Nanyfin
Nanyfin trust center

Privacy Policy

Nanyfin is a private household finance workspace. This page summarizes the product data we handle, how MCP and AI access work, and how to request support or deletion.

Data stays private by design. Financial records, MCP keys, and workspace access are treated as sensitive account data.
Tell us where to look Include the workspace domain, affected email, and a short description of what changed.
Keep secrets out of email Do not send passwords, raw MCP keys, bank credentials, or full card numbers.
Sensitive changes are verified Deletion, export, billing, and access requests are checked before workspace data changes.
1

Data we collect

  • Account and workspace data: email addresses, names, tenant names, tenant domains, billing metadata, plan status, and staff-entered support notes.
  • Finance workspace data: households, users, accounts, categories, transactions, transfers, credit-card bills, budgets, goals, subscriptions, investments, tags, dates, descriptions, balances, and reconciliation state.
  • MCP and API access data: MCP key metadata, hashed key material, token prefixes and last four characters, creation time, last-used time, revocation time, and API request authentication outcomes.
  • Security and operational data: signup invitations, password reset tokens, SSO tokens, language preference, request IP address, user agent, throttling outcomes, and email delivery failures.
2

How we use data

  • To run the finance workspace, authenticate users, route users to the correct tenant, enforce access status, provide support, and protect accounts from abuse.
  • To provide finance features such as summaries, category breakdowns, budgets, subscriptions, credit-card faturas, goals, transfers, and transaction history.
  • To diagnose security, signup, recovery, billing, and tenant-access issues without logging sensitive finance descriptions, balances, bearer tokens, or cookies.
3

AI and MCP access

  • Private MCP clients can use revocable workspace keys with a broader read/write tool surface. Keys are shown once and stored as hashes; keep them secret and revoke them when no longer needed.
  • The public ChatGPT V1 uses OAuth and five read-only tools for recorded summaries, transactions, accounts, budgets, and categories. An explicit account link selects one workspace; linked workspace members share tenant-wide read visibility.
  • Nanyfin sends only the requested minimized response to the user's selected ChatGPT account. OpenAI handles conversations, Memory, feedback, abuse monitoring, and possible model improvement under the user's ChatGPT plan and settings; disconnecting Nanyfin does not delete prior ChatGPT chats or saved memories.
  • The public path uses Railway hosting and Stytch-by-Twilio authorization in the United States and may involve published provider locations including the United Kingdom. Staging-only Sentry receives allowlisted technical events and is prohibited from receiving finance, identity, credential, request, or response data.
  • Public distribution remains pending production OAuth and reviewer evidence, publisher verification, and OpenAI review.
4

Retention and deletion

  • Workspace finance data, including soft-deleted history, is retained while the workspace is active. A verified workspace deletion removes its primary Nanyfin data, keys, and identity links; Nanyfin keeps no separate post-deletion finance archive.
  • Railway Hobby application and HTTP logs expire after seven days. Stytch dashboard Event Logs have a 30-day window and Twilio security logs a separate 180-day window. Provider-controlled backups, support records, and logical or asynchronous deletion may continue beyond primary Nanyfin deletion, so immediate physical erasure is not promised.
  • Deleting or disconnecting Nanyfin does not delete prior ChatGPT records. Delete the relevant chats and saved memories in ChatGPT. Send export, correction, revocation, or deletion requests to support; we verify requester authority before acting.