Anonymous debt planning for your tenants and employees - no logins, no data stored.
DebtRiot gives housing associations, EAP providers and employers a private, branded debt planning tool. Your users work out their own repayment plan in the browser. Nothing is collected. Nothing is stored. You get aggregate insight - never individual data.
Built for organisations that care about confidentiality
Most people struggling with debt are also worried about privacy. Asking them to create an account - even for a helpful tool - is enough to make them close the tab. DebtRiot removes that barrier entirely.
Users plan in the browser. No account. No login. No personal data collected or stored. When a session ends, nothing remains. Your organisation never becomes a processor of your tenants' or employees' financial data.
You receive anonymous, aggregate telemetry only - how many people used the tool, which strategies were most popular, how many plans were downloaded. Useful insight without individual exposure.
Four steps. No data touches your servers.
Your users plan privately. You see only aggregate, anonymous counts.
You share a branded link
We give you a unique URL — for example, yourassociation.debtriot.co.uk/app. You share it in your welcome pack, financial wellbeing communications, or tenancy support materials. No IT work required.
Users plan privately in their browser
No account. No login. No name, email or National Insurance number ever asked for. Your tenant or employee enters their debts, compares repayment strategies, and sees exactly what their options look like — all within their browser session.
Anonymous usage counts reach your dashboard
When a plan is generated, an anonymous count is logged — nothing else. Your admin dashboard shows how many sessions occurred, which strategies were chosen, and how many plans were downloaded. No individual data. Ever.
Users download their own PDF plan
Anyone who wants to keep their plan downloads it directly to their own device. The PDF is generated entirely in the browser — it is never sent to our servers, never stored anywhere. The user owns their plan. You never see it.
Built for UK organisations. Different by design.
Not adapted from a US product. Not a generic financial wellness platform. Built for the UK, from the ground up.
Three sectors. One platform.
Housing Associations
Tenants in arrears or at risk of arrears often need structured debt planning before they can meaningfully engage with a money advisor. DebtRiot gives them a private first step — without putting your organisation in scope for personal financial data.
- ✓Share via welcome packs or tenancy support communications
- ✓CHC and NHF umbrella body procurement-friendly
- ✓No IT integration required
- ✓DPA included as standard
EAP Providers
Financial stress is one of the leading drivers of EAP referrals. Most EAP platforms offer signposting, not tools. DebtRiot gives your clients' employees something they can act on immediately — privately, without disclosing anything to their employer.
- ✓White-label URL for each client employer
- ✓Aggregate usage data — employer sees only counts
- ✓Zero personal data ever processed
- ✓Complements existing coaching or counselling referral
Employers
Financial wellbeing is now a mainstream employer concern — but most financial wellbeing platforms require employees to create accounts and hand over sensitive data. DebtRiot provides the planning tool without the data risk or the account barrier.
- ✓Share via intranet, Slack, or wellbeing comms
- ✓Employees never identified — complete privacy
- ✓HR and payroll teams see only usage totals
- ✓No data incident liability for the employer
What we collect. What we don't. Who sees what.
This section is for data protection officers, procurement leads, and IT teams who need to understand exactly what happens to data when your tenants or employees use DebtRiot.
The short answer: we collect nothing that identifies an individual. All debt figures, strategy choices, and repayment calculations remain in the user's browser for the duration of their session. When the session ends, they are gone. The PDF plan is generated locally on the user's device - it is never transmitted to our servers.
The only data we store is an anonymous count - one number incremented each time a plan is generated. It cannot be traced back to a person. It cannot be combined with other data to identify anyone. It is stored in a UK-accessible cloud database (Upstash, EU-West region) and retained for 12 months.
A UK GDPR Article 28 Data Processing Agreement is included as standard with every subscription. Your DPO does not need to draft one. We provide it at the point of signature.
ICO registration: ZC115123 · Registered: Miss Monika Pankiewicz, sole trader, Cardiff, Wales
| Data point | Collected? | Where stored | Who sees it | Retained |
|---|---|---|---|---|
| Name | Not collected | — | — | — |
| Email address | Not collected | — | — | — |
| Debt figures entered | Not collected | Browser session only | User only | Cleared on session end |
| PDF plan content | Not collected | User's device only | User only | Never transmitted |
| IP address | Not collected | — | — | — |
| Anonymous session count | Collected (anonymous) | Upstash Redis, EU-West | Your org admin + DebtRiot | 12 months |
| Strategy chosen (aggregate) | Collected (anonymous) | Upstash Redis, EU-West | Your org admin + DebtRiot | 12 months |
Straightforward annual pricing. Start with a free pilot.
Pricing is based on organisation size and deployment scope. Contact us to discuss what works for your organisation — no commitment required.
Questions we hear from procurement and DPO teams
-
No. We provision a branded URL for your organisation — for example, yourassociation.debtriot.co.uk/app. Your team shares that link however you normally communicate with tenants or employees: email, welcome packs, intranet, Slack. There is no software to install, no integration with your systems, and no API connection required. Your IT team does not need to be involved at any point.
-
DebtRiot collects no personal data from end users. Debt figures, strategy choices, and repayment calculations exist only in the user's browser session — they are never transmitted to our servers. The PDF plan is generated on the user's device. The only data we store is an anonymous count, which by design cannot be traced to an individual. A UK GDPR Article 28 Data Processing Agreement is included with every subscription. ICO registration number: ZC115123.
-
No. DebtRiot is a calculation and planning tool — it presents mathematical comparisons of different repayment strategies based on numbers the user enters. It does not recommend specific products, advise users to take on credit, or make any regulated financial recommendation. It is comparable to a mortgage calculator — a tool that helps someone understand their options, not advice telling them what to do. Your organisation does not require FCA authorisation to offer access to a debt calculation tool.
-
We have designed the platform with accessibility as a requirement, not an afterthought — semantic HTML, keyboard navigation, appropriate colour contrast ratios, and screen reader compatibility. We are working towards a formal WCAG 2.1 AA audit and will share the audit report with enterprise and large-tier clients. If your organisation has specific accessibility requirements beyond standard WCAG compliance, please include these in your pilot request and we will review them with you.
-
No. The pilot is 3 months, includes full access to all features, and has no automatic renewal. At the end of the pilot period, we will ask whether you would like to continue. If not, the link is decommissioned and your admin dashboard is closed. There is no invoice, no chaser, and no rollover. If you decide to subscribe, we agree terms and issue an invoice for the annual fee at that point.
-
We can apply your organisation's name and logo to the interface and to the branded subdomain URL. Full white-labelling — removing all DebtRiot branding entirely — is available for enterprise and large EAP clients and is priced on enquiry. For small and medium subscribers, the interface carries a small "Powered by DebtRiot" attribution. If you need to discuss specific branding requirements during the pilot, include that in your request.
-
Yes — technically, a DPA is required under UK GDPR Article 28 whenever a controller engages a processor. However, because DebtRiot processes only anonymous counts (not personal data), the practical data risk during the pilot is near-zero. We provide a standard DPA at the point you request your pilot. It is a short document — plain English, no legal negotiations required. If your DPO has specific requirements, we are happy to discuss amendments before signing.
Ready to offer your tenants or employees a private debt planning tool?
The pilot is free, takes 48 hours to set up, and requires no IT work on your side. If you have questions before requesting, email us and we will reply within one working day.
DebtRiot is operated by Monika Pankiewicz, sole trader, Cardiff, Wales. ICO registration: ZC115123. Professionally insured. Trademark application filed, Class 42.
