Effective during Horizon Runway Beta.
Horizon Runway LLC provides Horizon Runway and is responsible for the data practices described here. Horizon Runway runs on your device by default, with an optional cloud account for syncing across devices.
Stored on your device
By default, everything lives in your browser's local storage — not on our servers.
- Money data you enter: balances, income, bills, habits, plans, and scenarios.
- A local backup copy, so a partial write can't lose your work.
- Your onboarding draft, plus small preference flags.
Clearing browser data or using "Clear everything" in Settings removes it all. Without an account, there is no server copy to restore.
Optional cloud backup
A free Horizon Runway account keeps your forecast in sync across devices and protected if browser data is cleared. Every feature works without it.
If you sign up, we store one copy of your money data on Lovable Cloud. It is sent over HTTPS. After it reaches our server, it is encrypted with a key derived for your account for database storage, on top of the platform’s encryption at rest. Access controls restrict the row to your signed-in account. It is not end-to-end encrypted: our server can decrypt the copy while serving your own sync request. We do not analyze or share it, and you can wipe the cloud copy from Settings at any time.
Not collected
- Bank credentials or bank connections.
- Advertising pixels, cross-site trackers, session recorders, or behavioral analytics.
- We do not sell your personal information or share it with data brokers.
Anonymous usage
Share anonymous usage in Settings is off by default. When on, Horizon Runway keeps a local log of event names and timestamps — no amounts, descriptions, dates, or account details. You can review or clear the log, and turning it off wipes it instantly.
Sending that log to us takes a second, separate opt-in. Until you turn it on, the log stays on this device. When it is on, Horizon Runway posts the same event names and timestamps you can see in Settings, along with a random per-install identifier that is not tied to you or your account and resets whenever you clear browser data.
Third parties
Lovable. Horizon Runway is served by Lovable, which processes standard request metadata like IP address, User-Agent, and requested URL. Your forecast contents stay on your device unless you enable cloud backup. It also receives a scrubbed diagnostic report only if you separately turn on crash reporting in Settings.
Lovable Cloud. Stores your cloud copy only if you create an account, used solely for sync and recovery. It also receives anonymous usage events if you turn on both usage opt-ins.
Fonts. Instrument Sans and Instrument Serif are bundled with the app. No third-party font CDN is contacted.
Errors
Crash reporting is off by default. If you turn it on in Settings and Horizon Runway catches a crash, it sends the error type, a scrubbed message, up to five stack frames, the current page path, locale, and app version to our hosting platform. It does not contain balances, transactions, income, form values, or anything you've typed. Turning it off clears any queued report and stops future diagnostic uploads.
How long we keep it
Data that reaches our servers is deleted on the following schedule:
- Anonymous usage events (only if you turned both usage opt-ins on) — 6 months.
- Coarse region counts for a page view — country, region, city, no identifier — 6 months.
- Anonymous “I'd want this” taps, such as the bank-sync waitlist toggle — 1 year.
- Delivery history for replies we sent you — 1 year.
- Short-lived counters that keep forms from being flooded — 2 days.
- Your record of agreeing to the Terms — including the plan and price shown at checkout — kept for at least 3 years, or 1 year after your subscription ends, whichever is longer
Each checkout acceptance record is kept for the longer of 3 years from the date of acceptance, or 1 year after the applicable subscription ends. After that it is deleted within a reasonable administrative period, around 90 days — unless it still needs to be kept for a legal hold, a pending dispute, a chargeback, a fraud or security investigation, or another legal obligation.
Messages you send us — a waitlist signup, an access request, a press or contact message, feedback on an invite — are kept until you ask us to remove them. Ask through Support and we will delete the records tied to that address.
Your control
Edit or remove anything from Settings at any time. With cloud backup, signing out or deleting your data removes both the cloud and local copies. Your data is always yours to keep or delete. For exports, wipes, and the plain-language promise behind all of this, see Your data.
Changes
We may update this page as Horizon Runway changes. Material changes will be surfaced in the app.
Plain-language guidance from the Horizon Runway team. Not a substitute for legal or financial advice.