Households and the plan
A household is a set of accounts, trades, and one retirement plan, shared by the people in it. This page covers getting the right people in, and then building the plan around them.
Households
Your Personal household is created for you and is always yours: you own it, it can't be deleted, and you can't leave it.
To plan alongside someone else, make a second one. The switcher in the header — it shows the current household's name — has New household…. Give it a name; you're its owner, and you're switched into it straight away. Accounts, trades, and the plan are entirely separate between households; the switcher is how you move.
Roles
Every login has one of three roles.
| Viewer | Editor | Owner | |
|---|---|---|---|
| See accounts, trades, the portfolio, and the plan | yes | yes | yes |
| Export CSV | yes | yes | yes |
| Add and edit accounts, trades, balances, cash; import; save the plan | — | yes | yes |
| Rename the household, add or remove people, invite/revoke logins, change roles, delete it | — | — | yes |
Controls you can't use aren't greyed out — they aren't shown. If you're a viewer, the household simply doesn't have an "Add account" button in it.
Owner can be granted to an existing login, but never handed out in an invitation: invites carry editor or viewer only. A household always keeps at least one owner, so the last one can't be demoted, removed, or leave.
The household roster
Open Household settings… from the switcher. It lists one row per person in the household — everyone whose name you've added — with their login as one column of that row, not their identity:
Don Owner you
Jenn — no login — [Invite to log in]
Maya — no login — [Invite to log in]
Sam Viewer [Revoke]
A person doesn't need a login to be in the household: they can own accounts and be added to the plan either way. This is the whole reason the roster is people-first rather than login-first — a child can't hold a Google account to be invited with at all, and a spouse who owns half the portfolio may never want one.
Add person
Add person, at the bottom of the roster, takes a name and nothing else — no email, no invitation, nobody to wait on. The person appears on the roster, and in every owner select and plan "Not in this plan" list, immediately.
Rename a person
Every row — including your own — has a Rename button. It swaps the name for a text box with Save and Cancel; Escape cancels too. This is the only way to fix a name typed in a hurry, or the "Me" a brand-new household starts with before anyone's given it a real one. The new name shows up everywhere that person appears — the accounts card, the account form's owner list, and the plan's Household section — without a reload.
Invite to log in
If a person should be able to sign in and use the app themselves, use Invite to log in on their row: an email address and a role (editor or viewer — owner is never invited, only granted, as above).
One thing to know up front, because it changes how you tell them:
No email is sent. The person you invite sees the invitation in the app the next time they sign in with this Google account, and joins by accepting it there.
So message them yourself. Invitations expire after 14 days, and they're matched against the email on the invitee's Google account — invite the address they actually sign in with, or they'll never see it. Pending invitations are listed under the form and can be revoked.
Accepting attaches the login to that existing person rather than creating a second row: everything they already own, and their place in the plan if they're already in it, is untouched. The only thing that changes is that they can now sign in.
Accepting one
From the invitee's side: sign in with the invited Google account, and the household switcher in the header carries a small numbered badge. Open it and there's an Invitations section:
Join "Henderson Household" as editor · from you@example.com — click to accept
One click accepts, joins, and switches them in. Acceptance lives in the switcher rather than in household settings for a simple reason: you aren't on the roster with a login yet, so there's no settings screen of that household for it to live on.
Revoke
Revoke, on a row with a login, removes only that login. The person stays in the household exactly as they were — still owning whatever they owned, still in the plan if they're in it — they just can't sign in any more. You can Invite to log in them again at any time.
Remove person
Removing the person, rather than just their login, is a quieter action next to their row (an icon, not a labelled button) — it's rarer, and it's refused while they still own an account or hold an entry in the retirement plan. The refusal names what's in the way, for example:
Jenn still has the account Jenn 401(k). Reassign it before removing her from the household.
Reassign the account (or remove the plan entry) and try again. Removing a person who has a login takes the login with them.
Very rarely, an account's owner or a plan entry may point at a person the household can no longer resolve — this can only happen if that person was removed outright, which the steps above exist to prevent. It renders as the label Unknown person rather than a raw identifier; see Accounts for what that means for an account.
