Privacy Policy
Effective Date: August 14, 2026
Last Updated: August 14, 2026
Our Privacy Commitment
nint is built on a simple principle: your financial data belongs to you. This isn't just a policy statement — it's an architectural guarantee. Our local-first design means your financial data is processed and stored on your device, not our servers.
This Privacy Policy explains what limited data we do collect, why, and how we handle it.
What We Don't Collect
Because of our local-first architecture, we never have access to:
- Your bank account numbers or credentials
- Your transaction history or details
- Your spending patterns or categories
- Your budget amounts or configurations
- Your investment or portfolio data
- Your income or salary information
- Your location or behavioral data within the app
This data exists only on your device and, if you enable sync, in your personal iCloud account with end-to-end encryption. We cannot access it even if compelled by law — we simply don't have it.
What We Do Collect
Account Information
- Email address — for authentication and account recovery
- Name (optional) — for personalization
- Subscription status and plan — to provide the correct features
- Payment method metadata — processed by Stripe (we never see full card numbers)
Technical Data
- Anonymous crash reports (opt-in only) — device type, OS version, app version, crash stack trace. No financial data is ever included.
- App preferences — theme, language, date format (synced to enable multi-device consistency)
Analytics (Minimal)
- Page views on nint.app — via Google Analytics (GA4) with IP anonymization enabled
- Feature usage counts — aggregated, anonymous counters (e.g., "budget created") to guide product decisions. No transaction data included.
Account Linking (Pro Tier)
If you use Pro features with account linking:
- We use Plaid and/or Salt Edge as third-party aggregation providers
- These providers receive tokenized, read-only access to your bank accounts
- Transaction data pulled via these providers is processed on your device and never stored on our servers
- You can revoke access at any time from within the app
- Plaid's privacy policy: https://plaid.com/legal/#end-user-privacy-policy
- Salt Edge's privacy policy: https://www.saltedge.com/pages/privacy_policy
AI Processing
On-Device AI (Default)
All AI features (spending analysis, categorization, anomaly detection) run locally on your device using CoreML. No financial data is transmitted for AI processing.
Optional Cloud AI
If you explicitly opt in to cloud-enhanced AI:
- Data is encrypted in transit (TLS 1.3)
- Processing occurs in an isolated, ephemeral environment
- Data is immediately discarded after processing — never stored or used for training
- You can revoke consent at any time, returning to on-device only
Data Storage and Security
| Data | Where Stored | Encryption | Access |
|---|---|---|---|
| Financial data | Your device | AES-256 | You only |
| Sync data | Your iCloud | E2E encrypted | You only |
| Account email + plan | Our servers (Vercel/Supabase) | Encrypted at rest | Minimal staff |
| Payment processing | Stripe | PCI DSS Level 1 | Stripe only |
Encryption Standards
- At rest: AES-256 encryption for local vault
- In transit: TLS 1.3 for all communications
- Key management: Device secure enclave (iOS Keychain / macOS Keychain)
- Sync: Apple CloudKit end-to-end encryption (only you hold the keys)
- Password hashing: Argon2id
Third-Party Services
We use a limited number of third-party services:
| Service | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, payment method |
| Google Analytics | Website analytics | Anonymous page views (IP anonymized) |
| Vercel | Website hosting | HTTP request logs (14-day retention) |
| Plaid/Salt Edge | Account linking (Pro only) | Tokenized bank access |
| Apple CloudKit | Sync (optional) | E2E encrypted data |
| Resend | Transactional emails | Email address |
We do not share, sell, or provide your data to:
- Advertisers
- Data brokers
- Insurance companies
- Credit scoring companies
- Marketing companies
- Any third party for monetization purposes
Your Rights
Regardless of your jurisdiction, we provide all users with:
Access
You can view all data we hold about you at any time via Settings → Privacy → Data Inspector.
Portability
Export all your financial data in standard formats (CSV, JSON) directly from the app. Your data lives on your device — you already have it.
Deletion
- Account deletion: Request via Settings → Account → Delete Account, or email privacy@nint.app. We delete all server-side data within 30 days.
- Financial data: Already on your device — delete the app or clear data locally.
Correction
Update your account information at any time via Settings.
Objection
Object to any processing by contacting privacy@nint.app.
GDPR-Specific Rights (EU/EEA)
- Right to erasure (Article 17)
- Right to restrict processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right to lodge a complaint with your local Data Protection Authority
CCPA-Specific Rights (California)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale — we never sell personal information
- Right to non-discrimination for exercising privacy rights
Data Retention
| Data | Retention Period |
|---|---|
| Account information | Until account deletion |
| Crash reports | 90 days |
| Website analytics | 14 months (Google Analytics default) |
| HTTP logs | 14 days (Vercel) |
| Payment records | As required by tax law (typically 7 years) |
| Financial data | On your device — you control retention |
Children's Privacy
nint is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@nint.app and we will delete it.
International Transfers
Our servers are hosted in the United States (Vercel) and European Union (Supabase). The minimal data we store (email, subscription status) may be processed in either region. We rely on Standard Contractual Clauses (SCCs) for EU-to-US transfers where applicable.
Your financial data never leaves your device unless you enable iCloud sync — in which case it remains within Apple's infrastructure under their data processing agreements.
Cookies
nint.app uses:
- Strictly necessary cookies: Authentication session, locale preference
- Analytics cookies: Google Analytics (GA4) — you can opt out via your browser settings or our cookie banner
- No advertising cookies: We do not run ads or use tracking pixels
Changes to This Policy
We will notify you of material changes via email and/or an in-app notification at least 30 days before they take effect. The "Last Updated" date at the top reflects the most recent revision.
Contact
For privacy-related questions, data requests, or concerns:
- Email: privacy@nint.app
- Response time: Within 30 days (within 45 days for CCPA requests)
- Data Protection Officer: privacy@nint.app
nint is operated by nint Technologies, Zurich, Switzerland.