Data & spreadsheets · DCF Calculator
Why a DCF Tool That Fetches No Market Data Keeps Your Assumptions Private
· Why it matters
dcf privacy browser-processing
Deal assumptions are sensitive. This post explains why a calculator that runs in the browser and makes no data requests means your inputs never leave the device, and how to verify that claim yourself.
Confidential forecasts typed into a web tool — what you are trusting when a calculator sends inputs to a server
Confidential forecasts entered into a remote calculator can become request bodies, logs or stored records. The relevant question is not whether the form looks simple but whether code transmits the values. ToolAcre’s DCF manifest declares local processing and no network requirement after load, a claim that can be checked from the browser rather than accepted on trust.
How this calculator runs — the arithmetic happens in your browser and no market data is fetched, so there is no request to carry your figures
The arithmetic module is pure JavaScript with no DOM, I/O, network or market-data access. Inputs are read from form controls and passed into calculateDcf in memory. The page does not need a quote service because every figure is manual, so there is no data request that must carry a ticker or the assumptions to complete the model.
Verifying it yourself — opening the browser's network panel while using the tool and watching for requests
Open Developer Tools before entering anything, preserve the network log, change fields and export a result. Page assets may appear from initial loading; inspect method, destination and payload for later requests. The strongest evidence is the observed absence of a request carrying assumptions, not a blanket claim that a web page can never communicate.
No account, but a local draft — what the browser stores and how Reset removes it
The outline claimed there was no history to delete, but the source deliberately saves working assumptions in localStorage so a refresh does not lose them. There is no account, server sync or identifier. Reset calls clearDraft and removes the key immediately; private modes or blocked storage simply disable the convenience without breaking calculation.
What the Content Security Policy adds — restricted script and connection sources on the shipped page
The shipped HTML uses a Content Security Policy limiting scripts and connections to declared sources, with connect-src restricted to self, blob and data. Its manifest also disables analytics and advertising. A policy narrows what compliant page code can load; it is defence in depth, not a substitute for inspecting the actual requests and extensions active in your browser.
The trade-off of fetching nothing — you must type every input, including rates a data-driven tool would prefill
Fetching nothing means nothing is prefilled. The user must provide FCF, debt, cash, shares and every rate, and must keep them current and consistently scaled. Privacy and convenience trade in opposite directions here: the tool cannot leak a quote it never requests, but it also cannot confirm that a manually entered quote or statement figure is correct.
What this does not cover — your own device, browser extensions and clipboard are outside the tool's control
Local processing does not secure the device, clipboard, downloaded exports or browser extensions. Anyone with access to the browser profile may read local storage, and exporting CSV or JSON creates a file the user must protect. The structural claim is limited to the tool’s own calculation path and storage code.
Privacy here is structural, not a promise — how the ToolAcre DCF Calculator's no-network design is something you can check rather than take on trust
Privacy here is an inspectable architecture: pure local arithmetic, manual inputs, local draft persistence and no required post-load network. Verify that architecture in the network and storage panels for the session that matters. The result remains an assumption-driven model and local execution does not make it investment advice.