A planning tool asks for inputs that can feel personal even when they are only hypothetical. ETF Compass therefore treats calculation, saving, account sync and advertising as separate product decisions instead of bundling them into one mandatory data path.
The calculator must work before an account exists
A visitor can enter an initial amount, contribution, horizon, return assumption, costs, inflation and tax inputs without signing in. The calculation runs in the application, and local scenarios and preferences can remain in browser storage. This keeps the core educational task available without turning identity into the price of trying the tool.
Local does not mean permanent or indestructible. Browser storage can be cleared, reset or lost with a device, profile or browser change. The interface and privacy notice therefore distinguish a local convenience from a backup promise. A user who wants to test a scenario can do so locally; a user who wants cross-device persistence can make a separate choice.
Cloud sync is a feature, not a hidden prerequisite
Optional sign-in uses Firebase Authentication, and optional cloud sync can store scenarios and settings chosen for synchronization. The account boundary is visible because it changes where selected data is kept. It should not silently activate merely because someone opened the calculator or changed a number.
This separation also gives the product a clearer failure mode. If sign-in or sync is unavailable, local calculation remains the primary path where the browser supports it. A cloud error should not change a formula or imply that an unsynced scenario has been backed up.
Education and calculation have different jobs
The public guides explain assumptions, model limits, ETF risks and source material in ordinary web pages that a reader and crawler can access without running the Flutter application. The calculator turns chosen inputs into an illustration. Keeping those surfaces distinct prevents a precise output from becoming a substitute for context.
The guide can say that a currency stress input is a simple terminal adjustment; the calculator can show the numerical effect. Neither claims that the adjustment captures exchange-rate paths, hedging, fund exposure or a person’s spending currency. The explanatory page and the interactive result are designed to challenge each other.
Advertising is gated away from active calculation work
At publication, browser advertising is disabled while the site is under AdSense review. Static editorial pages include ownership metadata but do not load an ad unit. If advertising is approved later, the rollout is designed around an explicit code switch, Google-managed consent where applicable and a limited guide placement rather than automatic insertion across the product.
Active calculator and dashboard surfaces remain outside that placement plan. This is a usability boundary as much as a privacy boundary: a person changing financial assumptions should not have an ad inserted beside a control or mistaken for part of a result. Approval, consent and ad delivery are separate conditions; none is inferred from the presence of an account identifier.
A useful privacy choice must remain understandable later
People can avoid optional sign-in, clear browser storage and use browser privacy controls. If advertising is enabled after approval, an ad-enabled page must provide the applicable consent and revocation route. The privacy notice is the operational source of truth and must change when deployed behavior changes.
This makes corrections part of product work rather than legal decoration. If a feature begins sending data to a new provider, the implementation, notice and consent behavior need to change together. If a planned integration remains disabled, the site should not describe it as though it were already active.
Current evidence and limitations
The public privacy notice documents browser storage, optional Firebase services, advertising status and user choices. The About page identifies Lambda Software as publisher and provides a correction route. Product tests keep the web-ad switch disabled during review and verify that the static publication does not contain an ad unit.
Those controls reduce unnecessary data flow; they do not make a browser, network or third-party provider risk-free. Readers should use the current notice and provider policies when deciding whether a feature fits their needs. Sources were reviewed on 30 August 2026.
Key takeaways
- Use the calculator locally without making identity mandatory.
- Treat cloud sync, editorial context and advertising as separate, explicit boundaries.
- Update implementation, consent and privacy wording together when deployed behavior changes.