Renaming, leaving, and deleting a household
The rest of household settings, all owner-only except leaving:
- Name — rename the household; everyone's switcher follows.
- Leave household — available to anyone (except in your personal household). You lose access immediately, and only an owner can invite you back. Leaving removes your login, not you as a person — you keep owning whatever you owned, exactly like a revoke.
- Danger zone — Delete household permanently removes its accounts, trades, balances, and plan, for everyone in it. It can't be undone.
The retirement plan
The Plan tab answers "am I on track?". With nothing saved yet it offers Start planning, which writes a starting plan seeded from your household's people.
Everything after that is a draft: each change re-runs the simulation immediately, but the plan itself changes only when you press Save plan. Discard puts the draft back to the last saved version.
Leaving the page doesn't lose the draft: unsaved edits are set aside for you (per person, per household — nobody else sees them) and are waiting the next time you open the plan, on any device. Edits made in the last moment before a tab closes can occasionally miss the cut. Only Save plan, Discard, or switching to another scenario lets go of a draft.
What you tell it
The plan is spending-driven. You don't tell it a target income — you tell it what your household spends, and what money comes in. The portfolio funds the difference. This section is a tour of the fields; Money in, money out goes through each lever in depth, including the retirement spending smile and the health insurance bridge.
Spending — your baseline monthly spending in today's dollars. Nothing feeds this automatically: what you'd spend in retirement is a judgment call, not an average of last year's transactions.
Household — one block per person in the plan, each with a birth year and a role:
- An adult saves, retires, and eventually claims Social Security. They carry what they save each month, the year they stop working, a benefit at 67 (what you'd get at full retirement age, in today's dollars) and the age you claim at.
- A child never produces income. They affect spending, and they step out of it once they reach the age you mark them independent at.
These live on the plan entry, not on the person — the household doesn't keep a birth year anywhere else, so two plans could give the same person different figures.
There is no "retirement year" field. Each adult says when they stop, and the household retires when the last of them does — the card shows that year at the top, marked (derived). That is what lets you describe the ordinary case: I retire in 2035, my spouse works to 2038. Saving steps down in 2035 when your share stops, stops altogether in 2038, and the portfolio starts covering your spending that same year.
Your working years are described by exactly one number: what goes into the portfolio. The plan doesn't model your salary or your living costs while you're working — the difference between them is what you save. Two consequences are worth knowing: money that arrives before you retire (a rental, some consulting) is assumed to be saved in full, on top of what you told it; and a working year whose goals cost more than you save plus that income draws the difference back out of the portfolio, taxed like any other withdrawal. The Year by year table says both under the table.
Social Security — each adult's benefit and claim age live on their household entry, and the Social Security section is where you tune them: pick a claim age between 62 and 70 per person, or try one of the four strategies, and watch the chart move. The section also has an In the plan checkbox in its top right, covering the whole program at once. Untick it and the plan collects no Social Security at all, for anyone, in any year — every claim age and benefit stays exactly where it was, so ticking it back restores them. It's the fastest way to ask what does our plan look like if this isn't there?
Health insurance — see Health insurance below. It's a term of its own, per adult, because its years come from your dates rather than from a calendar you type in.
Goals — the lump sums you want the plan to carry: tuition years, a wedding, a kitchen, a car every eight years. Each is a need, a want, or a wish, and each can be switched off without deleting it. Goals land in every year they fall in, including years before you retire — a 2030 college bill doesn't wait.
Pensions and other income — any number of pensions and annuities, and any number of other income streams.
A pension is a monthly check that starts when one person in your household reaches a certain age, and it belongs to that person, so the plan works out the year from their birth year. The one thing worth checking is the cost-of-living adjustment. Without one, the check never gets smaller — but everything else does get more expensive, so it buys less every year, and the section says how much less in the year it happens (worked through in Money in, money out). The survivor option (50% or 100%) is recorded and shown, but not simulated — the plan doesn't model anyone dying, so electing 100% here won't change your odds.
An income stream is a rental, part-time consulting, a trust distribution: anything with a start and an end. Each has a label, a monthly amount, a start year, and an optional end year — leave the end blank and it runs to the end of the plan.
Both can be switched off without being deleted, which is how you compare a plan with and without them rather than retyping the numbers.
