Privacy policy
How Road User Tools handles calculation data, accounts, API usage, analytics, and cookies.
Last updated: 22 September 2026
Who we are
Road User Tools is operated by Watch & Navy. This privacy policy explains how we handle information when you use the Road User Tools websites, road calculators, REST API, MCP server, and account area.
Information we process
Calculation data
Road User Tools uses the values you provide, including distances, fuel economy figures, prices, units, and other calculation inputs, to perform the calculation and return a result.
Calculations on the public website are performed in your browser. If you enable input remembering, the values you enter are saved in your browser.
For REST API and MCP server requests, we process the information needed to complete and return each calculation. We do not store calculation inputs or results.
Account information
You do not need an account to use the public calculators. An account is required to create and manage API keys and view usage.
We use Firebase Authentication for the sign-in methods offered in the account area. Account information may include your email address, display name, profile image, sign-in provider, and account activity. Watch & Navy does not receive or store your plaintext password.
We use this information to identify and secure your account and, where available, display your profile image. Firebase provides more information in its Privacy and Security in Firebase documentation.
API keys and usage
When you create an API key, we keep the information needed to manage and authenticate it, including its name, permissions, creation and last-used dates, and status. The complete key is shown only when it is created or rotated. Later account views show only part of the key. We do not store the plaintext key.
Treat API keys as secrets. Do not publish them, place them in public client code, or commit them to source control. Avoid including personal or sensitive information in an API key name.
We store monthly request totals by tool and daily successful request counts by API key. This lets you review activity for the previous 7 or 30 days. Usage records do not contain calculation inputs, request bodies, or calculation results.
Connected applications
You can connect external applications, such as AI assistants, to your Road User Tools account. When you authorise an application, we keep the information needed to manage that authorisation, including the application’s name, the permissions you granted, and the creation, last-used, and revocation dates. We also keep the credentials that let the application make requests on your behalf. These are stored in a hashed form and are never stored in plaintext, in the same way as API keys.
Authorising an application does not give it your email address, name, or profile image. It can only use the road tools you approved, on your behalf.
Authorisation records expire automatically when they are no longer usable, and unused application registrations are removed after a period of inactivity. You can remove a connected application at any time from your account, which immediately ends its access without affecting your API keys or other connected applications.
Information you send through a connected application is also handled under that application’s own privacy policy.
Service operation and security
We keep limited operational information to deliver and secure the service, enforce request limits, prevent abuse, and investigate failures. This may include the requested endpoint, response status, timing, and an account or API key identifier. If sign-in fails in your browser, it may also send us a small failure report containing only the sign-in step and a standard error code — never your email address, password, or any free text.
Our ordinary application logs do not contain request bodies, calculation results, authorisation headers, or plaintext API keys.
We also collect limited, cookie-free statistics about REST API and MCP server reliability and use, such as which tools are used, request outcomes, and response times. These statistics do not include calculation inputs or results, request or response bodies, account or API key identifiers, IP addresses, or full user-agent strings. We do not use this information for advertising or personalisation.
Website analytics
If you accept analytics cookies, we use Google Analytics 4 to understand how the website is used and where it can be improved.
Analytics may record pages and tools viewed, selected language, completed actions, settings changes, error categories, navigation, and the domain of links opened from Road User Tools. We do not send calculator values, pasted text, free-text error messages, or complete outbound URLs to Google Analytics.
Google Analytics may also collect standard session, approximate location, browser, device, and cookie information. Google processes this information according to its Privacy Policy and partner sites notice.
Website analytics runs only after you accept analytics cookies. You can change your choice at any time in Settings.
Information stored in your browser
Road User Tools saves functional preferences in your browser so the website works as you expect. These may include your theme, precision, whether to remember calculator inputs, saved inputs when that option is enabled, analytics choice, and documentation display preferences. While you are signed in, your browser also keeps a short-lived cached copy of your account display details (name, email address, and profile image) so pages can show your signed-in state immediately; it expires within a day and is removed when you sign out.
These preferences remain available if you decline analytics. You can clear saved calculator values from Settings or remove the site’s stored data through your browser.
Service providers
We use trusted service providers to deliver Road User Tools:
- Cloudflare helps deliver and protect the service. It may process request and network information, including IP addresses and request content, as needed to provide these services.
- Google Cloud and Firebase provide authentication, account, database, hosting, and security services. They process account, authentication, network, and request information as needed to provide these services.
- Google Analytics processes the optional website analytics and limited service statistics described above.
We do not sell personal information. We share information only with service providers needed to operate Road User Tools, when required by law, or when necessary to protect users, Watch & Navy, or the service.
Cookies and similar technologies
We use cookies for optional website analytics. Functional preferences are stored in your browser separately from analytics cookies. Firebase Authentication may also use browser storage to keep you signed in.
You can accept or decline analytics when the cookie banner appears, or change your choice later in Settings.
How we use information
We use information to:
- Provide calculations, accounts, API keys, usage reporting, REST API responses, and MCP server responses
- Authenticate users and protect accounts and API keys
- Validate requests, enforce limits, prevent abuse, and investigate failures
- Maintain and improve the reliability and usability of Road User Tools
- Understand aggregate use of the website, REST API, and MCP server
- Meet legal obligations and protect our rights and users
Legal basis for UK and EEA visitors
Where UK or EEA data-protection law applies, we rely on:
- Contract to provide the calculations and account features you request
- Legitimate interests to operate, secure, maintain, and improve Road User Tools, prevent abuse, and understand aggregate service use
- Consent for optional website analytics, which you can withdraw at any time
- Legal obligations when processing is required by law
International processing
Some service providers may process information outside the UK or EEA. Where required, the provider or Watch & Navy uses safeguards recognised under applicable data-protection law. See Firebase’s service processing information for more information.
Retention
We do not store REST API or MCP calculation inputs or results.
Account information is kept while your account remains active and as required for security, legal, and service-operation purposes. API key, usage, and necessary operational records are kept only for as long as reasonably needed to operate and secure Road User Tools, administer accounts, prevent abuse, resolve disputes, and meet legal obligations.
Google Analytics user-level and event-level data is available for detailed analysis for no longer than 14 months. Aggregated reports may be kept for longer. Preferences and saved calculator values remain in your browser until you clear them, disable input remembering, or remove the site’s stored data.
Security
We use technical and organisational measures intended to protect information, including encrypted connections, restricted access, and secure verification of API keys. No internet service can guarantee absolute security.
Your rights
Depending on where you live, you may have rights to access, correct, delete, receive a copy of, restrict, or object to the processing of your personal information. You may also withdraw consent.
You can remove connected applications and revoke or rotate API keys from your account, change your analytics choice in Settings, and clear locally stored preferences through Road User Tools or your browser.
To request access to or deletion of account, API key, usage, or other service records, contact Watch & Navy. We may need to verify your identity before acting on a request. Withdrawing consent does not affect processing that took place before withdrawal.
If you have questions or concerns about how we handle personal information, please contact Watch & Navy first so we can try to resolve them. You can also contact the Information Commissioner’s Office for independent advice or if you remain dissatisfied.
Children
Road User Tools is a general-purpose road calculation utility and is not directed at children under 16.
Changes
We may update this policy from time to time. The Last updated date at the top will change when we do.
Contact
Questions, privacy requests, and account-data deletion requests can be sent through Contact Watch & Navy.