Calculation inputs and outputs are never logged or stored. When you send a salary, a filing status, or a state to the API, the figure is computed in memory and returned. Nothing about it is written to a database, a log, or a file. We could not produce a history of your calculations if asked, because none exists.
What we do keep is the minimum needed to run an account: who you are, that you paid, and how many calls you made.
| Stored | Why | Where |
|---|---|---|
| Email address | Identify the account, send billing and correction notices | Cloudflare D1 |
| Stripe customer & subscription id | Link the account to its subscription | Cloudflare D1 |
| SHA-256 hash of each API key | Authenticate calls | Cloudflare D1 |
| Key prefix (first 14 characters) | Let you recognise a key in a list | Cloudflare D1 |
| Plan and account status | Apply the right quota | Cloudflare D1 |
| Monthly call count, per account | Enforce the quota; show usage | Cloudflare D1 |
| Timestamp a key was last used | Help you spot an unused or compromised key | Cloudflare D1 |
This matters if you are evaluating the Service for payroll-adjacent use. Because inputs are never stored, personal data about your employees or contractors does not persist in our systems. It is processed in memory to compute a response and is gone when the request ends.
You need not send names, addresses, Social Security numbers, or any direct identifier — the API does not accept or require them. We ask that you do not send them.
Where you do transmit personal data in a request, we act as a processor on your behalf and solely to return the calculation. A data processing addendum is available on request.
| Who | What they do | What they receive |
|---|---|---|
| Cloudflare, Inc. | Compute (Workers) and database (D1) | Account records above; request metadata such as IP and timestamp, retained per Cloudflare's own policy |
| Stripe, Inc. | Payment processing and subscription billing | Email, billing details, payment method — held by Stripe, not by us |
We do not sell personal information, and we do not share it with anyone other than the sub-processors above, except where required by law.
Account records are kept while the account exists. Cancelling a subscription does not delete the account — it reverts to the free plan, keeping your key and usage history so you can return. To delete everything, email us and we will remove the account and its records within [30] days, except where we must retain billing records for tax or accounting purposes.
Usage counts are per calendar month and are retained as account history.
Depending on where you live, you may have the right to access, correct, port, or delete your personal information, or to object to its processing. Because we hold so little, most requests resolve quickly. Email [support@DOMAIN] and we will respond within [30] days.
We do not use personal information for automated decision-making or profiling.
No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you promptly and describe what happened.
The Service is a developer tool for businesses and is not directed to children under 13. We do not knowingly collect their information.
We may update this policy. For material changes we will email the account address and update the effective date above.
Studio Ropewalk, LLC — [support@DOMAIN]