Privacy
Last updated: June 6, 2026.
Short version
Nova helps you track your net worth across accounts. If you only join the waitlist, the only thing we hold is your email address, used once to tell you when access opens. If you create an account and connect institutions, we also store the financial data needed to build your balance sheet (described below). We do not show advertising, run third-party tracking pixels, or sell your data. You can request deletion at any time by emailing hello@novanetworth.com.
What we collect
- Email address you submit to the waitlist.
- If you create an account: your email and authentication metadata (via Clerk), and your subscription status (via Stripe).
- If you connect a bank or brokerage: account names and types, balances, holdings, and (when authorized) transactions and tax-lot cost-basis data. Access tokens and connection secrets are encrypted at rest (AES-256-GCM). We never receive or store your institution login credentials.
- Standard server logs (IP, user-agent, timestamp) for security and rate limiting. Retained 30 days.
Who we share it with
Subprocessors only, to operate the service:
- Vercel — hosting and edge logs.
- Resend — email delivery and audience storage.
- Clerk — authentication and account session management. Stores your email address, hashed credentials, and session metadata.
- Plaid — bank and brokerage account connectivity. When you connect an institution, Plaid (acting as our service provider) collects credentials directly from you and returns access tokens, account metadata, balances, and (when authorized) transactions to Nova. See Plaid’s End User Privacy Policy.
- SnapTrade — read-only brokerage connectivity used to import positions and broker-native tax-lot cost basis. When you connect a brokerage, SnapTrade returns account metadata, balances, holdings, and tax-lot data to Nova; we never place trades, move money, or change your account settings. SnapTrade is SOC 2 Type II certified and encrypts data in transit and at rest. See SnapTrade’s Privacy Policy.
- Stripe— subscription billing and payment processing. Card details are entered into Stripe’s hosted checkout and never touch Nova servers; we receive only a customer ID, subscription state, and the last four digits of your card. See Stripe’s Privacy Policy.
- Frankfurter — public foreign-exchange rate feed used for non-USD account valuation. No personal data is sent; we query only currency codes (e.g. “EUR”, “GBP”).
- FRED (Federal Reserve Economic Data) — public U.S. Treasury yield feed used to benchmark idle-cash and savings-rate suggestions. No personal data is sent; we query only public economic-data series.
We do not sell or rent your information.
Your rights
You can request access, correction, or deletion of your data. EU/UK residents have GDPR rights; California residents have CCPA rights. Email us and we’ll respond within 30 days. When you delete your account, we remove your data from Nova and revoke our connections at Plaid and SnapTrade, so they stop sending us your account data. You can also export your balance sheet and history as CSV at any time from your dashboard.