Terms of use
What Vyarno is
Vyarno is a calculator over official statistics. You enter your own figures, it compares them with published data from Eurostat, the ECB, БНБ, НСИ and asking prices from imot.bg, and shows you the result. Every figure carries a link to its upstream source so you can check it yourself.
Vyarno describes; it does not advise. It shows a figure and what it was computed from; the conclusion is yours.
This is not financial advice
Nothing on this site is financial, investment, tax, legal or credit advice, and no figure it produces is a recommendation. Vyarno is not a credit intermediary: it does not offer credit, does not compare bank offers, does not steer you towards a particular lender and takes no part in concluding a credit agreement. No figure here depends on who is paying: which data we show, how we compute it and how affordable a home comes out are decided by the source and the method.
The mortgage panel applies БНБ's borrower-based limits and a standard annuity formula to a published interest rate. The 30%-of-net-income line is ours and is deliberately stricter than the law allows. It is not a lender's decision and no bank is bound by it. A credit decision is made by the lender and by you.
What you may do
You may load and use the site in a browser as often as you like, with no account and at no cost, for whatever you need it for, personal or professional, commercial use included. There is no paid version, no locked features and nothing that money would unlock: what you see is all there is. You may quote an individual figure in an article, a presentation or a conversation, provided you also name the source it comes from and the date it refers to. This is encouraged rather than tolerated: sourced quotation is exactly the use the site was built for.
What you may not do
Loading the site in any way other than ordinary use by a person with a browser: crawling with a bot, scripted downloading in a loop, repeatedly pulling the data files. Vyarno is delivered by a content network rather than a machine of its own, and this is a request for courtesy rather than protection of anything secret. The next paragraph has the better route.
Presenting our figures as someone else's or someone else's as ours, embedding that removes the source attribution, and using the name “Вярно”, the domain or the mark in a way that suggests a connection or an endorsement. You may say your work is based on Вярно: that is accurate and welcome. You may not call your own version “Вярно”.
If you need machine access to the data, take it from the repository rather than scraping it from the site. The code is open (Apache-2.0) and the published data files are in git with their history, schema and refresh date: vyarno-bg/vyarno. You get more than scraping would give you, and nobody pays for it in traffic.
One thing about the figures themselves: they are not ours and we cannot license them to you. The open licence covers the code, not the statistics: every figure carries the address of its source, and that publisher's terms are what govern it. See the “Sources” section below.
The figures are not ours
The statistics Vyarno shows are produced by Eurostat, the ECB, БНБ, НСИ and imot.bg and remain subject to each publisher's own terms. We are not in a position to grant you rights in them and do not purport to. What each source provides and what it requires is set out in the “Sources” section below.
The schema, the field names, the arrangement, the selection of sources and the checks the data pass before publication are ours.
Accuracy, availability and liability
We take real care that the figures are right: every publication passes automated checks, and every figure carries a source and a date. But statistics are revised by the bodies that produce them, asking prices are not transaction prices, and the pay distribution is modelled from a survey. The site is therefore provided “as is”, without warranty of accuracy, completeness or fitness for a particular purpose, and we are not liable for decisions taken on the basis of what it shows.
We do not promise uninterrupted access, and we may change, suspend or withdraw any part of the site. Data refreshes run on a schedule, with one of them done by hand. The date of the last refresh is always visible on the page: if it is old, the site says so itself rather than hiding it.
Nothing in these terms limits rights that consumer law gives to consumers and that cannot be limited by agreement.
Governing law
Bulgarian law applies. We do not nominate a court: for a consumer that is settled by law (Regulation (EU) 1215/2012 gives them the right to sue and be sued where they are domiciled), and a clause saying otherwise is ineffective. Not writing one is more honest than writing one and taking it back in the same sentence.
As a consumer you may also complain to the Commission for Consumer Protection (details below).
Changes to these terms
If we change these terms we publish the new version here with a new number and a new effective date. We do not change terms retroactively.
Privacy
The short answer: your figures stay with you
The salary, rent, savings and basket you enter are computed entirely in your browser and are never sent anywhere. There is no server to receive them. We ask for no name, no e-mail address, there is no registration and there is no account. The only thing that takes you off the site is the donation link. What happens if you use it is set out below.
The rest describes the site as it stands in this version of the document. Today exactly one thing runs on the page that is not our own code: a visit counter that has no way of telling who you are. There is no tracking script, no pixel and no cookie, neither ours nor anyone else's. The section “How visits are counted” below describes the counter as far as it goes. If we ever add anything else that runs in your browser or leaves anything in it, it gets its own section here and this document's version changes, in the same release, before the change reaches you, not after it.
