Skip to content
Geo-Parity
Ask Paid plans only

Legal

Privacy Policy

Last updated 18 July 2026.

This policy explains how Geo-Parity ("we", "us") handles personal data when you use https://geo-parity.com. It is written to comply with the UK GDPR and the Data Protection Act 2018. Geo-Parity is designed to be privacy-first: the calculators run in your browser, and we collect as little as possible.

1. Who we are (data controller)

The data controller is Adam Simmons Spaans (United Kingdom). For any privacy question or to exercise your rights, contact info@geo-parity.com.

Suite 657, 80a Ruskin Avenue, Welling, DA16 3QQ, United Kingdom

2. What we collect, why, and our legal basis

a. Tool inputs — not collected

The numbers you type into the calculators (income, savings, itinerary, team timezones, etc.) are processed in your browser and are not sent to or stored by us, except when you deliberately call a JSON API endpoint (e.g. /api/calculate.json), in which case the parameters travel in the request URL so the result can be computed. Those requests are not tied to your identity.

b. Account data — only if you register

If you create an account, we store your name, email address, a securely hashed password (we never store the password itself), and — if you sign in with Google — the account identifier they return. We also store session records to keep you signed in. This is handled by the open-source better-auth library in a Cloudflare D1 database.
Legal basis: performance of a contract (providing the account you asked for).

c. Payment data — only if you buy something

Purchases are processed by Polar, which acts as our merchant of record — meaning Polar, not us, is the seller on your receipt and the party that charges and remits your local VAT or sales tax. Your card details go straight to Polar and are never seen or stored by us. We keep only what's needed to know what you've bought: your Polar customer and subscription identifiers, the plan and its status, and a record of one-off purchases — linked to your account. Polar also collects the billing address and any tax ID it needs to calculate that tax, and holds your invoices; see Polar's privacy policy.
Legal basis: performance of a contract (supplying the plan you bought), and legal obligation for tax and accounting records.

d. Email we send you

Account emails — password resets and address confirmation — are sent through Zoho ZeptoMail, from its EU data centre. We do not track them. There is no open-tracking pixel and no click tracking: the messages are plain text, so there is nothing to load and no rewritten links, and we do not know whether you opened one. Tracking is switched off explicitly on every message we send, not merely left at its default. They also carry no unsubscribe link, deliberately — these are security emails you asked for, and an unsubscribe on a password reset would silently stop future resets reaching you.
This is why we changed provider in August 2026: the one before added a tracking pixel and an unsubscribe link to every message and would not let us remove either.
Legal basis: performance of a contract (sending the email you asked for), and legitimate interest in the security of accounts.

e. API keys — only if you create one

If you create an API key we store a hash of it (never the key itself), its short visible prefix, and per-hour request counts used to apply your rate limit. Anonymous API traffic is counted against your IP address for the same purpose.
Legal basis: performance of a contract, and legitimate interest in protecting the service from abuse.

f. Analytics — aggregate and cookieless

We may use Cloudflare Web Analytics, which is privacy-first and cookieless: it records aggregate page views and performance without setting cookies, without fingerprinting, and without tracking you across sites.
Legal basis: our legitimate interest in understanding, in aggregate, how the site is used.

f2. The adviser

If you ask the adviser a question, the question and any optional details you give (home country, monthly income, household) are sent to our /api/adviser endpoint and passed to an AI model run by Cloudflare Workers AI, which calls this site's own calculators to answer. We do not store your question, the answer, your IP address or anything that identifies you. What we keep is a daily count of model calls and the compute they used, held for 30 days, so the adviser can stop before it costs anything. A short-lived per-address rate-limit counter, like the one on our API, is discarded within the hour. Answers are generated automatically from published figures and are not financial, legal, tax or immigration advice.
Legal basis: performing the service you asked for, and our legitimate interest in keeping it within its free limits.

f3. TypeSafe (paid plans only)

