1. Summary
Your financial data is stored on your device, not on our servers. Nova has no user accounts, so there is nothing on our side tied to you — no email address, no password, no profile, and no copy of your financial history.
A small number of features send specific data to our backend so it can be processed and returned. Section 4 lists each one, what it contains, and whether you trigger it. We do not sell personal data, we do not share it with advertisers, and there is no advertising or tracking SDK in the app.
2. No account, no server copy
Nova does not have a sign-up or sign-in. We do not ask for your name, email address or phone number, and we do not create a profile for you. Because there is no account, there is no server-side record of your transactions, budgets, goals, holdings or receipts.
3. What stays on your device
- All financial data — transactions, categories, budgets, envelopes, goals, investment holdings and receipt photos — is stored in a local SQLite database on your device.
- Plaid access tokens — the tokens that let Nova refresh your accounts — are stored in the iOS Keychain or Android Keystore, not in general app storage.
- Settings — language, currency, display preferences — are stored in local device storage.
Data stored on your device is protected by your device's own security: passcode, biometrics and operating-system encryption. Keeping your device locked and up to date is an important part of keeping this data private.
4. What leaves your device, and exactly what it contains
All outbound requests go to Alpha Nova AI LLC's own backend, which passes the relevant part on to the service provider that performs the work. The table is the complete list.
| Feature | What is sent | Triggered by |
|---|---|---|
| Connecting a bank | A Plaid public token, exchanged for an access token. Your bank credentials are entered inside Plaid's own interface and never touch Nova or our servers. | You, when you link an account |
| Transaction categorization | Transaction id, merchant name and amount, plus your own category labels. Sent in batches of 40. | Automatically, during sync |
| Daily brief | Aggregates only — month, budget, amount spent, amount available, today's spend, transaction count, days remaining, and per-category totals. No merchant names and no individual transactions. | You, when you open the brief |
| Investment statement import | The image or PDF you chose. It contains the account names and holdings printed on it. | You, when you pick a file |
| Bank statement import | The statement file you chose. | You, when you pick a file |
| Receipt reading | The receipt photo you took or picked, resized on the device before it is sent, plus your category names. It contains whatever the receipt shows — merchant, date, total, payment method, and the last four digits of a card when the receipt prints them. | You, when you photograph or pick a receipt |
| Voice entry | The transcribed text only — for example “Starbucks eight forty five” — plus the language and your category names. Speech recognition runs on your device; the audio itself never leaves the phone. | You, while you hold the voice button |
| Subscription analysis | For each recurring-charge candidate found on your device: merchant name, average amount and number of occurrences. No transaction ids and no account information. | You, when you run the check |
| Stock prices | Ticker symbols only. No share counts, no balances, no account names. | Automatically, to refresh prices |
| Abuse prevention | An anonymous installation identifier and an Apple App Attest verification, which confirm the request came from a genuine, unmodified copy of Nova on a real device. No financial data, and not linked to your identity. | Automatically, with each request to our backend |
Every one of these is initiated by you except transaction categorization, which runs as part of sync. We state this asymmetry plainly rather than summarizing it: categorization sends merchant names and amounts; the daily brief sends only totals.
Seven of these features are processed by Anthropic's Claude API after passing through our backend: transaction categorization, receipt reading, voice entry, bank-statement import, investment-statement import, subscription analysis and the daily brief. Connecting a bank goes to Plaid, and stock prices go to our market-data provider; neither involves Anthropic. Section 5 states what Anthropic does and does not do with that data, and section 7 states how long it is kept.
5. Third parties we use
- Plaid Inc. — bank connectivity. You enter your bank credentials in Plaid's secure interface; Nova never sees or stores them. See plaid.com/legal.
- Anthropic, PBC — the AI processing behind transaction categorization,
receipt reading, voice entry, bank- and investment-statement parsing, subscription analysis and the
daily brief. We use the Claude API under Anthropic's Commercial Terms of Service, under which
customer content submitted through the API is not used to train Anthropic's models.
Anthropic's commercial data retention policy provides that API inputs and outputs are automatically
deleted from its systems within 30 days of being received or generated, and are
held during that window for security and abuse monitoring rather than for any product or
advertising purpose. Those commitments — no training, no advertising use, no onward sale, and
deletion on a fixed short schedule — are equivalent to the protections we commit to in this
policy, which is why we are willing to route the features above through them. See
Anthropic's Commercial
Terms and Anthropic's privacy
policy.
