Privacy, in plain language

Ordinary calculations stay in your browser. Real-world measurement contributions are optional, explicit, and designed to avoid personal household information.

Calculator usage

The calculator processes scenario inputs in your browser. We do not require an account, name, email address, or exact location to calculate a result.

Optional measurement contributions

If you deliberately submit a measured reading, we store the appliance description, canonical device identity, rated power, measured energy, duration and method, country, optional broad region and model, climate and grid context, tariff context, cohort and campaign classification, quality and trust grades, evidence status, consent version, a random reading-passport ID, a hashed device-local contributor token, and submission time. The token helps count repeat contributors without asking who you are. Do not include personal information in free-text fields.

Private meter evidence

You may attach a meter or charger image. Before upload, the contribution form redraws supported images to remove embedded camera metadata. Evidence is stored separately from structured observations, is available only in the protected review console, and is never included in public benchmarks or data exports. Avoid names, addresses, account numbers, faces, and reflections in the image.

Aggregated research and deletion

Contributed measurements may be used to improve aggregated benchmarks and calculation accuracy. We do not sell identifiable household profiles. After a contribution, PowerCost Lab provides a private deletion receipt. The browser may save the most recent receipt on that device as a convenience, but the server stores only its cryptographic hash. Anyone holding the receipt can view review status and delete both the associated anonymous observation and its private evidence image; we cannot recover a lost receipt.

Quality review and publication thresholds

Measurements are graded by provenance and context, checked for implausible or duplicate records, and reviewed before becoming benchmark candidates. Evidence is reviewed separately. Cohort benchmarks require at least 10 approved, evidence-verified observations across at least three canonical models and two countries.

Analytics and advertising

To limit automated abuse, contribution and private-passport endpoints use a rotating daily hash of the network address supplied by our hosting provider and delete old rate-limit windows. The raw address is not stored in the observation. Our own publishing measurement uses daily aggregate counts for page-family loads and copied calculator results; campaign measurement similarly records aggregate stages without creating visitor profiles. Google Analytics loads only after a visitor chooses “Allow analytics”; it measures site usage with cookies while advertising storage, Google signals, and ad-personalisation signals remain disabled. Visitors can withdraw that choice through “Analytics settings.” Display advertising remains disabled until a publisher account, site approval, and Google-compliant advertising consent controls are ready. Private passports, contribution forms, evidence, authentication, and operator pages are excluded from ad inventory.

Run your own scenario

Use your tariff, currency, and real usage.

Open calculator