Legal
Privacy Policy
Effective 21 September 2026. English.
What Live Zero Path stores on this origin. This policy describes our practices; it is not a government registration document. Terms cover the account contract.
Who is responsible
Live Zero Path is operated by Darren Chin as an individual operator, who is the data controller for the personal data described here. We are not a licensed financial institution, bank, broker-dealer, or investment advisory firm.
Where data is stored
Member data is stored on servers in Singapore. Backups we keep for recovery are stored in the same region.
Access from other countries
If you access the service from another country, your data is processed in Singapore as described above. Processors listed below may handle data in their own regions when you use their services.
Children
Accounts are for people aged 18 or older. If you enter information about children in your household book, you are responsible for having a lawful basis to do so. Live Zero Path is not directed at children as account holders.
What we do not take
We do not accept or persist PAN, CVV, or bank-login passwords. Checkout is hosted Stripe or in-app purchase. We may keep last4 and processor ids after Plus, not the card number.
Account
We do not collect a member legal name. Passwords are stored as hashes when you agreed to the terms — not as readable text. Profile fields you set (including a birth year — approximate is enough — sex, height, weight, currency, country) stay because FIRE, Health, and You need a whole-year age and those body facts. We do not collect a member calendar birthday. Invite names and invitee addresses you save under Household — stored for a future share; we do not email the invitee yet. Sessions: HttpOnly refresh cookie, CSRF cookie, access token in memory (not localStorage). We may store IP, a short user-agent string, and a coarse location (city / country when the edge provides it) on the session. Not GPS.
Security in brief
Passwords are stored as one-way hashes, not readable text. Login email uses the identity-column treatment described below. Sessions use HttpOnly cookies and in-memory access tokens. Connections to this origin use HTTPS. Household amounts and balances are not encrypted at rest; owner checks stop other members from reading your ledger.
How login email is stored
Your login email lets us mail you and show it in Settings. It is not kept as plaintext in the database identity columns used for lookup. Someone with only a stolen copy of those columns cannot search by your address and find your household. Invitee addresses saved under Household use the same identity-column treatment.
If someone has the running app and its secret keys and the database, they can read login emails. We do not claim otherwise. Database copies from before this policy date may still contain a plaintext login email, a full name, and a calendar date of birth.
Household data you type
Owner-scoped ledgers. Another user cannot read them. Household amounts stay in a form the app can calculate. We do not encrypt net worth or balances. If you type an email address into notes, that text is stored as you wrote it. Names you type on accounts, kids, nominees, or invites are stored as you wrote them. We do not collect government ID / NRIC / SSN on policies. We do not collect policy numbers. Fitdays import is parsed in the browser before you save logs. Import may fill weight; body-composition extras are not saved.
Public pages
Figures in the public FIRE and Path to Zero calculators are not saved. Contact from the landing or signed-in Support stores the message. Public contact requires an email so operators can reply; that identity field is not a plaintext email column. The Contact message and subject are stored as you wrote them. Signed-in Support may attach a file (image, PDF, text, or log, up to 5 MB). Operators may read those messages and files.
Payments and sign-in
During the preview period, Plus is not billed on this origin and we block new paid subscriptions. Google / Apple / Stripe (or app stores) handle pay or sign-in when those flows are open. They still see the email you use with them. Google / Apple may still see the name on their account; we do not keep a copy. When a paid plan exists, we keep subscription and invoice metadata needed to show your plan — not the card number. Admin processor secrets are encrypted.
Processors
Cloudflare Turnstile may run when that Admin Enable is on (bot check; Cloudflare sees the widget token and visitor IP). MAIL / SES sends confirmation, password-reset, and email-change letters only; those letters are addressed to your inbox. Live FOREX fetches a USD rate map; the request does not include names or balances. When Market data is enabled we fetch a delayed last price for tickers you listed. The market-data provider sees the symbol, not shares or cost. If you already used Refresh marks on a holding, we may refresh that delayed last without another click.
We do not sell or share personal information for cross-context advertising. We do not send household ledgers, health logs, or notes to an LLM.
Export and delete
Settings → Privacy & data: download the household money file (profile, accounts, cash flow, lots, funds, policies, children — name and birth year) after you confirm it's you — not life vision, health logs, or invoices — or clear household data (books and plans go; login and subscription stay — continue, then confirm it's you and type CLEAR) or delete the account (continue, then confirm it's you). Delete wipes owned rows, then the user. When this login had a Stripe Customer, we ask Stripe to delete the billing customer; local books still wipe if Stripe fails. Contact messages you sent are deleted with the account or when you clear household data, including files. Security events stay as the action and time, without your email or IP. Demo and season overlays do not write your real household.
Logs
Request id may be logged. Authorization, cookies, passwords, MFA codes, tokens, account numbers, IBAN, card-like numbers, and email addresses are not meant to be kept there.
Changes to this policy
We may update this policy. The date at the top is the current version. Continued use after a change means you accept the updated policy. The Terms of Service govern your account contract.
Contact
Questions: hello@livezeropath.com or Contact on the home page. UTF-8 names and messages are accepted.