On a paid plan, three features use a decision model run by TypeSafe AI (San Francisco, USA): the adviser, which sends your question and the details you gave so the model can choose which of our calculators to run; the "which country fits me" tool, which sends the preferences you type so they can be turned into slider settings; and, for paid API keys, the name of an MCP tool that does not exist, so we can suggest the nearest real one. Separately, if you email support@help.geo-parity.com, the subject, the first 4,000 characters of your message and the domain of your address (never the address itself) are sent to TypeSafe to label the email by kind, so it reaches the right place; the email itself is forwarded to our inbox unchanged. Nothing else is sent: no account details, no IP address. TypeSafe states it does not train its models on customer data. We store none of this text ourselves — only a daily count of calls and their size per feature, held for 30 days, to keep spending within a fixed ceiling. Apart from support email, free visitors never reach TypeSafe: every tool works for them without it.
Legal basis: performing the service you asked for.

g. Link-click and referral counts

When an outbound affiliate/sponsored link is clicked, the browser sends a minimal fire-and-forget beacon to our /api/event endpoint recording the link's id and the page path. It contains no cookies, no user identifier, and is not stored in a database — it is an aggregate counter written to our server logs.

The banking tool holds a register of banks and money apps that is not published: a provider is shown only where we have a partner relationship with it, and none is shown today. Nothing about which countries or providers you look at is recorded.

If your browser exposes tools to an AI agent (the WebMCP browser API, currently a Chrome and Edge trial), our pages register their calculators with it. When such an agent uses one, the call goes to our /api/mcp endpoint exactly like any other API call, marked with a request header so we can count it. What we keep is a daily total of tool calls held for 90 days — no cookie, no identifier, and nothing that could distinguish one visitor from another. The registration itself sends one beacon per page saying how many tools were registered, which is logged and not stored.

Separately, if you arrive from another site the same beacon reports the referring website address only — never the full link, never a search or conversation — together with the section of our site you landed on. We keep a count only when the referrer is an AI assistant, so that we can tell whether being read by AI systems actually sends anyone here; every other referrer is discarded on arrival and never stored. What is kept is a daily total per assistant per section (for example, “perplexity.ai → 4”), held for 90 days. It contains no cookie, no identifier, and nothing that could distinguish one visitor from another.
Legal basis: legitimate interest in measuring, in aggregate, which links and sources are useful.

If you arrive by clicking one of our own adverts or a link we have tagged, the address you land on carries labels such as utm_source=facebook. The same beacon reports those labels and we keep a daily count per advert — the source, the medium and the campaign name we chose, and nothing else. We do this because our analytics provider cannot see them, so it is the only way to tell whether an advert we paid for brought anyone here. Click identifiers that platforms add to identify one click (fbclid, gclid and the like) are never read or stored, nor is the page you landed on. A visit with no such label sends nothing at all. Counts are held for 180 days and contain no cookie and no identifier.
Legal basis: legitimate interest in knowing whether our own advertising works.

h. Server logs

Our host records standard technical request data (such as IP address, timestamp, and user agent) transiently for security and to keep the service running.
Legal basis: legitimate interest in the security and integrity of the service.

3. Cookies & local storage

We use only strictly-necessary and functional storage — there are no advertising or cross-site tracking cookies, so no consent banner is required. Analytics, if enabled, is cookieless.

NameTypePurpose
better-auth sessionCookieKeeps you signed in after login. Only set if you have an account.
themeLocal storageRemembers your light/dark preference.
geo-homeLocal storageRemembers your chosen home country and currency so tools default to them.

4. Who processes your data (sub-processors)

We do not sell your personal data, and we do not share it for advertising.

5. International transfers

Geo-Parity runs on Cloudflare's global edge network, so data may be processed on servers outside the UK. Where that happens, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum / Standard Contractual Clauses.

6. How long we keep it

Account data is kept for as long as your account exists; if you delete your account, it is removed. Sessions expire automatically. Payment and invoice records are kept by Polar and by us for as long as tax and accounting law requires, even after an account is deleted. Rate-limit counters are discarded within a few hours. Aggregate analytics and log data are retained only for a limited period in line with our host's defaults.

7. Your rights

Under UK GDPR you have the right to:

To exercise any of these, email info@geo-parity.com. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO).

8. Children

Geo-Parity is not directed at children under 13, and we do not knowingly collect their data.

9. Changes

We may update this policy; material changes will be reflected by the "last updated" date above. Continued use after an update means you accept the revised policy.

Related: Terms of Use · Affiliate & Sponsorship Disclosure · About.

to move Enter to open