Where your plan lives
Compensation data is sensitive. This page explains plainly what Arrange stores, where, and what each kind of sharing exposes. It will grow as the product does.
Local first by design
Arrange runs in your browser and keeps a working copy of your plan in browser storage, which is why editing is instant. Without an account, plans stay on your device and are not sent to us. Signing in adds sync, so your plans follow you across devices.
When you sign in
Signing in enables sync, sharing, and review. Identity is handled by WorkOS AuthKit with standard sign-in providers; Arrange never sees or stores your password. Synced plans, review requests, and decision records are stored in Convex, our hosted database, and every change is validated server side against your membership in the plan.
What sharing exposes
- View-only links show the current plan structure and costs as a read-only page. They never include review requests, comments, member lists, or any editing controls. Anyone with the link can see the page, so treat it like any document link you send.
- Reviewer invites admit one signed-in person, recorded under their verified identity. Reviewers can comment and decide funding requests; changing plan structure stays with editors.
Money and estimates
Benchmark rates that ship with Arrange are public estimates, labeled as such. Rates you enter yourself stay in your plan and are shown only to people with access to that plan.
Analytics
We use PostHog for product analytics: which features are used and where people get stuck. Events describe actions, such as a plan being created or a scenario being forked. The contents of your plan, including names, rates, and structure, are not part of analytics events. Usage is anonymous until you sign in.
What we do not do
- No selling or sharing of your planning data with third parties.
- No training of models on your plans.
- No payment details collected today; billing has not opened.
Questions or a security report: hello@witharrange.com. We read everything.