Legal

Privacy Policy

How Nobleway collects, uses, and protects information during the public beta.

Overview

This Privacy Policy describes how Nobleway (nobleway.app), operated by Stansa Labs LLC ("we", "us", or "our"), collects, uses, and handles information when you use our household financial tracking service during the public beta.

Nobleway is designed for you to enter and manage your own financial records. We do not offer bank account synchronization.

Information we process

Account and identity information. When you sign up or sign in, authentication is handled by Clerk. We receive identifiers and profile details needed to operate your account (for example, your user ID and email address).

Financial and household data you provide. This includes transactions, accounts, categories, people, imports, exports, and related metadata you create or upload in your workspace. This data is stored in our application database (PostgreSQL) as your ledger.

AI-assisted features. When you use capture, natural-language query interpretation, or optional explanations, limited context from your workspace (such as catalog labels and the text you submit) may be sent to the configured AI provider. The AI suggests structured interpretations; it does not directly write to your ledger. You confirm before capture results are saved.

Bring-your-own-key (BYOK) credentials. If you configure your own AI provider key (Gemini, OpenAI, Anthropic, or OpenRouter), that key is stored encrypted for use with your account or workspace according to the product settings.

Support and operational data. If you contact us, we receive the information you choose to send (for example, your message, User ID, or Workspace ID). Server logs may include request metadata such as timestamps, paths, and request IDs. We configure logging not to include authentication tokens, API secrets, or full financial payloads.

How we use information

We use the information above to provide, maintain, and improve Nobleway; to authenticate you; to store your ledger; to run AI-assisted features you request; to send transactional email such as workspace invitations and optional due-recurring reminders; to respond to support requests; and to protect the service from abuse.

We do not sell your personal information or ledger data.

AI processing

Nobleway's deterministic financial engine is authoritative for ledger calculations and writes. AI is used to help interpret natural-language capture input, interpret natural-language questions, and optionally generate explanations. AI output is a draft or suggestion until you review and confirm (for capture) or until results are shown from your existing ledger data (for queries).

When AI features run, requests may be sent to Google Gemini (platform default) or to another provider you configure with BYOK, including OpenRouter. OpenRouter is an intermediate API that can route your request to an underlying model provider. We have not verified provider-side retention schedules; review your provider's policies if you use BYOK or need details about platform AI handling.

Cookies and local storage

Nobleway does not currently use advertising or marketing analytics cookies, and the application does not currently operate a separate analytics product.

Authentication (Clerk). Clerk sets cookies and similar technologies needed to keep you signed in and secure your session. These are essential for using the authenticated product.

Application preferences (first-party). We use browser cookies and local storage for product functionality, including:

  • Theme preference (light, dark, or system)
  • Sidebar layout preference
  • Date and time display format
  • Active workspace selection
  • Draft capture and ask-query input stored locally per workspace until submitted or cleared

These mechanisms are used to remember your choices and improve your experience. They are not used for cross-site advertising.

Optional error monitoring. If configured by the operator, Sentry may receive error reports. Our integration is designed not to send request bodies, authentication headers, or financial form contents.

You can clear cookies and local storage in your browser at any time; doing so may sign you out or reset local preferences and drafts.

Service providers

Depending on how the service is deployed, information may be processed by:

  • Clerk - authentication and session management
  • Hosting and database providers - to run the application and store your ledger
  • AI providers - Google Gemini by default, or OpenAI, Anthropic, or OpenRouter when you supply BYOK keys. OpenRouter may forward requests to an underlying model provider.
  • Resend - optional transactional email for workspace invitations and due-recurring reminders when enabled by the operator
  • Sentry - optional error monitoring when configured

Depending on the service and configuration, these providers may process information to provide authentication, hosting, monitoring, email, or AI functionality. Providers such as Clerk, hosting and database vendors, Resend, and Sentry (when enabled) support operation of the service. BYOK AI providers are used at your direction when you configure your own provider credentials.

Data retention and deletion

We retain your ledger and account-related data while your account and workspace remain active and as needed to provide the service.

You can close your account from Settings. Closing your account deletes it and any households you solely own, and we ask Clerk to delete your authentication record. If you still own a household with other members, transfer ownership first. You can also delete a household you own from Workspace settings. Deletion is permanent. For help, contact privacy@nobleway.app or support@nobleway.app with your User ID and Workspace ID.

Security

We use technical and organizational measures appropriate for a beta financial tracking application, including authenticated API access, encrypted transport (HTTPS), and encryption for stored BYOK credentials. No method of transmission or storage is completely secure.

Children

Nobleway is not directed at children under 13, and we do not knowingly collect information from children.

Changes

We may update this Privacy Policy as the product evolves. We will post the updated version on this page and adjust the "Last updated" date.

Contact

Questions about this policy or your data: privacy@nobleway.app or support@nobleway.app. See also our Terms of Service.