← Back to Norviq

Privacy Policy

Last updated 21 July 2026

Norviq is a private financial planning tool. This policy explains what data we collect, why, who helps us process it, and the controls you have. This is a product draft pending counsel review.

Data we collect

Account information (email, authentication identifiers), financial data you enter or import (portfolios, holdings, expenses, budgets, tax preferences), and usage and diagnostics data used to operate and improve the app.

When subscriptions are enabled, we process billing state from RevenueCat and App Store or web billing events (subscription status, entitlement level, product and event identifiers). Raw billing provider payloads are operational records and are not included in standard user exports.

Connected financial accounts

When you connect a brokerage or bank account, Norviq accesses that data on a read-only basis. Norviq cannot place trades, move money, or modify data at your financial institution.

Interactive Brokers (IBKR): when enabled, portfolio and statement data may be ingested through the Norviq Web Service reporting feed using credentials you provide. IBKR acts as a sub-processor for that reporting data.

Bank connections use Plaid (United States) and GoCardless (European Union) as data processors. Access tokens are stored encrypted at rest. You can revoke any connection at any time from Integrations.

AI features and MCP

In-app assistant, insight cards, and proactive tips are provided by Norviq and may send limited portfolio and spending context to our AI model providers (for example OpenAI or OpenRouter) to generate responses. Those calls are Norviq-paid and subject to usage limits.

Model Context Protocol (MCP) access is user-directed: you connect your own LLM client (such as Claude, Cursor, or ChatGPT) with a Norviq personal access token. Norviq provides tools and your account data to that client; the LLM provider is chosen and billed by you, not by Norviq. Do not treat your Norviq PAT as an OpenAI or Anthropic API key.

Receipt scanning

Receipt images captured for expense entry are processed transiently to extract amount, merchant, and date, and are not retained as a long-term image archive after processing completes.

Sub-processors (summary)

Infrastructure and hosting (compute, database, Redis, object storage), email and push delivery, market-data providers, billing (RevenueCat / App Store / web payments), observability, IBKR reporting feed (when connected), Plaid, GoCardless, and AI model providers for in-app features.

A records-of-processing checklist for launch and DPA status is maintained internally by Norviq operations. Contact privacy@norviq.com for the current sub-processor list or a data processing agreement request.

Your controls

You can disconnect financial accounts, delete individual records, export data through support, or delete your entire account and associated product data from within the app where supported.

Contact

Privacy, export, and deletion requests: privacy@norviq.com.