Skip to main content
About Horizon RunwayOpen the app

Trust & security

We hold almost nothing.

Horizon Runway forecasts future balances. It is a calculator, not a bank — and that shapes every answer below.

This page is maintained by the Horizon Runway team to answer common security and privacy questions about Horizon Runway. It describes our own practices and the platform features we rely on. It is not an independent audit, a certification, or a legal guarantee.

What we hold

Forecast data, on the device
Balances, bills, income, and scenarios are stored in the browser by default and never leave it unless cloud backup is switched on.
Cloud backup, if enabled
One copy of the same forecast data, held on Lovable Cloud and readable only by the signed-in account. It can be deleted from Settings at any time.
Account identity
An email address, and — if the person signs in with Google — the identifier Google returns. Used for sign-in and support, nothing else.
Support and feedback messages
What someone chooses to write to us, and our replies.
Operational records
Standard request logs and crash reports produced by the hosting platform, used to keep the service working.

What we never collect

No bank credentials
There is no field for a bank username or password anywhere in Horizon.
No bank connections
Horizon does not connect to financial institutions today. If that ever ships it will be opt-in, and this page will change first.
No card or payment details
Payments, when they start, are handled entirely by Stripe. Card numbers never reach Horizon's systems.
No Social Security or government ID numbers
Horizon has no use for them and no place to put them.
No credit reports or scores
Horizon does not pull, hold, or resell credit data.
No advertising trackers or third-party analytics SDKs
Horizon is not funded by advertising and does not sell or share data.

Subprocessors

Lovable

Application hosting and content delivery.

Standard web request metadata: IP address, user agent, timestamps.

Lovable Cloud

Managed database, authentication, and optional cloud backup.

Account email, and forecast data only for people who turn cloud backup on. Encrypted in transit and at rest by the platform.

Resend

Transactional email delivery — invites, replies, account mail.

Recipient email address and the contents of the message being sent.

Googleonly if used

Optional sign-in with Google.

Only for people who choose it: the email address and account identifier Google returns.

Stripeonly if used

Payment processing for paid plans.

Billing details entered directly with Stripe. Horizon receives a subscription status, never card data.

We keep this list current. If we add a subprocessor that can see customer data, we update this page, and organizational customers on a signed agreement get notice before the change takes effect.

Access & authentication

Accounts are optional
Horizon works fully without an account. Signing in exists to sync devices and survive a cleared browser.
Row-level isolation
Every stored record is scoped to its owner at the database level, so one account's data is not reachable from another.
Least privilege
Administrative access is limited to the founder and used only for support and incident response. There is no shared login.
Encryption in transit and at rest
All traffic is served over HTTPS. Cloud backups are encrypted by Horizon with a per-account key before they are written, on top of the managed platform's own at-rest encryption.

Retention & deletion

Device data
Lives until the person clears it. Settings → Clear everything removes it immediately, along with any cloud copy.
Cloud backup
Kept while the account exists. Deleting the account removes it; backups age out of platform storage within 30 days.
Support and feedback
Kept for up to 24 months so we can follow a conversation, then deleted. We erase sooner on request.
Operational logs
Retained by the hosting platform on its standard short rolling window and used only for reliability and abuse handling.
Erasure requests
Email support@horizonrunway.com and we erase everything held for that address. We acknowledge within three business days and complete within 30 days.

Continuity

Nothing to restore, for most people
Because forecasts are device-local by default, a platform outage does not take a person's data with it.
Managed backups
The cloud database is backed up by the managed platform with point-in-time recovery.
Portable by design
One tap exports a plain JSON copy of everything. If Horizon disappeared tomorrow, the data still opens in a text editor.

Accessibility

Horizon targets WCAG 2.1 AA. We run automated accessibility checks across every public route, keep tap targets at 44px or larger, respect reduced-motion preferences, and support keyboard navigation and screen readers throughout. A formal VPAT/ACR is not yet published; we will prepare one on request for an organizational evaluation.

Who is responsible for what

Infrastructure

Platform
Hosting, network, patching, physical security.
Horizon
Choosing the platform and configuring it correctly.
You

Data storage

Platform
Encryption at rest, backups, availability.
Horizon
Per-account isolation rules and keeping stored data minimal.
You
Deciding whether to enable cloud backup at all.

Access

Platform
Authentication service and session handling.
Horizon
Which routes require an account, and admin discipline.
You
Protecting their own sign-in and device.

Financial decisions

Platform
Horizon
An accurate forecast from the numbers entered.
You
The numbers entered, and the decision made from them.

Checks, with dates

A security page without dates is a brochure. These are the checks we actually run, when each last ran, and the ones we have not done yet.

Dependency vulnerability scan
August 2, 2026 · today
Run across the full package tree. No known high or critical advisories outstanding.
Database security review
August 2, 2026 · today
Row-level security confirmed enabled with an owner-scoped policy on every table holding customer data.
Backup restore drill
August 2, 2026 · today
A cloud backup was decrypted, schema-validated, and compared against the device copy. Anyone with cloud backup on can run the same check from Settings.
Automated accessibility sweep
August 2, 2026 · today
Every public route checked against WCAG 2.1 AA rules. No violations outstanding.
Third-party penetration test
Not yet
None yet. Planned before we charge anyone. We would rather say that than let the omission be discovered.
Independent security audit (SOC 2 / ISO 27001)
Not yet
None yet, and we do not claim one. Our posture rests on holding almost nothing rather than on a certificate.

Status

All systems normal

Confirmed August 2, 2026 · today

Horizon Runway is up and forecasting normally.

No customer-affecting incident, and no data loss, since the beta opened. If that changes, this line changes first and affected people hear from us directly.

This status is maintained by hand, not by an automated monitor. We would rather tell you that than dress up a green dot.

Leaving

Settings → Delete my account closes the account and removes the cloud copy in one step, no email to us and no waiting. We send a receipt to your address confirming it is gone, with nothing in it trying to win you back.

Reporting a security problem

Email support@horizonrunway.com with “Security report” in the subject line. Our full disclosure promise, and what we commit to if something ever goes wrong on our side, is on the data page.

What we are not

Horizon is not a bank, broker, or financial advisor. We don't hold or move money, and we don't guarantee future balances.

Horizon does not hold SOC 2, ISO 27001, PCI-DSS, HIPAA, or GDPR audit status. If you need audited software for your situation, Horizon isn't the right fit yet.

Evaluating Horizon for an organization? Write to support@horizonrunway.com and we will complete your questionnaire and sign a data processing agreement.

Data processing agreement

Our DPA is published in full rather than held back until someone asks: processing scope, subprocessors, security measures, a 72-hour breach notice, retention, and deletion on termination. It is an unsigned template pending outside counsel review, and we are glad to sign yours instead.

Execution checklist

Where this template stands today, before anyone signs it.

  • Full text published — completeEvery clause and annex is readable before you ask for it, including subprocessors, retention, and the 72-hour breach notice.
  • Matches our live trust facts — completeThe document is generated from the same source the trust page renders, so the two can never drift apart.
  • Outside counsel review — outstandingNot yet complete. Treat this as a draft for evaluation, not a signature-ready contract.
  • Governing law named — outstandingPending. The governing state is filled in when entity formation completes.
  • Deal-specific fields completed — outstandingNames, dates, scope, and notice contacts are filled in per agreement — never signed blank.
Confirm the note above to download.

The rest of the detail

The plain-language promise lives on your data, the mechanics in the privacy policy, and the agreement itself in the terms.