Taxes — the plan sorts your accounts into three buckets and taxes a withdrawal by which bucket it comes from (all of this in depth in Taxes in the plan): taxable (brokerage, bonds, crypto, cash, other assets), tax-deferred (retirement accounts — 401(k)s, traditional IRAs, HSAs), and Roth (retirement accounts you've marked Roth on the Accounts screen). Roth withdrawals are never taxed. In simple mode your one effective rate applies to the other two; the full model prices a tax-deferred dollar above a taxable-account one, and shows the buckets, the forced distributions and an estimated lifetime tax.
Shortfalls are drawn taxable first — taxable, then tax-deferred, then Roth, the conventional order — or proportionally from all three at once; the Taxes section has the switch. Tax-deferred money belongs to a person: draws from an account whose owner is under 59½ carry the 10% early-withdrawal penalty on top (there's no Rule-of-55 or 72(t) exception — if you have one of those arrangements, the plan overstates what your bridge years cost), and required minimum distributions are forced out of each owner's tax-deferred balance from their own start age, whether the year needs the money or not. What an RMD doesn't fund lands, after tax, in the taxable bucket.
Roth conversions, in the full model, are simulated as the transfer they are: switch them on, say how much per year, and that amount moves from tax-deferred to Roth in each year of a window that opens when the household retires. The toggle alone moves nothing; the amount is the decision.
Either way, every dollar you spend out of the portfolio is grossed up: withdrawing enough to spend $50,000 means withdrawing more than $50,000. That applies before you retire too — a year whose goals cost more than you save plus any income the plan lists takes the difference out of the portfolio, taxed like any other withdrawal.
Inflation — an annual rate, and the age you want the plan to run through.
Assumptions — expected return and volatility per asset class. The simulation blends these by your current allocation, so you rarely need to touch them.
Health insurance
If you retire before 65, you buy your own health cover until Medicare starts. For an early retirement that's routinely the largest single line in the budget, and it's the line that moves most when a retirement year moves — so the plan models it per adult rather than asking you to fold it into your spending. There's a longer treatment, including why it can't live inside your baseline spending, in Money in, money out.
Each adult's card takes three things:
-
Before Medicare — the monthly premium plus what you expect to pay out of pocket, in today's dollars.
-
From 65 — Part B, Part D and Medigap once Medicare starts (plus IRMAA if you expect to pay it).
-
Starts paying — when you retire, or when the household retires. These differ only if one of you stops working before the other: the first to retire often stays on the working spouse's employer plan, and the bill starts when they stop. The default is the earlier, more expensive one.
Under when the household retires, the household's plan is assumed to cover that person right through 65 — they're charged nothing at all until the last of you stops working, and their Medicare figure starts in that year rather than on their 65th birthday. If that isn't your arrangement, use when you retire and adjust the amount. (With three or more adults in the plan, "the household" means the last of all of them to stop, which may not be the person you had in mind.)
Nothing else is typed, because nothing else needs to be. The plan works out the years itself: coverage starts on the retirement year you chose above, and switches to the Medicare figure the year that person turns 65. Change a retirement year on the Household card and the bridge moves with it, in the same keystroke that moves the chart. The card says the answer back to you in a sentence — "Don pays for coverage 2038 → 2044 (7 years, ≈$116k in today's dollars), then Medicare from 2045" — and Year by year carries it as its own Health column, between Spending and Goals.
Leave an adult on Not modeled and the plan charges them nothing. That's different from entering $0, which would assert that their coverage is free.
Each card also has an In the plan checkbox in its top right, and the × beside it deletes the card. They do different things on purpose: unticking the box keeps the premiums and the dates and stops the plan charging them — the card still tells you what that coverage would cost — while the × takes the person back to Not modeled. Untick it to ask what an early retirement looks like if someone else's employer covers you, or if you get a job with benefits again; delete it only when the figures were never right. It's per person, so parking one adult's coverage leaves the other's charged.
Medical inflation, above CPI is one setting for the whole plan, below everyone's cards rather than on any of them. Health costs have run one to two and a half points a year faster than everything else for decades, so this figure — 1.5% by default — compounds everybody's premiums above and nothing else in the plan. Set it to 0 to price the bridge flat in today's dollars.