That is why this page is short: it describes little because the site does little. If that changes, this page gets longer rather than vaguer.
What is stored on your device
Four things, and each of them only if you ask for it: the language, the light or dark theme, the place you are looking at the figures for, and (only if you yourself switch on “Remember my figures on this device”) the figures you typed. Touch nothing and nothing is written: a first load leaves no trace in your browser. Change one and it is kept in localStorage under the key vyarno_lang, vyarno_theme, vyarno_region or vyarno_inputs. These are not cookies, but the rule about storing data on your device covers them anyway (art. 4a of the Bulgarian E-Commerce Act); we keep them because you asked for exactly that, which is why we do not ask you again. The place is a preference about which published figures to show you rather than a fact about you: it is sent nowhere and tied to nothing else you typed. None of the four is ever sent with a request. The first three contain nothing personal; the fourth contains your own figures, which is why it has a section of its own directly below. You can clear them from your browser's settings whenever you like.
If you turn on “Remember my figures”
The switch sits under “Your numbers. Your reality.” on the front page, and it is off until you turn it on. Turn it on and what you entered in the calculator is written under the key vyarno_inputs: the pay, the raise, the rent, the savings, the basket and the home settings. That record is written in your browser and stays there: it is not sent with a request, it does not reach us, and there is no server to receive it. The arithmetic still happens entirely on your device.
It is off by default because of the one thing we cannot judge for you: the figures are yours, but the device may not be yours alone. On a shared laptop or tablet the next person to open the site sees them. So the choice is yours and it reverses at once: switch it off and the record is deleted in the same action, and the “Forget everything on this device” button beside it does the same in one press. Clearing the site's data from your browser's settings removes it too.
What the host sees
We are precise here, because “we collect nothing” slips easily into being untrue. Like every web server, the machine that delivers the page records the ordinary log line: IP address, timestamp, requested URL and browser type. That is what it takes to get the page to you and to defend against abuse, and it is the only thing that exists about your visit.
We may read those lines in aggregate: how many visits there are, which pages get opened and where people arrive from. That is counting, not tracking: we build no profile of you, we join the log to no other source, and we pass it to no third party. We hold no such log ourselves and cannot download one: the page is delivered by Cloudflare, Inc., the plan we deliver it on gives no access to per-request records, and what we see is the host's finished counters: figures, not lines.
How long that record survives is set by the host's policy rather than by a setting of ours: Cloudflare processes request data in its own data centres in the European Union and the United States “for a limited period of time”, and publishes no figure in days. We have no way to extend it and no wish to: there is no copy of ours, no archive, and no file that outlives it. Part of the processing therefore happens outside the EU. That is significant enough to state plainly rather than leave out: the transfer runs on the European Commission's Standard Contractual Clauses, and Cloudflare is additionally certified under the EU-U.S. Data Privacy Framework.
One more thing the page's own code does not show: if a request to the site fails (a dropped connection, a timeout, a refused certificate), your browser may send a short technical report about that failure to a reporting address belonging to the host. The report carries the URL that failed, the kind of failure and the time; it is sent only on a failure and it reaches the same host that delivers the page. The mechanism is the host's rather than ours, and it does not touch the figures you type: those leave your browser under no circumstances.
How visits are counted
Besides the host's log there is a counter: Plausible. It loads from plausible.io, and each time you open a page it sends there the page address including anything after the question mark in it, where you came from if you followed a link, the browser and its version, the kind of device, and the country. Those are the same fields the host's log already holds. The difference is that we see them counted rather than scattered.
Besides the opening itself, three things you do on the page are counted. Follow a link that leads off vyarno.bg (to Eurostat, the ECB, НСИ, БНБ, imot.bg or a donation page) and it is recorded that a link was followed, together with the address it leads to. Downloading a file is recorded. So is how far down the page you got and how long it stayed open in front of you. None of the three carries a figure you typed and none of them says who you are: they stay at the level the visit itself is at, which is what was opened and what was clicked, with no person behind it.
It sets no cookie, writes nothing in your browser and gives you no number. Whether it has counted you already today it works out from a fingerprint computed from your IP address, your browser and our domain together with a random value that is replaced and deleted every 24 hours. Once it is replaced the old fingerprints cannot be matched to the new ones, including yours to yours, so it cannot follow you from one day to the next, or from one site to another. The IP address itself is not stored: the fingerprint and the country are derived from it, and it is discarded.
What the counter does not see matters more than what it does: the figures you type. The salary, the rent, the savings and the basket are computed in your browser and go neither to us nor to it: there is no event that carries them and no line of code that sends one. We do not count shares either: a measurement taken at the moment you share your basket is a measurement that can see what you typed, which is why there is none.