Anthropic, PBC processes this data under contractual terms that require protection equivalent to Nova's own. Data sent to Anthropic is used solely to return a result to you, is not used to train models, and is not retained for any other purpose.
These features are off by default. Nothing is sent to Anthropic unless you turn them on, and you can turn them off at any time in Settings → AI Features. - Vercel Inc. — hosting for our backend.
- Cloudflare, Inc. — hosting for this website.
- A market-data provider — stock prices, from ticker symbols only.
We do not sell personal data to anyone, and we do not share it with advertisers, data brokers or analytics companies.
6. Camera and photo-library access
Nova asks for camera access so you can photograph a receipt or a statement, and for photo-library access so you can choose an existing image to attach or import. Both are used only for receipts and statement imports, and only for the specific file you pick. Nova does not scan, index or upload your photo library.
7. Server logs and retention
Our backend does not store your financial data. It receives a request, performs the work described in section 4, returns the result, and keeps no copy of your transactions, holdings or statements.
Our hosting provider generates operational logs — timestamp, endpoint, response status, IP address and error diagnostics — which exist for security and debugging. These are retained by our hosting provider for no more than 24 hours and are not used for profiling, advertising or any other purpose.
Retention at Anthropic. Because our backend keeps no copy, the only place data sent for an AI feature persists at all is Anthropic's own systems, and only briefly. Under Anthropic's commercial data retention policy, the text or image we send and the result it returns are deleted automatically within 30 days, and are not used to train models at any point. We have not enabled any Anthropic feature that extends retention beyond that window. This is the honest ceiling: not zero, but 30 days at a processor that cannot connect the data to a name, an email address or an account, because we never send one.
8. Deleting your data
- Delete the app. Because your financial data is stored on your device, removing Nova removes the database with it.
- Erase data in the app. Settings includes a function that clears the local database. This cannot be undone, and there is no server copy to restore from.
- Unlink a bank. Removing a linked institution in Nova deletes the stored access token for it and stops future syncing.
Since we hold no account and no copy of your data, there is nothing on our side for us to delete. If you believe we hold information about you, write to privacy@alphanovaai.app.
9. Cookies and tracking — we don't
Nova does not track you, and this website sets no cookies of any kind. There are no analytics, no tag managers, no advertising or tracking identifiers (including Apple's IDFA), no fingerprinting, no cross-app or cross-site tracking, no data brokers, and no joining of your data with third-party data for advertising. Because we do no tracking as defined by Apple's App Store Review Guideline 5.1.2(i), the app does not present an App Tracking Transparency prompt.
alphanovaai.app loads no fonts or scripts from third parties and makes no external network requests. Our host records standard server request logs for security and availability, described in section 7.
Connecting a bank opens Plaid's own secure page. Any cookies or notices you see there belong to Plaid and exist for bank authentication, not for tracking or advertising. See plaid.com/legal.
10. Children
Nova is not directed to children under 13, and we do not knowingly collect information from them.
11. California privacy rights (CCPA/CPRA)
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use personal information for cross-context behavioral advertising. We do not collect personal information into an account, so there is generally nothing for us to disclose, correct or delete on request. You have the right to know, delete, correct, and to be free from discrimination for exercising those rights; write to privacy@alphanovaai.app and we will respond.
12. Your rights
Where data-protection law gives you rights of access, rectification, erasure, restriction, portability and objection, we honor them. In practice, your data is in your hands: it is on your device, you can export or erase it yourself, and we hold no account copy. Requests that concern us directly — for example our server logs — should go to privacy@alphanovaai.app.
Where we process data to deliver a feature you asked for, our legal basis is performance of the service you requested; where we keep security logs, it is our legitimate interest in operating the service safely.
13. Mexico
For users in Mexico, the Spanish version of this document is presented as an Aviso de Privacidad under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). Leer el Aviso de Privacidad.
14. Changes to this policy
If we change how the app handles data, this policy changes before the release ships. The effective date at the top marks the current version, and material changes will be noted in the app.
15. Contact
Privacy questions and requests: privacy@alphanovaai.app
Product support: support@alphanovaai.app
Sammamish, WA
United States
This policy is governed by the laws of the State of Washington, United States.