Legal
Privacy Policy
What information Nora collects, why it is used, who helps process it, and the choices available to you.
Last updated 26 August 2026
Placeholder page. This page reflects the reviewed product code, but final contacts, retention periods, processing regions, and some provider settings still need confirmation before publication.
1. Scope and operator
Nora is operated by Benjamin Ollomo. This Policy applies to Nora's website and personal-finance service, including connected accounts, transactions, Nora Chat, Boards, and related features. Nora is currently intended for users in the United States and Canada.
2. Information we collect
Account information
Nora supports Google sign-in and verified email-and-password accounts. We may receive your name, email address, a one-way password hash when you choose password sign-in, Google account and authentication-provider information, account and session identifiers, and settings and preferences. Nora does not receive your Google password or store a readable Nora password.
Connected financial information
When you connect through Plaid, Nora may receive institution and account details, partial account numbers, currencies, balances, credit limits, transaction dates and amounts, descriptions, merchants, categories, and pending or posted status. Nora may normalize, categorize, or derive additional information so features work consistently.
Information you create
We store transaction edits, category and merchant choices, Nora Chat messages and conversations, Board descriptions and content, Board conversation history, and product preferences you choose to create or change.
Technical and operational information
Nora and its infrastructure may process session data, IP address, browser and device information, timestamps, request metadata, authentication lifecycle and audit events, sync status, errors, feature usage, AI model and token usage, and application or AI timing. Better Auth Infrastructure can receive server-generated authentication events containing identifiers, name, email, session ID, login method, user agent, IP address, and approximate location. Nora does not enable its Sentinel browser fingerprinting or request-enforcement plugins. The public site and authenticated product offer separate opt-ins for privacy-minimized PostHog analytics and session replay; replay cannot operate without analytics consent. Nora uses a random browser identifier that rotates every 30 days and is not linked to a Nora account. Events exclude financial values, prompts, content, names, emails, and Nora, database, and provider identifiers. Replay masks all inputs and rendered text by default and blocks financial pages, Chat, Boards, settings, sign-in, Plaid, search, and exports. It excludes network bodies and headers, console logs, clipboard contents, canvas, cross-origin provider frames, and performance capture. URLs omit query strings and fragments and redact sensitive path segments. Provider access, retention, deletion/export permissions, processing region, and disable controls still need separate production verification. Resend receives the recipient address and authentication-message content required to deliver verification, recovery, and password-change email. Nora retains hashed-recipient delivery and webhook metadata for 90 days.
3. Bank login credentials
Your bank username and password are entered through Plaid or your institution, not Nora. Nora receives a Plaid access token for the information you authorize and encrypts it before storage. Plaid's own processing is governed by its privacy notices and terms.
4. How we use information
We use information to authenticate you; connect and synchronize institutions; display and search accounts and transactions; support transaction edits; calculate spending, income, cash flow, and other metrics; identify recurring activity; provide analytics; answer Nora Chat questions; generate requested explanations; create and validate Boards; enrich merchant data; support and secure Nora; diagnose errors; measure reliability; comply with law; and enforce the Terms.
We do not use connected financial information for third-party advertising.
5. Artificial intelligence
Nora currently uses Google Gemini for Nora Chat, contextual explanations, Board creation and editing, and merchant enrichment. Depending on the feature, Gemini may process messages, authenticated finance-tool results, verified explanation inputs, Board descriptions and content, or merchant names and transaction descriptions.
Nora uses these features as a financial coach and decision-support tool. Facts, interpretations, estimates, and coach suggestions are presented as distinct types of information. AI output is not professional financial, tax, legal, insurance, investment, or debt advice and does not guarantee an outcome.
Gemini does not receive unrestricted database access, bank passwords, Plaid tokens, or encryption keys as financial context. AI output can still be inaccurate. The production Google project's paid-service status, abuse-monitoring retention, and optional data-sharing settings must be verified before Nora makes broader promises about Google's use of inputs and outputs.
6. Service providers and disclosure
Nora currently relies on:
- Plaid for financial-account connectivity;
- Google for authentication, Gemini AI, and cloud infrastructure;
- MongoDB technology for application data storage;
- Vercel for web hosting and delivery;
- PostHog for optional public-site and product analytics and privacy-masked session replay;
- Brandfetch for merchant websites, branding, and logos;
- Better Auth Infrastructure for authentication event logging and provider-hosted account and session administration.
- Resend for transactional authentication email.
We may also disclose information when required by law, to protect people or the service, in a business transfer, or at your direction. Nora does not sell personal or connected financial information or share connected financial information for cross-context behavioral advertising.
7. Internal access
Nora is currently operated by Benjamin Ollomo. Stored information may be accessed when reasonably necessary for support, troubleshooting, maintenance, security, reliability, or legal compliance. The product does not yet have a dedicated Nora support role or Nora-owned administrative console. Better Auth Infrastructure provides provider-hosted authentication audit and user or session administration capabilities; its deployed roles, access reviews, and retention settings require separate verification.
8. Retention, disconnection, and deletion
Disconnecting stops normal synchronization and asks Plaid to remove the connection. If removal is pending, the encrypted token may be held temporarily for a retry. Once removal completes, a separate action can soft-delete imported connection data from normal product use.
Chat threads and Boards also use separate soft-delete behavior. Nora does not yet have one account-wide deletion route or a finalized schedule for permanent erasure, Better Auth Infrastructure authentication events, telemetry, or backup retention. Authentication-email delivery and webhook metadata expires after 90 days; bounce and complaint suppressions remain so Nora does not repeatedly send to an unusable address. We will update this Policy when the broader procedures are finalized.
Production replay is limited to a stable 5% sample of consenting anonymous browsers by default. Nora targets seven days for replay and 90 days for analytics events, subject to production-provider verification. Withdrawing analytics consent stops capture and removes the anonymous identifier from that browser. Existing anonymous provider data expires under retention or may require a separate privacy request because it is not mapped to your Nora account.
9. Security and international processing
Nora uses authenticated ownership checks, encrypted provider tokens, and server-side secrets, but no system is completely secure. Providers may process information outside your location; the database hosting region and complete cross-border details still need confirmation.
10. Your choices and rights
You can choose not to connect an institution, disconnect one, delete eligible connection data after provider removal, remove individual Chat threads or Boards, or stop using Nora. Depending on where you live, law may also provide rights to access, correct, delete, or receive a copy of personal information, or object to or restrict certain processing.
A self-service application-data export is available under Settings, Privacy & Data. Anonymous PostHog analytics and replay are not included because they are not mapped to your Nora account. Account-wide deletion and a verified privacy-request process are not yet implemented. Until a privacy contact is confirmed, use the support page.
11. Children and policy changes
Nora is not intended for children under 18. We may update this Policy as the product, providers, or law changes and will provide notice of material changes where required.