The counter is run by Plausible Insights OÜ, Tartu, Estonia, which processes this data as our processor, solely on our instructions, under a GDPR art. 28 contract. The records sit on servers inside the European Union, in Germany, Slovenia and Finland, and do not leave it. Unlike the host's log, there is no transfer outside the EU here.
Why count at all: the site is kept going by donations, that is not expected to carry it indefinitely, and any other way of keeping it going requires being able to say how many people read it. If you would rather not be counted, run localStorage.setItem('plausible_ignore', 'true') in your browser's console. The counter reads exactly that key before it sends anything, and stops. It does not write the key: you write it and you delete it. An extension that blocks counters stops it too, and we do nothing to work around one.
If you choose to donate
This site takes no payments and has no donation form. What it has is links to Ko-fi and GitHub Sponsors: follow one and you leave vyarno.bg. If you do not follow them, nothing in this section is about you.
Ko-fi, GitHub and Stripe are separate companies with their own terms and their own privacy policies; there you are their user, not ours. The payment goes entirely through the platform and its own payment provider: your card details do not pass through this site and do not reach us in any form.
From the donation we receive the name or alias you entered, your e-mail address, your message if you left one, the amount and the date. The basis is the donation itself, a contract gratuitous though it is, and our obligation to account to the tax authorities for what we receive. We keep those records for as long as the tax periods that apply to them run, and we use them for nothing else: we build no profile, we send no newsletter, and we publish no list of donors.
Some platforms show supporters on a page of their own. GitHub Sponsors does, unless you mark yourself a private sponsor there. That is their page and your setting with them; we copy no such list onto this site, we rank nobody, and we give nothing in return for a donation.
Your GDPR rights cover that record too and are exercised at the same address, contact@vyarno.bg. For what Ko-fi, GitHub or Stripe hold about you, go to them: we have no access to your account with any of them and cannot change it.
Why this is enforced, not promised
A promise is not enough, so it is nailed down in the page itself. The Content-Security-Policy the site is served with names the addresses the browser may reach at all, and there are two: vyarno.bg and plausible.io. Everything else the browser blocks by itself. If someone added a third tracking script it would not quietly work, it would break. The list is in the public repository, and a test checks it against what the page actually loads.
The fonts are ours too and are served from our own address rather than a third-party network. Apart from the counter described above, your browser contacts nobody else in this version: everything else that loads the page comes from vyarno.bg. There is a third address it can reach: the host's own error-reporting address, described above and outside what the policy governs, because error reports are not subject to its rule about connections. If that list ever has to grow, it will grow explicitly and visibly, and this section changes with the policy, in the same release.
Your rights
The data controller for the purposes of the GDPR is the person identified in the “Identification” section below. The legal basis for briefly logging requests and for counting visits is the legitimate interest in delivering the page, protecting it from abuse, and judging in aggregate whether anyone is using it at all. There are two recipients, and each processes as our processor, solely on our instructions, under a GDPR art. 28 contract: the host that delivers the page (Cloudflare, Inc.), and Plausible Insights OÜ, which counts the visits. There is no other recipient; for a donation, the section above applies.
The GDPR gives you rights of access, rectification, erasure, restriction, portability and objection. Here they meet an unusual practical limit: apart from the request record the host holds and, if you have donated, the record of that donation, we hold nothing connected to you, so there is nothing else for them to attach to. If you would like to exercise one anyway, or simply to check what we have, write to contact@vyarno.bg. We answer within one month.
If you believe we process data unlawfully you have the right to complain to the Commission for Personal Data Protection (details below).
Children and special categories
The site is not directed at children and does not ask for an age, because it asks for nothing. We process no special categories of personal data. The figures you enter are personal in substance, which is precisely why we neither ask for them nor receive them.
If this ever changes
The sentence on the front page, “everything is anonymous, we don't collect personal data”, is a promise that has to stay true. If we ever build something that changes it, the sentence changes in the same release, not later. A promise must not outlive the truth.
Reporting a vulnerability
If you have found a security problem, write to contact@vyarno.bg. Describe what you saw and how to reproduce it; if it helps we will agree a way to exchange encrypted messages. We acknowledge receipt within three working days.
We ask for reasonable behaviour: no bulk data extraction, no modifying or deleting anything, no testing that degrades access for other people, and no disclosure before we have had a chance to fix it. Behave that way and we will take no action against you. We do not pay bounties: the site holds no one else's personal data, so a bounty would be out of proportion to the risk.