Nanyfin
Nanyfin trust center

Privacy Policy

Nanyfin is a private household finance workspace. This page summarizes the product data we handle, how MCP and AI access work, and how to request support or deletion.

Data stays private by design. Financial records, MCP keys, and workspace access are treated as sensitive account data.
Tell us where to look Include the workspace domain, affected email, and a short description of what changed.
Keep secrets out of email Do not send passwords, raw MCP keys, bank credentials, or full card numbers.
Sensitive changes are verified Deletion, export, billing, and access requests are checked before workspace data changes.
1

Data we collect

  • Account and workspace data: email addresses, names, tenant names, tenant domains, billing metadata, plan status, and staff-entered support notes.
  • Finance workspace data: households, users, accounts, categories, transactions, transfers, credit-card bills, budgets, goals, subscriptions, investments, tags, dates, descriptions, balances, and reconciliation state.
  • MCP and API access data: MCP key metadata, hashed key material, token prefixes and last four characters, creation time, last-used time, revocation time, API request authentication outcomes, and temporary public-write preview, receipt, revision, and idempotency metadata.
  • Security and operational data: signup invitations, password reset tokens, SSO tokens, language preference, request IP address, user agent, throttling outcomes, and email delivery failures.
2

How we use data

  • To run the finance workspace, authenticate users, route users to the correct tenant, enforce access status, provide support, and protect accounts from abuse.
  • To provide finance features such as summaries, category breakdowns, budgets, subscriptions, credit-card faturas, goals, transfers, and transaction history.
  • For separately consented public ChatGPT writes, to prepare one exact ledger preview, wait for a distinct confirmation, record one user-specified income or expense, offer a separately confirmed eligible audited undo, and prevent stale or duplicate changes.
  • To diagnose security, signup, recovery, billing, and tenant-access issues without logging sensitive finance descriptions, balances, bearer tokens, or cookies.
3

AI and MCP access

  • Private MCP clients can use revocable workspace keys with a broader read/write tool surface. Keys are shown once and stored as hashes; keep them secret and revoke them when no longer needed.
  • The public ChatGPT V1 uses OAuth and five read-only tools for recorded summaries, transactions, accounts, budgets, and categories. An explicit account link selects one workspace; linked workspace members share tenant-wide read visibility.
  • Public ChatGPT V2 keeps those five reads and adds a separate finances.write permission for exact previews, confirmed recording, cancellation, and eligible audited undo. It changes only Nanyfin's internal ledger; it does not connect to banks, move or pay money, transfer funds, trade, purchase, cancel subscriptions, or reverse external activity.
  • Every public write starts with a five-minute preview and requires a new explicit confirmation. Confirmation accepts only the preview reference and a duplicate-safe request key; Nanyfin rechecks the linked workspace, permissions, expiry, and selected ledger targets before changing the ledger.
  • Nanyfin sends only the requested minimized response to the user's selected ChatGPT account. OpenAI handles conversations, Memory, feedback, abuse monitoring, and possible model improvement under the user's ChatGPT plan and settings; disconnecting Nanyfin does not delete prior ChatGPT chats or saved memories.
  • The public path uses Railway hosting and Stytch-by-Twilio authorization in the United States and may involve published provider locations including the United Kingdom. Staging-only Sentry receives allowlisted technical events and is prohibited from receiving finance, identity, credential, request, or response data.
  • V1 is published. V2 remains limited to controlled testing and OpenAI review until OpenAI approves the new version for broader directory availability.
4

Retention and deletion

  • Workspace finance data, including soft-deleted history, is retained while the workspace is active. A verified workspace deletion removes its primary Nanyfin data, keys, and identity links; Nanyfin keeps no separate post-deletion finance archive.
  • Public-write previews are valid for at most five minutes and their temporary rows are normally removed within 24 hours after expiry. Duplicate-safe receipt and idempotency metadata is normally kept for seven days. Cleanup removes that temporary metadata without changing the recorded or audited soft-deleted ledger history.
  • Railway Hobby application and HTTP logs expire after seven days. Stytch dashboard Event Logs have a 30-day window and Twilio security logs a separate 180-day window. Provider-controlled backups, support records, and logical or asynchronous deletion may continue beyond primary Nanyfin deletion, so immediate physical erasure is not promised.
  • Deleting or disconnecting Nanyfin does not delete prior ChatGPT records. Delete the relevant chats and saved memories in ChatGPT. Send export, correction, revocation, or deletion requests to support; we verify requester authority before acting.