Nanyfin
Nanyfin trust center

Privacy Policy

Nanyfin is a private household finance workspace. This page summarizes the product data we handle, how MCP and AI access work, and how to request support or deletion.

Data stays private by design. Financial records, MCP keys, and workspace access are treated as sensitive account data.
Tell us where to look Include the workspace domain, affected email, and a short description of what changed.
Keep secrets out of email Do not send passwords, raw MCP keys, bank credentials, or full card numbers.
Sensitive changes are verified Deletion, export, billing, and access requests are checked before workspace data changes.
1

Data we collect

  • Account and workspace data: email addresses, names, tenant names, tenant domains, billing metadata, plan status, and staff-entered support notes.
  • Finance workspace data: households, users, accounts, categories, transactions, transfers, credit-card bills, budgets, goals, subscriptions, investments, tags, dates, descriptions, balances, and reconciliation state.
  • MCP and API access data: MCP key metadata, hashed key material, token prefixes and last four characters, creation time, last-used time, revocation time, and API request authentication outcomes.
  • Security and operational data: signup invitations, password reset tokens, SSO tokens, language preference, request IP address, user agent, throttling outcomes, and email delivery failures.
2

How we use data

  • To run the finance workspace, authenticate users, route users to the correct tenant, enforce access status, provide support, and protect accounts from abuse.
  • To provide finance features such as summaries, category breakdowns, budgets, subscriptions, credit-card faturas, goals, transfers, and transaction history.
  • To diagnose security, signup, recovery, billing, and tenant-access issues without logging sensitive finance descriptions, balances, bearer tokens, or cookies.
3

AI and MCP access

  • Users can generate MCP keys from inside their workspace. Anyone with an active MCP key can use exposed tools to read summaries and transactions and to create or update finance records according to the tool surface.
  • MCP keys are shown once, stored as hashes, and can be revoked from the workspace UI. Once a DB-backed key exists, the bootstrap MCP_SECRET no longer authenticates that tenant.
  • Nanyfin is not claiming public ChatGPT app readiness yet. Public ChatGPT distribution still requires OAuth-backed MCP authorization, review metadata, and approval.
4

Retention and deletion

  • Workspace finance data is retained while the tenant is active so households can keep their ledger history. Some records are soft-deleted for auditability and recovery instead of immediately removed from the database.
  • Signup invitations, reset tokens, SSO tokens, MCP key metadata, and security events may be retained for account security, abuse prevention, and support investigation.
  • Deletion or export requests should be sent to support. We will verify requester authority before deleting tenant data, personal account data, MCP keys, or security-sensitive records.