Security at Nova.
Nova asks you to link your financial accounts, so here is exactly what happens to that data: what we store, how it’s encrypted, who else touches it, and how to take it back. No vague “bank-grade” language, and no certifications we don’t hold.
Last updated: September 28, 2026.
Read-only connections
Banks connect through Plaid and brokerages through SnapTrade, both read-only. Nova has no code that moves money, starts transfers, or places trades.
Connection secrets are envelope-encrypted
Each bank and brokerage connection token is sealed with its own AES-256-GCM key, and that key is wrapped by a master key kept outside the database.
Access you can take back
Disconnect an institution, revoke an API token, or delete a shared scenario, and that access ends on the next request.
Your data leaves with you
Download your balance sheet and history as CSV any time. Deleting your account also removes our connections at Plaid and SnapTrade.
How your data flows
Banks, through Plaid. You sign in to your bank inside Plaid’s window. Plaid collects your credentials, not Nova. Nova asks Plaid for transactions and, where your bank supports them, investment holdings and loan details. Plaid sends back a connection token and your account data. Nova does not request any Plaid product that moves money.
Brokerages, through SnapTrade. You sign in to your brokerage directly through SnapTrade’s connection portal. Nova calls SnapTrade’s data endpoints only; its trading endpoints aren’t called anywhere in our code.
What we store. Your accounts, balances, holdings, transactions, and entity structure, plus anything you enter by hand, like a property address or a vehicle’s VIN for valuations. It lives in a managed Postgres database hosted by Supabase.
What we never store. Your bank or brokerage password (Plaid and SnapTrade handle that sign-in), your Nova password (Clerk handles sign-in), or your card number (Stripe’s hosted checkout handles payment).
Where AI fits. Nova’s suggestions come from its own deterministic rules. AI only explains: when you click “Explain this Math,” that suggestion and a snapshot of your portfolio go to OpenAI to write the plain-English explanation. If you never click it, nothing goes to OpenAI.
Encryption
In transit. Nova is served over HTTPS and sends a Strict-Transport-Security header that tells browsers to refuse plain HTTP for two years, on every subdomain.
Connection secrets at rest. Plaid access tokens and SnapTrade user secrets are the keys to your linked accounts, so they get an extra layer. Each one is encrypted with its own random 256-bit key using AES-256-GCM. That per-record key is then encrypted with a master key held in our hosting environment’s secrets, not in the database, so a copy of the database alone can’t unlock your connections. The master key can be rotated without re-linking accounts.
Everything else. Balances, holdings, and transactions are stored as regular database rows so Nova can do the math on them. The envelope layer covers the connection secrets.
API tokens. Nova stores only a SHA-256 hash of each API token. The token itself is shown to you once, when you create it.
Who else touches your data
These are the services Nova uses to run. We don’t sell or rent your information. The same list, with links to provider policies, is on our Privacy page.
| Provider | What it does and what it receives |
|---|---|
| Vercel | Hosting and edge logs. |
| Supabase | Managed Postgres database. Stores your balances, holdings, transactions, and entity structure. |
| Clerk | Sign-in and sessions. Stores your email address, hashed credentials, and session metadata. |
| Plaid | Bank and brokerage connections. Collects your bank credentials directly from you; Nova never sees them. |
| SnapTrade | Read-only brokerage connections. You sign in to your brokerage on their side. |
| Stripe | Billing. Card details go into Stripe’s hosted checkout and never touch Nova servers. |
| Resend | Email delivery and audience storage. |
| OpenAI | Only when you click “Explain this Math.” Receives that suggestion and a snapshot of your portfolio to write the plain-English explanation. The suggestion itself comes from Nova’s own rules. |
| Sentry | Error monitoring. Default personal-data collection is off and sensitive fields are scrubbed before sending. |
| Upstash | Rate limiting and caching. Receives IP addresses and account identifiers used as rate-limit keys. |
| PostHog | Product analytics, only if analytics is enabled. No automatic click capture or session recording. |
| ATTOM | Real-estate valuation. Receives the property address you enter. |
| Smarty | Address autocomplete. Receives the address text you type. |
| MarketCheck | Vehicle valuation. Receives the VIN, mileage, and ZIP code you enter. |
| NHTSA vPIC | Public U.S. government VIN decoder. Receives only the VIN. |
| Metals.dev | Precious-metal prices. No personal data; we send only which metal. |
| CoinGecko | Crypto prices. No personal data; we send only which coin. |
| JustTCG | Trading-card prices. No personal data; we send only which card. |
| Frankfurter | Public foreign-exchange rates. We send only currency codes. |
| FRED | Public U.S. Treasury yields for savings-rate comparisons. We send only public series IDs. |
Read-only API and MCP access
From the Developer page in the app, you can create a personal access token to read your own data through Nova’s API, or connect it to an AI assistant over MCP. Every endpoint and tool is read-only: net worth, net-worth history, accounts, holdings, and transactions. There are no write scopes.
New tokens expire after one year. You can revoke a token at any time from the same page. A revoked token is deleted, and the next request made with it is rejected.
Share links
You can share a saved tax-loss-harvesting scenario with your accountant through a link. The link shows that one scenario, read-only, and search engines are told not to index it. To stop sharing, delete the saved scenario: the link stops working immediately and shows a generic not-found page that reveals nothing about what was there. A revoked link never comes back; sharing again creates a new one.
Export, disconnect, delete
Export. Download your balance sheet and your net-worth history as CSV from the dashboard, any time.
Disconnect an institution. Removing a bank connection tells Plaid to delete it on their side and deletes our stored connection token. The accounts stay in Nova as manual accounts with their history, so your past numbers don’t disappear.
Delete your account. Email hello@novanetworth.com from the address on your account and we’ll respond within 30 days. When your account is deleted, Nova cancels your Stripe subscription, removes your connections at Plaid, deletes your SnapTrade user, and only then deletes your records from our database. That order is deliberate: if a provider is briefly unreachable, the deletion retries instead of leaving your data behind at the provider.
Backups. Our database host takes daily backups and keeps them for 7 days, so deleted data ages out of backups after that. We keep a written restore runbook for recovering from an incident.
What we don’t claim
Nova is not SOC 2 certified and hasn’t had a third-party security audit yet. When that changes, this page will say so. Some of the providers above hold their own certifications; theirs are not ours.
Nova is built by a Service-Disabled Veteran-Owned Small Business, certified by the U.S. Small Business Administration.
Report a vulnerability
If you think you’ve found a security problem in Nova, email hello@novanetworth.com with “Security report” in the subject. A real person reads that inbox. Include what you found, the steps to reproduce it, and what an attacker could do with it.
Please test only against your own account, don’t access or change anyone else’s data, avoid anything that degrades the service for other people, and give us a reasonable chance to fix the problem before you publish it. There’s no paid bug bounty today.