What this doesn't cover, and what to do instead
Some of it is deliberately out of scope for now:
- ACA premium subsidies. They depend on your income for the year, which depends on which accounts a withdrawal comes from — the plan doesn't model that yet. Enter the premium you expect to actually pay, after any subsidy you expect to get.
- IRMAA, the Medicare surcharge for higher incomes, for the same reason. If you expect to pay it, include it in the From 65 figure.
- Long-term care. That's a different kind of risk — a possible large cost late in life, not a monthly premium. Carry it as a goal if you want the plan to hold room for it.
Anything the per-adult model can't express, a goal can. A goal is charged in every year it lands in and is funded from the portfolio just the same, so a cost with its own calendar — a few years of COBRA at a known price, a one-off dental year — belongs there: give it a tier of need, a start year and an end year, and the annual amount in today's dollars. The one thing a goal can't do is move on its own when your retirement year changes, which is exactly why health insurance is its own section.
The household section is offered, never applied
A plan's members are seeded from your household's people once, when you first start planning. After that the two are allowed to drift, and the plan reconciles by offering rather than by changing anything behind your back:
- A person the household has who isn't in this plan shows up under Not in this plan, with an Add button — this includes anyone you add later, with or without a login. They're added as an adult on placeholder defaults you'll want to correct — including their role, since nothing in your household records a birth year.
- A plan entry naming a person the household can no longer resolve is labelled Unknown person, with a note: No longer in your household. Their birth year and benefit keep counting until you remove them from the plan. There's an X to remove them when you're ready. This is rare — a person can only disappear from the household by being deleted outright, which is refused while they hold a plan entry (see The household roster above) — but the plan protects against it either way.
Nothing about the household ever edits a saved plan on its own. Adding a person, revoking a login, or removing someone from the household shouldn't silently change your projection.
The primary member
The first member in the list is the primary, and the plan runs to their horizon age — their birth year plus your "plan through age". Make primary on anyone else's block promotes them, which reorders the list and moves the end of the plan.
A plan always has at least one member, so the remove button disappears when only one is left. If that one is the rare "Unknown person" case above, add someone before removing them.
What it computes
A Monte Carlo simulation: a thousand market scenarios, month by month, from today to the primary member's horizon age. Monte Carlo and scenarios explains why a plan is scored this way rather than with a single average return, and what the percentage does and doesn't claim.
Only the market return is random — drawn each month from your assumptions, blended by your current allocation. Everything else is deterministic.
Each month adds your contributions, for as long as the person making them is still working. Each year the plan works out what you spend (once you've retired: your baseline, bent by the children who've left home and by the way spending tapers with age) plus any goals landing that year and any health insurance you're buying yourselves, subtracts the income in effect (Social Security, pensions, other streams, a spouse still working), and takes any difference out of the portfolio — bucket by bucket, in your chosen withdrawal order, grossed up for the tax on each bucket's own dollars.
That last step isn't only a retirement step. A working year whose goals cost more than you save plus that income draws the difference from the portfolio too, and it's taxed the same way: your saving carries on, and the shortfall comes out on top of it.
Every figure the plan shows you is in today's dollars. Rather than inflating fifty years of cash flows forward, it discounts the return instead, so a balance in 2060 means what it would buy today.
Projected success is the share of those scenarios that never ran out of money. A scenario that hits zero has failed, even if a later windfall would have refilled it.
Reading the fan chart
The chart plots calendar years against portfolio value:
- the solid line is the median scenario,
- the inner band is the middle half — the 25th to 75th percentile,
- the outer band is the 10th to 90th,
- and a dashed vertical line marks the year you retire.
Underneath, a sentence spells out the useful number: by a given year, where the middle half of scenarios land.
One quirk to expect: the number moves slightly if you change something and change it back. The simulation draws fresh randomness every time it runs, so a percentage point of wobble is the sampling, not your plan.
To keep an answer rather than a memory of one — and to lay two plans over each other on this chart — see the scenario chips in Monte Carlo and scenarios.
Who can do this
Saving a plan requires editor or owner access. Viewers see the plan, the chart, and the success number, but the inputs are read-only and there's no save button.