Privacy

RangefinderInvest Privacy Policy

Effective September 14, 2026 · Kalman Software LLC

The short version: RangefinderInvest sends no accounts, holdings or plan anywhere on its own. Your portfolio is stored in one local file, and Kalman Software does not receive it, sell personal information, or track how you use the app. Optional connections are disclosed below.

Your app data

Accounts, holdings, transactions, imported statements, plans, settings, and backups are stored on your device. RangefinderInvest has no account or cloud sync, and Kalman Software does not receive that information.

RangefinderInvest has no usage analytics or crash reporter. Deleting the app and its data folder removes its local data; Kalman Software has no server copy.

The app never asks for brokerage credentials, connects to a brokerage, places a trade, or uploads a portfolio automatically. You enter balances, import supported CSV exports, and review and place every order yourself.

Network requests

Market-data requests go directly from your device to the provider you use: Tiingo, Yahoo Finance, tsp.gov, or treasury.gov. They contain ticker symbols and date ranges, not holdings, quantities, balances, account names, or plans. Provider terms apply to those requests.

About daily, but never sooner than 20 hours after the last successful automatic check, the app asks rangefinderinvest.com whether a newer version exists. It sends the product, app version, operating system, whether this is the first successful check, and a random retry receipt during that first check. The receipt prevents a lost response from counting the same install twice; the app discards it after a successful response, and the server keeps only its SHA-256 digest for up to 90 days. We retain aggregate counts by product, version, and operating system and do not use the request to identify or track anyone. You can turn automatic update checks off. Microsoft Store builds use the Store's update system instead.

Optional AI access

AI features are off by default. If you enable one, the portfolio context and tool results you allow go directly to the provider you configure, such as Anthropic, DeepSeek, LM Studio, or another OpenAI-compatible endpoint. Kalman Software does not proxy or receive that content. A local model such as LM Studio can keep the entire flow on your device.

Hosted-provider API keys are safeStorage-encrypted into opaque app-owned blobs beside the app's config file, outside the portfolio database and its backups. The renderer receives configured/error status only; main decrypts the selected key only to call that provider.

The same app-defined tools can be exposed to an external AI client. On macOS and Linux, the local socket's file permissions exclude other operating-system accounts, not other programs running as you. Do not use or rely on the Windows 0.45.1 named-pipe connector: Task 13's two-account test disproved its account-private claim, and the 0.46.0 source candidate disables it. Use the separately enabled, access-token-protected loopback HTTP address on Windows. A second switch can open that address to other devices; both are off by default, and the network option uses plaintext HTTP. Whatever a connected client reads is handled under that client's configuration and the AI provider's terms. The tools can read and compute; the only write creates a target-model proposal that you must approve in the app. They cannot edit holdings, delete data, connect to a broker, or place a trade.

Buying a license

Stripe processes direct purchases. Kalman Software receives the name, email address, billing location, product, amount, and order reference needed to fulfill and support the order. We never receive or store your complete card number. License activation is verified offline.

Website and email

Cloudflare hosts this site and may process standard technical information such as IP addresses and browser information. We use cookieless aggregate analytics and count downloads. We do not use advertising cookies or cross-site tracking.

If you email us, we keep your address and message only to respond or provide support. Addresses collected through the former Windows waitlist remain stored as historical records; the retired endpoint cannot add records or send email.

Sharing and selling

We do not sell personal information or share it for advertising. Information is provided only to services needed to run the business, such as Cloudflare, Stripe, Resend, and Microsoft, or when legally required.

Your choices

You can disable market-data requests, automatic update checks, and optional AI features. You may email us to ask what personal information we hold about you or request its correction or deletion, subject to purchase records we must retain for legal and accounting purposes.

Changes

If our data practices change, we will update this page and its effective date.

Contact

Kalman Software LLC · [email protected]