True Returns
Menu

TrueReturns LLC

Privacy Policy

Last updated: September 2026. This policy describes how we handle information on yourtruereturns.com.

Overview

Your True Returns is operated by TrueReturns LLC. You can use our tools in two ways:

  • As a guest, without an account. Guest data is stored in your browser and is not sent to our servers.
  • Signed in with Google. When you sign in, we create an account for you and store the properties you save to that account in our database, so they are available on your other devices.

Your Crypto Returns stores data only in your browser, whether or not you are signed in. We also receive the information you send through our contact form.

Using the tools as a guest

Without signing in, the property tools (Property Returns and Property Portfolio) and Your Crypto Returns save your entries in your browser's localStorage on your device. That data is not uploaded to our servers, and we cannot see it.

Guest browser storage can include:

  • Properties: property names and types, values, loan and mortgage details, taxes, insurance, HOA fees, rental income and expense assumptions, projection assumptions, and any tenant names, lease end dates, and notes you enter.
  • Crypto holdings: asset symbols and names, quantities, cost basis, current values, realized gains, staking or yield income, fees, and notes.

Guest data can be lost if you clear your browser data, switch browsers, or use a different device. You can export a JSON backup file to your device and import it later. Backup files are stored wherever you save them; treat them like any sensitive financial notes.

Signing in with Google

Accounts are created only through Google sign-in. We do not receive or store your Google password. When you sign in, Google shares the following with us, and we store it in our database:

  • your name, email address, and profile photo address (URL); and
  • your Google account identifier.

We request only basic profile and email permissions and do not use Google sign-in to access other Google services.

We also store a session record (a random session identifier, your account ID, and an expiry time) so you stay signed in. Sessions expire after a period of inactivity, and signing out removes the session for that browser.

When you are signed in, your profile photo is loaded directly from Google's servers and shown in the site header and on your account page.

Cloud property portfolio (signed-in users)

When you are signed in and save a property, or choose to import properties from this browser into your account, the property is stored in our database and linked to your account. This can include:

  • property name and type (for example, home, rental, second home);
  • purchase price, down payment, current value, loan balance, interest rate, remaining loan term, mortgage payment and payment type, property tax rate or amount, homeowners insurance, and HOA fees;
  • rental income, vacancy, maintenance, and property-management assumptions;
  • growth and projection assumptions, and any extra principal payments;
  • notes, tenant information, and lease end dates you enter;
  • the dates you last reviewed your assumptions, and when each record was created and updated.

We do not ask for or store bank or brokerage account numbers, card numbers, Social Security numbers, or login credentials for financial institutions, and we do not connect to your financial accounts.

Data stored in our database is accessible to TrueReturns LLC as the operator of the service. Within the app, your cloud properties are available only when you are signed in to your account.

Signing in does not delete guest data already saved in your browser, and importing does not remove the browser copy.

Retirement accounts (Your 401k Returns)

As a guest, what you enter in Your 401k Returns is used only to calculate results on the page. It is not saved in your browser or sent to our database, and it is gone when you leave or refresh the page.

When you are signed in and save a retirement account, it is stored in our database and linked to your account. This can include:

  • account name, provider name, plan type, and whether it is with a current or former employer;
  • current balance and its as-of date, vested percentage, account start date, and a history of the balances you save;
  • annual salary, your contribution rate or amount, Traditional/Roth split, and your employer's match or contribution formula;
  • salary growth, expected return, inflation, and expense-ratio assumptions; and
  • your birth year (not your full date of birth) and target retirement age, used for projections and IRS catch-up contribution limits.

We do not ask for plan account numbers or plan login credentials, and we do not connect to plan providers. Deleting a retirement account also deletes its saved balance history.

Information about tenants

For rental properties, you can enter a tenant name, a lease end date, and free-form notes. We do not collect information about tenants on our own — it is stored only if you enter it. Guest entries stay in your browser; entries you save to your account are stored in our database. Please enter only what you need, and make sure you are permitted to record it.

Contact form

When you submit the contact form, we collect your name, email address, optional topic, and message. The message is sent to us as an email through our email delivery provider, Resend, with your email address set as the reply-to address. We use Resend only to deliver email — we do not sell contact form data.

To limit abuse, our server temporarily keeps your IP address in memory to count recent submissions; the count resets after 15 minutes and is not written to our database. Contact messages may be retained in our email inbox for as long as needed to respond and maintain ordinary business records.

Service providers

We use these service providers to run the site:

  • Google — sign-in (OAuth) and hosting of your Google profile photo.
  • Vercel — website hosting. Like any web host, Vercel processes technical request information such as IP addresses and browser details to deliver the site.
  • Neon — our PostgreSQL database, which stores account, session, cloud property, and retirement account data.
  • Resend — delivery of contact form messages.

Cookies and browser storage

We use cookies only for sign-in and security. They are set by our authentication library (Auth.js) and are not used for advertising or analytics. Because each page checks whether you are signed in, the CSRF and callback cookies below are set even if you never sign in:

  • authjs.session-token — set only after you sign in, to keep you signed in. It expires after 30 days of inactivity by default, or when you sign out.
  • authjs.csrf-token — protects sign-in and sign-out requests from forgery.
  • authjs.callback-url — remembers which page to return to after sign-in.
  • Short-lived sign-in security cookies (such as authjs.pkce.code_verifier) used during Google sign-in, which expire within about 15 minutes.

On secure (HTTPS) connections these cookie names may carry a __Secure- or __Host- prefix.

We also use your browser's localStorage and sessionStorage on your device:

  • guest property and crypto data, as described above;
  • which browser properties you have already imported into your account, and whether you chose to keep your cloud portfolio instead of importing;
  • for the current browser session only (sessionStorage): if you chose “Remind me later” for the annual property review or “Decide later” for importing.

Analytics and advertising

We do not currently use third-party analytics or advertising trackers on this site. If that changes, this policy will be updated.

Keeping, exporting, and deleting your data

  • Guest data: you can delete individual properties or crypto holdings, clear saved browser properties or crypto holdings in each tool, or clear your browser's site data.
  • Cloud properties: while signed in, you can delete individual properties and export a JSON backup of your account's properties. Deleted properties are removed from our database. Cloud properties you do not delete stay stored until they are deleted.
  • Retirement accounts: while signed in, you can delete individual retirement accounts in Your 401k Returns; the account and its saved balance history are removed from our database.
  • Account: account deletion is not yet available in the app. Your account, profile, and sign-in records remain stored until they are deleted. To ask us about deleting your account and cloud data, email hello@yourtruereturns.com.

Preview product pages

The Your Stock Returns page shows illustrative demo data only. It does not connect to brokerages or live accounts, and it does not store personal financial data.

Security

Database credentials, sign-in secrets, and email API keys are stored as server environment variables and are not exposed to browsers. Cloud property data is read and changed only through requests tied to your signed-in account.

Changes to this policy

We will update this page when our practices change and revise the “Last updated” date above.

Contact us

Questions about this policy? Email hello@yourtruereturns.com or use the contact form.