RetIQ’s founding promise is simple: your plan never leaves your device. No accounts, no cloud sync, no server that receives your numbers — there is no mechanism by which we could see them.
But there’s one moment when your plan does exist as a file on the outside: when you export it. You export to back it up, to move it to another device, or to hand it to an advisor. Up until now, that file was as private as the folder you saved it in. Today, on both the web app and the iOS app, you can lock it.
Encrypted on your device, before it goes anywhere
When you export your plan as JSON, RetIQ now offers a “Protect this file with a password” option. The file is encrypted on your device — not on a server, not after transmission — using AES-256-GCM with a key derived from your password via PBKDF2-SHA256 at 600,000 iterations. That is the same standard password managers use to protect your vault. The bytes that leave your device are ciphertext. Without your password, they are noise.
And because the format is identical across platforms — verified, not just claimed — a file you lock on the web app opens on iOS, and a file you lock on iOS opens on the web. Lock it once, move it anywhere.
There is no recovery. That’s the point.
Here is the part we want to be unmissable, because it’s the honest trade this feature is built on: if you forget the password, the file cannot be opened — by you, by us, by anyone.
There is no backdoor, no “forgot password” reset, no support ticket that can recover it. That’s not an oversight; it’s the entire point of encrypting it. The moment we could open your file without your password, so could anyone else who got it — including someone who got past us. The security of a lock is measured by the fact that nobody has a spare key, and we refuse to keep one.
So the one piece of advice that matters: choose a strong passphrase and keep it somewhere safe. A few random words (“correct horse battery staple” is the famous example) beat a short complex password every time, and you can actually remember it. Write it down somewhere secure, or use a password manager — the same tool that protects files like this.
How to use it
On the web app, go to Save → Save as JSON. Tick “Protect this file with a password,” enter and confirm your passphrase, and export. To open it later, load the file and enter the password.
On iOS (arriving in the v3.7 update), the Plans sheet’s Share / Export button offers the same option, and importing a protected file asks for the password. Unprotected JSON and HTML files work exactly as before on every platform — this is strictly additive, for when you want it.
Your retirement plan is one of the most complete pictures of your financial life that exists. We built RetIQ so that picture never leaves your device. Now, on the rare occasions it does, it goes out locked.
Try it free — no account, no card required. Your data never leaves your device.
Try RetirementIQ →