Skip to main content

Navigation

Privacy policy

Page last checked .

Effective date:

Your plan and browser storage

ApplyOrWait checks card eligibility and application timing without an account, email address or credit pull. The tools can store your answers and plan in localStorage on your device. This includes your score, card and bonus history and other answers you entered. Local storage can also contain draft backups, archives of unreadable drafts and a pending-application flag used to remind you to update your plan after an application. Clearing this site's browser data removes these local copies and preferences.

New saved-plan links put your answers in the URL fragment, after #p=. The fragment is not sent to our server in an ordinary website request or HTTP referrer. It is reversible encoding, not encryption: anyone with the copied link can read your answers. Links may remain in browser history, synced history, messages and the services you use to share them. Legacy links using ?p= send their answers to the website host when first opened, before the browser can convert them to a fragment. Share links only with people you choose.

Calendar files are generated on your device. Reminders include a saved-plan link containing your exact score, card history and other answers. Your calendar provider can read those answers. People with access to your calendar may also read them. Opening the Google Calendar option sends the reminder and its plan link to Google; importing a calendar file sends its contents to the calendar app or provider you choose. We do not receive your calendar or its account address.

First-party analytics

We use first-party analytics to understand tool use. There are no advertising pixels, third-party analytics SDKs or application analytics cookies. Analytics records are pseudonymous and session-linked, rather than anonymous: a random session identifier links events from the same browser tab.

We record page views, planner starts, steps and completions, plan saves and copied links, calendar additions, and eligibility-checker use. Clicking a card application link records an apply_link_click event with the recommended card ID, issuer and destination domain, plus decision state, position and plan month when available. Clicking an identified points tool records redeem_link_click with the tool ID, destination domain and, when available, currency and plan month. We do not currently emit a separate generic outbound_click event for other external links.

Events include only known public page paths, device category (mobile, tablet or desktop), approved referring domains and approved landing campaign labels. Unknown paths are not recorded. Unknown attribution, including IP-literal referring hosts and unapproved campaign labels, is blanked. Recommended-product and interaction metadata use catalog IDs, fixed labels and bounded counts. Analytics does not record your answers, goals, credit scores, score ranges, owned-card history, names, email addresses, IP addresses, raw browser user-agent or full saved-plan URL.

The session identifier and landing attribution are stored in sessionStorage, with a memory fallback if that storage is unavailable. Tab closure normally clears sessionStorage, but browser session restoration or tab copying can preserve or reuse it. Tab closure does not delete database records.

Providers, use and retention

Events are stored in our analytics database and used to understand tool usage and improve the site. Hosting provider Vercel processes website requests, and database provider Neon processes stored event records on our behalf. We do not sell these records or share them for cross-context behavioral advertising. Provider processing is different from selling data.

Analytics records currently have no scheduled expiry. There is no automatic deletion or aggregation schedule implemented for these session-linked records. Clearing browser data or closing a tab does not remove records already stored in the database. Hosting providers may process network IP addresses and ordinary request headers; our statement that IP addresses are not stored refers to our analytics event records, not all hosting logs.

Your privacy controls

Do-Not-Track and Global Privacy Control suppress analytics. The analytics_opt_out preference below is stored in localStorage and checked before creating a session identifier and again before sending queued events. If we cannot read that preference, analytics stays disabled. Content blockers can also block /api/e. Already-sent requests cannot be recalled. Clearing site data removes preferences and is not a lasting opt-out.

Browser preference: loading.

Other websites and contact

No affiliate programs are active today, and application links go directly to issuers. Issuers and other destinations apply their own privacy policies and may use cookies. Application and points-tool links do not append your answers and suppress the navigation referrer.

If you email us, email providers process your message and the contact information you choose to send. Correspondence is separate from analytics. Please do not send account numbers, credit reports, personal plan links or sensitive financial documents. Use our contact page for privacy questions, access, correction or deletion requests. We will explain what records we can identify and any limits; we do not require you to create an account.

Policy changes

We will update this page and its effective date when processing changes. New analytics behavior will be described here before it is introduced. Material changes will also be called out on this page so returning visitors can review them.