this date; only what this document admits to.

Contact

Questions about this policy, about privacy in the application, or about Pro-Active Connect — including a request to see or delete what Connect holds about you — can be sent to:

dave@softwarebydaw.com

David A. Weilert, SoftwareByDaW.