Data minimisation

What Neto does not request

Calculators and report creation work without an account, name, phone number or email address.

  • A Neto-specific password, phone number or full name
  • Company name, free-text job title or CV
  • A payslip file, bank details or financial documents
  • Identity number, address or date of birth
  • Form 101 sex classification, child counts or age groups selected in the credit wizard
  • The locality name or locality-search text
  • Advertising identifiers, cross-site tracking or email inside the compensation record

Consent-based storage

What a full report stores

Salary amounts and combinations of employment attributes are sensitive. Reports are never exposed as individual records.

  • A required current scenario and an optional, separate target scenario
  • Closed occupation, education and employment categories
  • Exact base pay and optional bonus, equity, options and benefit amounts when entered; a blank field remains missing rather than becoming zero
  • Contribution assumptions, the resulting tax-credit point total and calculated results
  • For a locality benefit, only the official rate and cap, never the locality name
  • Submission day, consent version and quality status

Local comparison

Two offers, no salary history

Offer-comparison and negotiation-preparation scenarios, including contracted hours, vacation and office days, remain in temporary tab memory. They are not added to the URL, local storage, the report database or analytics.

Neto keeps work terms separate from money. It does not assign a monetary value to vacation or remote work, score an offer or choose a preferred package.

An explicit Share or Copy Plan action sends a text summary to the device share sheet or clipboard. Neto does not create a public salary-bearing link or send the action to analytics.

Local export

A personal copy without a file server

Printing or saving as PDF uses the device print dialog. Neto does not receive the file or report content during export.

The action area, deletion code and deletion controls are excluded from print output. The export action is not sent to analytics.

Control and deletion

A deletion key instead of identity

When a report is created, Neto returns a private deletion code and stores only its cryptographic hash. The code works without an account or contact details.

Accepted reports are retained for up to 36 months, pending reports for 180 days and rejected reports for 30 days. A daily maintenance process deletes expired records, and a new report triggers an additional fallback check.

Product analytics stores only daily aggregate counts from the closed funnel contract for 120 days. The ephemeral session identifier is discarded before storage, no personal event history is created and Do Not Track is respected.

Neto does not accept payslip files in this MVP.

A full report, only with consent

Create a structured report without an account and delete an existing contribution at any time with its private code.