Privacy
Lunch Money for Agents is operated by Oliver Newth as an independent project. It is not affiliated with, endorsed by, or sponsored by Lunch Money. This notice covers lunchmoney.sh and its hosted MCP connector.
Information processed
When you sign in through Auth0 at auth.n3wth.com, the connector uses your verified account identifier to associate your connection with your account. It stores an internal user ID, the authentication issuer and subject, connection identifiers, connection status, environment, and timestamps in Cloudflare D1.
When you request a financial tool, the connector retrieves the requested information from Lunch Money, such as accounts, transactions, categories, tags, recurring items, or budget summaries. It processes those results to answer your request and does not persist financial responses in its database.
Your Lunch Money token
You enter your token in Nango's browser-based connection flow, not in chat. Nango stores the token. The connector retrieves it temporarily to make allowed requests to the Lunch Money API. The connector enforces financial reads only, even if the token itself has broader permissions.
Who receives information
Auth0 handles authentication. Nango handles credential storage and connection setup. Cloudflare runs the connector and stores identity and connection records. Vercel hosts the website and routes requests to the connector. Lunch Money processes requests made to its API.
Requested financial results are returned to the MCP client you choose, and may be sent to that client's model provider. Your client's privacy settings and provider policies govern their handling and retention of those results. This connector does not control or delete your chat history.
Website and operational logs
The website's example conversations use fictional data and run locally. The site includes no third-party analytics or advertising trackers. Authentication providers may use cookies on their login pages.
Connector telemetry contains allowlisted event labels and HTTP status codes. The application does not log tokens, connection links, request bodies, or financial results. Hosting and authentication providers may retain their own operational or security logs, including network information such as IP addresses.
Disconnecting and retention
Call lunchmoney_disconnect to block further reads and request deletion of the Nango connection. If deletion is pending, retry until it succeeds. Disconnecting does not revoke the original Lunch Money token: revoke it in Lunch Money to prevent its further use elsewhere.
Identity records and connection lifecycle records remain after disconnect to preserve ownership and prevent replay or reconnection races. The service does not currently apply an automatic expiry period to these records. Infrastructure backups and provider logs follow the respective providers' retention settings. Uninstalling a plugin alone does not disconnect the service.
For a request about your information or removal of retained connector records, contact oliver@newth.ai. Do not include API tokens or financial records in your email.
Questions and changes
Contact oliver@newth.ai with privacy questions. Changes to the connector's data handling will be reflected on this page with an updated date.