1. Summary
Your financial data is stored on your device, not on our servers. Nova has no user accounts, so there is nothing on our side tied to you — no email address, no password, no profile, and no copy of your financial history.
A small number of features send specific data to our backend so it can be processed and returned. Section 4 lists each one, what it contains, and whether you trigger it. We do not sell personal data, we do not share it with advertisers, and there is no advertising or tracking SDK in the app.
2. No account, no server copy
Nova does not have a sign-up or sign-in. We do not ask for your name, email address or phone number, and we do not create a profile for you. Because there is no account, there is no server-side record of your transactions, budgets, goals, holdings or receipts.
3. What stays on your device
- All financial data — transactions, categories, budgets, envelopes, goals, investment holdings and receipt photos — is stored in a local SQLite database on your device.
- Plaid access tokens — the tokens that let Nova refresh your accounts — are stored in the iOS Keychain or Android Keystore, not in general app storage.
- Settings — language, currency, display preferences — are stored in local device storage.
Data stored on your device is protected by your device's own security: passcode, biometrics and operating-system encryption. Keeping your device locked and up to date is an important part of keeping this data private.
4. What leaves your device, and exactly what it contains
All outbound requests go to Alpha Nova AI LLC's own backend, which passes the relevant part on to the service provider that performs the work. The table is the complete list.
| Feature | What is sent | Triggered by |
|---|---|---|
| Connecting a bank | A Plaid public token, exchanged for an access token. Your bank credentials are entered inside Plaid's own interface and never touch Nova or our servers. | You, when you link an account |
| Transaction categorization | Transaction id, merchant name and amount, plus your own category labels. Sent in batches of 40. | Automatically, during sync |
| Daily brief | Aggregates only — month, budget, amount spent, amount available, today's spend, transaction count, days remaining, and per-category totals. No merchant names and no individual transactions. | You, when you open the brief |
| Investment statement import | The image or PDF you chose. It contains the account names and holdings printed on it. | You, when you pick a file |
| Bank statement import | The statement file you chose. | You, when you pick a file |
| Subscription detection | Recurring-charge candidates identified on the device. | You, when you run the check |
| Stock prices | Ticker symbols only. No share counts, no balances, no account names. | Automatically, to refresh prices |
Every one of these is initiated by you except transaction categorization, which runs as part of sync. We state this asymmetry plainly rather than summarizing it: categorization sends merchant names and amounts; the daily brief sends only totals.
5. Third parties we use
- Plaid Inc. — bank connectivity. You enter your bank credentials in Plaid's secure interface; Nova never sees or stores them. See plaid.com/legal.
- Anthropic, PBC — AI categorization, statement parsing and daily-brief generation. Data sent for these features is processed to return a result and is not used to train models.
- Vercel Inc. — hosting for our backend.
- Cloudflare, Inc. — hosting for this website.
- A market-data provider — stock prices, from ticker symbols only.
We do not sell personal data to anyone, and we do not share it with advertisers, data brokers or analytics companies.
6. Camera and photo-library access
Nova asks for camera access so you can photograph a receipt or a statement, and for photo-library access so you can choose an existing image to attach or import. Both are used only for receipts and statement imports, and only for the specific file you pick. Nova does not scan, index or upload your photo library.
7. Server logs and retention
Our backend does not store your financial data. It receives a request, performs the work described in section 4, returns the result, and keeps no copy of your transactions, holdings or statements.
Our hosting provider generates operational logs — timestamp, endpoint, response status, IP address and error diagnostics — which exist for security and debugging. These are kept for a short operational period and are not used for profiling, advertising or any other purpose.
Note for review before publication: confirm the exact log retention period and whether request bodies are logged, then state the number here. Do not publish an estimate.
8. Deleting your data
- Delete the app. Because your financial data is stored on your device, removing Nova removes the database with it.
- Erase data in the app. Settings includes a function that clears the local database. This cannot be undone, and there is no server copy to restore from.
- Unlink a bank. Removing a linked institution in Nova deletes the stored access token for it and stops future syncing.
Since we hold no account and no copy of your data, there is nothing on our side for us to delete. If you believe we hold information about you, write to privacy@alphanovaai.app.
9. This website
alphanova.ai sets no cookies, runs no analytics, loads no fonts or scripts from third parties, and makes no external network requests. Our host records standard server request logs for security and availability.
10. Children
Nova is not directed to children under 13, and we do not knowingly collect information from them.
11. California privacy rights (CCPA/CPRA)
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use personal information for cross-context behavioral advertising. We do not collect personal information into an account, so there is generally nothing for us to disclose, correct or delete on request. You have the right to know, delete, correct, and to be free from discrimination for exercising those rights; write to privacy@alphanovaai.app and we will respond.
12. Your rights
Where data-protection law gives you rights of access, rectification, erasure, restriction, portability and objection, we honor them. In practice, your data is in your hands: it is on your device, you can export or erase it yourself, and we hold no account copy. Requests that concern us directly — for example our server logs — should go to privacy@alphanovaai.app.
Where we process data to deliver a feature you asked for, our legal basis is performance of the service you requested; where we keep security logs, it is our legitimate interest in operating the service safely.
13. Mexico
For users in Mexico, the Spanish version of this document is presented as an Aviso de Privacidad under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). Leer el Aviso de Privacidad.
14. Changes to this policy
If we change how the app handles data, this policy changes before the release ships. The effective date at the top marks the current version, and material changes will be noted in the app.
15. Contact
Privacy questions and requests: privacy@alphanovaai.app
Product support: support@alphanovaai.app
Sammamish, WA
United States
This policy is governed by the laws of the State of Washington, United States.