Security and data

Last updated September 15, 2026

This unofficial plugin connects your chosen AI app to Lunch Money. Here is what passes through the service, what is stored, and how to stop access. For the full notice, read our Privacy policy.

Read-only access

The connector exposes tools for reading accounts, transactions, categories, tags, recurring items, and budgets. It does not expose tools to edit your financial records. Read-only access is enforced by this connector; your Lunch Money API token may have broader permissions.

Enter your token only on the browser connection page. Never paste it into a conversation. Nango stores the token, and the connector retrieves it temporarily to make allowed requests to Lunch Money.

What we process and retain

  • Account and connection records: internal user ID, authentication issuer and subject, connection identifiers, status, environment, and timestamps are stored in Cloudflare D1 to associate your connection with your account.
  • Financial results: requested records pass through the connector to your AI app. The connector does not persist financial responses in its database. Your AI app and its model provider may retain those results in conversations under their own settings and policies.
  • Operational counts: allowlisted event labels, tool names, and HTTP status codes help measure reliability. Connector telemetry excludes user identifiers, tool arguments, tokens, connection links, request bodies, and financial results. Infrastructure providers may keep separate security and network logs.
  • Website usage: PostHog receives page-view, Connect-click, and successful setup-copy events with a fresh random identifier for each event. We do not send financial data, credentials, chat content, page URLs, referrers, or user identities in those events. The website uses no analytics cookies or session recording. PostHog still receives network information, including your IP address, when your browser connects.

Website usage counts are enabled by default. You can disable them; Global Privacy Control and Do Not Track also prevent collection. An explicit preference is stored locally for 180 days.

Services involved

These providers handle different parts of the connection. Their policies explain their own processing and retention.

  • Auth0 (Okta): account sign-in at auth.n3wth.com and authentication information. Privacy policy.
  • Nango: browser connection setup and storage of your Lunch Money API token. Privacy policy.
  • Cloudflare: connector execution, identity and connection records in D1, and operational telemetry. Privacy policy.
  • Vercel: website hosting and routing requests to the connector. Privacy notice.
  • PostHog US Cloud: website usage events described above. Privacy policy.
  • Lunch Money: your original financial records and API requests authenticated with your token. Privacy policy.

Your chosen AI app also receives the requested financial results. Review its privacy policy and data controls before connecting: OpenAI (ChatGPT and Codex), Anthropic (Claude), Cursor, or xAI (Grok). Listing a provider here does not mean its integration is available or verified.

Disconnecting and deleting data

Ask your AI to disconnect Lunch Money using the plugin's disconnect tool. This blocks further reads and requests deletion of the Nango connection. If deletion is pending, retry until it succeeds. To revoke the original token, use Lunch Money's Developers page. Uninstalling the plugin alone does not disconnect it or revoke the token.

Identity and connection lifecycle records remain after disconnect to preserve ownership and prevent replay or reconnection races. They do not currently have an automatic expiry. Provider logs and backups follow their respective retention settings. This integration does not configure automatic deletion of PostHog events.

Disconnecting does not delete your AI chat history. Manage that through your AI provider. For removal of retained connector records, contact oliver@newth.ai.

Report a security issue

Email oliver@newth.ai with a description and steps to reproduce. Do not include API tokens or financial records. You can also inspect the source code.