Privacy
This tool exists because money conversations are awkward. That only works if the privacy claims are precise. Here is what actually happens, including the parts we cannot promise.
The short version
- No accounts, no names, no email addresses, no phone numbers.
- Your amount is never shown to the group, the organiser, or anyone else.
- Individual amounts are encrypted before they are stored.
- They are deleted the moment the group result is calculated.
- Rooms are temporary. Nothing is kept longer than 14 days in total.
- Private room pages load no advertising and no third-party tracking.
What we store, and for how long
While a room is open
- The room: a random identifier, the title you typed, the currency, the expected number of people, how many answers have arrived, and when it was created.
- Each answer: stored only as encrypted data. The amount is encrypted before it reaches the database, using a key held outside it. Nothing in the database contains a readable amount.
- Your browser token: a random value your browser generates so you can edit your own answer. We store only a one-way keyed hash of it, and the hash is different in every room, so it cannot be used to link you across rooms.
After the result appears
The individual answers are deleted in the same database operation that publishes the cap. What remains is the room title, the currency and the single rounded number. The lowest submitted amount is not kept either, only the rounded cap.
Deletion
- A room with no result is deleted 7 days after it was created.
- A room with a result is deleted 7 days after the result appeared.
- The organiser can delete a room, and everything in it, at any moment.
- Resetting a room deletes every answer immediately, including the organiser’s own.
What we deliberately do not have
There is no account system, so there is no profile to build. There is no participant list, so there is no record of who took part. There is no field anywhere in the product for a name, an email address or a phone number. Not hidden, not optional: it does not exist.
What we cannot promise
This is the part most privacy pages leave out.
- Small groups can leak by inference. The system never reveals who submitted what. But in a group of three or four, someone who knows the others well may be able to guess whose number set the cap. Rounding makes this harder. It does not make it impossible, and no software could.
- Anyone with the link can open the room. That is the access model: no accounts means no way to check who a visitor is. Room links contain 128 bits of randomness, so they cannot be guessed or found, but they can be forwarded.
- One person can answer more than once. The browser token stops accidental duplicates. It cannot stop somebody deliberately using a second device or a private window. We are not going to pretend otherwise by asking for verification we don’t want to collect.
- Infrastructure sees network-level data. Like every website, requests to this one reach a server that can see IP addresses and browser user agents. We do not store them. Our hosting provider processes them to deliver the site and to block abuse.
Third-party services
| Where | What runs |
|---|---|
| Private room, result and organiser pages | Nothing. No analytics, no advertising, no pixels, no embedded widgets. |
| Public pages such as this one | Privacy-preserving site analytics (page views and loading performance, no cookies, no cross-site identifiers) and Google AdSense, which does use cookies and does profile for advertising. |
| The create form | Cloudflare Turnstile, a bot check that runs without cookies or behavioural profiling. It never runs when someone is answering a room. |
| Hosting and database | Cloudflare Workers and Cloudflare D1. |
Advertising
This site is free and is paid for by advertising on its public pages: how it works, the FAQ, and the use-case guides. Those ads are served by Google AdSense, which sets cookies and may use your activity across sites to choose what to show you. Google’s handling of that data is described in its partner-sites policy.
No advertising runs on a private budget room. Not on the question page, not on the result, not on the organiser view. That is enforced in three independent ways: the room is built as a separate application that contains no ad code, the ad script is added only to public pages, and the security policy sent with every room page forbids the browser from contacting any external site at all. If an ad were ever added there by mistake, the browser would refuse to load it and our tests would fail.
In the EEA, the UK and Switzerland you are asked for consent before personalised advertising runs. That prompt appears on public pages only. It will never interrupt someone answering a budget question.
Cookies
The product itself sets no cookies. Your browser stores a random token per room in local storage so you can edit your own answer. Clearing site data removes it, and the room still works. You simply cannot edit an earlier answer any more.
The language you are reading in is stored the same way, so the site opens in it next time. It is a display preference, it is never sent to us, and clearing site data resets it to whatever your browser asks for.
Cookies on this site come from advertising, on public pages only. A private budget room sets no cookies of any kind.
Our own measurements
We count events, such as a room was created or a result was reached, as daily totals grouped by country and by the broad type of referrer. There is no record of a single visit: each event increments a counter and nothing else is written.
These counters never contain an amount, a room title, a room link, a browser token or any identifier. We use them to answer one question: does this tool actually get used the way we think it does?
Who runs this
Budget Cap is made by Global Anomaly. It is the only party with access to the database, and there is no analytics vendor, advertising network or data processor receiving anything from a private room.
Contact
Privacy questions: helpdesk@budgetcap.org. Anything else: helpdesk@budgetcap.org.
Because rooms are anonymous and short-lived, we usually cannot identify the data relating to a specific person in order to act on a request about it. The most reliable way to remove a room is to delete it from the organiser’s link, or to wait for it to expire.