Last updated: August 7, 2026
Your employees' leave records never reach us. Names, leave dates, hours, medical-leave history — all of it is written to your own browser's storage on your own computer. There is no account to create, no server to sync with, and no database here that contains a single one of your employees.
We couldn't hand your team's data to anyone if we were asked, because we don't have it. Below is the precise, boring detail of what stays put and what doesn't.
What stays on your device
Everything you type into any calculator or into the team tracker is processed by JavaScript
running in your browser and stored locally. Specifically, the tracker writes these keys to your
browser's localStorage:
- lc_team_v1 — your employees: names, hours per week, FMLA year method, every leave period you enter, the team workday settings, the optional company name used to prefill printed forms, and the activity log of changes made in this browser.
- lc_license_v1 — your Pro licence key, if you've activated one.
- lc_file_saved_v1 — a timestamp, so the tracker can tell you when you last saved a company file.
- lc_rated_… — on pages with a star-rating widget, a note that you already rated that page, so you aren't asked twice.
The single-employee calculators also remember your last inputs locally so the page isn't blank when you come back. Same mechanism, same computer, same non-transmission.
Team file and company file. When you use Save file or Connect team file, the tracker writes a JSON file straight to the location you pick, through your browser's file picker. It never passes through us. If you point that file at a OneDrive, Google Drive or Dropbox folder — which is how the tracker supports several people and several computers — then your team's data is in your own cloud account and that provider's privacy terms apply to it. Choose that folder deliberately.
To delete everything: clear site data for leavecalc.com in your browser, and delete any files you saved. That's it. Nothing survives anywhere else, and no request to us is needed.
What does leave your browser
Four things, and only these four.
1. Google Analytics 4
Every page on this site loads Google Analytics 4 (measurement ID G-YSXFCZ6S9H). It
tells us which pages get visited, from where roughly, on what kind of device, and from which
referring site or search engine. Google receives your IP address as part of that, and sets
cookies named _ga and _ga_<id> in your browser to recognise
repeat visits.
We also send a handful of named events so we can see which parts of the site actually work:
calculate when a calculator is run, add_to_calendar,
begin_checkout when a payment link is clicked (with the URL of that link),
tracker_cta_click, and etsy_click. These events carry the page path
and the link clicked — never the values you typed in. No employee name, no date, no
hours figure, no calculation result is included in anything sent to Google.
A browser-level tracking blocker or "do not track" extension will stop all of it, and the site works exactly the same without it.
2. Star ratings
Some calculator pages have a 1–5 star widget at the bottom. Clicking a star sends a single request to our own server containing two things: the page slug and the number of stars. No identifier, no session, no comment box. On the server it's added to a running count and total per page. There is no way to trace a rating back to a person, including by us.
3. Stripe, when you buy something
Upgrade links take you off this site to Stripe's own checkout pages. Stripe collects your name, email address, billing address and card details there and processes the payment as an independent controller under its own privacy policy.
We never see or handle your card number. It is entered on Stripe's page, not ours, and it never touches our servers. What we can see afterwards in the Stripe dashboard is the ordinary merchant view: your email, the plan and amount, the country, the card brand and its last four digits, and the payment status. We use that only to issue your licence, answer billing questions and process refunds.
4. Your licence key, after payment
Stripe returns you to our thank-you page with a checkout session ID in the URL. That page calls a small service of ours, which asks Stripe whether the session is paid and for the buyer's email, then signs a licence key for that email. Our server keeps a record of the session ID, the email and the key it issued — so that reopening the page returns the same key rather than a new one, and so we can resend your key if you lose it. Email addresses of paying customers are the only personal data of any kind that sits on our server.
Cookies
We set no cookies of our own — no login cookie, no preference cookie, no advertising cookie.
The only cookies placed while you're here are Google Analytics' _ga and
_ga_<id>. Local storage, described above, is not a cookie and is never sent to
any server; it just sits on your disk until you clear it.
Server logs
Our web host keeps standard access logs — IP address, timestamp, the URL requested, browser user agent — as every web server does. They exist for security and debugging, are not used to build any profile of you, and are not combined with anything else.
If you email us
Email sent to us arrives in an ordinary mailbox and we keep the thread so we can help you properly and remember what was already tried. Please don't email us employee medical records or completed certification forms — we don't need them, and the whole design of this product is that we never receive them.
Who we share data with
Three companies, each for one job: Google (analytics), Stripe (payments and the licence email), and our hosting provider (serving the site and its logs). Nobody else. We run no advertising pixels, no session recording, no heatmaps, no data brokers, no email tracking, and we have never sold or rented data to anyone. There is no affiliate network here.
Medical information and HIPAA
FMLA records can contain sensitive health information about your staff. Because that information never reaches us, we are not a service provider, processor or business associate for it under HIPAA or any comparable law — there is nothing for us to process. The flip side is equally true and worth stating plainly: the security of those records is entirely in your hands. Use a computer with a password, keep your backups somewhere appropriate, and think about who else can open the browser profile the tracker lives in.
Your rights
For your team's data, the usual rights are already yours in the most direct way possible: you hold the only copy, you can export it to CSV or JSON at any time, and you can destroy it without asking anyone. For the records we do hold — the customer email and licence entry described above — email bogartlg@gmail.com and we'll show you what's there or delete it. Deleting it means we can no longer resend your key, so keep a copy first. We do not sell personal information, and we honour deletion and access requests regardless of which country you're in.
Children
This is a workplace tool for employers and employees. It isn't directed at children, and we don't knowingly collect anything from anyone under 16.
Changes to this policy
If what we collect changes, this page changes with it and the date at the top moves. If a change is material — a new third party, a new kind of data — it will be described here in the same plain terms as everything else, not buried.
Contact
Privacy questions, or anything on this page that reads as vague: bogartlg@gmail.com.