Overview
Nami: Spending Tracker ("we", "our", or "us") is a personal finance app that helps you understand your spending by analysing your transactions using AI. Your transactions reach Nami in one of two ways: through a read-only open banking connection to a bank you choose to connect, or from a bank statement you upload yourself. This policy explains what data we collect, how we use it, which third parties we share it with, and your rights.
Last updated: 11 September 2026
AI At a glance — AI data processing
- What we share: transaction data, whichever way it reached Nami. From a connected bank, that is the direction, amount, description and merchant of a transaction. From a statement (PDF or CSV) you upload, it is the content of that file — dates, merchant names, amounts, and surrounding statement text.
- Who it goes to: a third-party AI service, named in full in the AI Processing section below, used to categorise your transactions and to generate the spending insights you see in the app.
- What never goes with it: your bank login. From a connected bank, nothing that identifies you goes either: a transaction is sent with an opaque row reference and no name, email address, account identifier or account number. A statement is different. It is sent as it is, so whatever is printed on it, such as your name or an account number, goes with it.
- Retention: the AI provider does not use your data to train AI models, and keeps it only for a short period, to check for misuse and to meet its legal duties.
- Your control: Nami asks for your consent before any of your data is sent for AI processing. That consent is recorded against your account and checked again on our own server on every request. You can delete all your data at any time from Profile → Privacy & Data → Delete Account.
The full breakdown is in the AI Processing section below.
Data We Collect
- Email address — used to create and manage your account. Provided either when you sign up with email and password, or returned to us by Apple or Google when you choose Sign in with Apple or Sign in with Google.
- Account identifier — a unique opaque user ID is created for your account. This is the only identifier we use to associate analytics events with your account.
- Bank connection data — if you choose to connect a bank, we receive from that bank, through our open banking provider: the names and types of your accounts, their balances, your cards in masked form (the card's name and its last four digits only), and your transactions — date, description, merchant and amount. We never see or ask for your online banking login details, and we do not store your full card number, account number or sort code. This is fully described in Connecting a Bank (Open Banking) below.
- Bank statement content — when you upload a PDF or CSV bank statement, the content of that file is sent to our AI provider to extract and categorise your transactions. You will be asked for your consent before this occurs.
- Financial transaction data — the transactions synced from a connected bank, and those extracted from your statements, are stored securely in your account.
- Subscription status — if you purchase a subscription, RevenueCat records your purchase and renewal status against the account identifier described above — the opaque ID that carries no name or email but does identify your account — so we can unlock paid features. Apple processes the payment itself; we never see your card details.
- Notification token — if you allow notifications, Apple issues a token that identifies this installation of Nami on your device. We store it against your account so that notifications can be delivered to you. It is deleted when you sign out, and removed along with everything else if you delete your account.
We do not collect your phone number, location, contacts, photo library, or payment card information. If you use shift pay, Nami reads your work calendar on your device to work out what your shifts earned — the events themselves are never uploaded. What is saved to your account is the shift's start and end times, the hours and the pay Nami worked out, and an internal reference to the calendar entry so the same shift is not counted twice. No event title, location, notes or attendee ever leaves your device. If you sign in with Apple or Google, those providers may pass your name and profile picture to the app during the sign-in handshake, but Nami does not retain or transmit your name or profile picture beyond that initial response.
How You Sign In
Nami offers three sign-in methods. You choose which one to use:
- Email and password — handled by Supabase Auth. Your password is never seen by us in plain text; Supabase stores a salted hash.
- Sign in with Apple — Apple authenticates you and returns an identity token plus your email (which may be a private relay address you control) and, on first sign-in only, your name. Nami exchanges the identity token for a Supabase session. Apple's relay address means you can revoke our access at any time from your Apple ID settings without losing access to your account on our side.
- Sign in with Google — Google authenticates you via the official Google Sign-In iOS SDK and returns an identity token, your email address, and your Google account ID. Nami exchanges the identity token for a Supabase session. See the Google Privacy Policy for how Google handles your account.
Whichever method you choose, the only piece of identity data we retain on our backend is your email address and an opaque Supabase user ID.
How We Use Your Data
- To provide the core features of the app (transaction summaries, insights, categorisation).
- To keep a connected bank's accounts, balances and transactions up to date in the app.
- To securely store your transactions so they persist across sessions.
- To generate AI-powered spending insights via our AI provider.
We do not use your data for advertising, profiling, or any purpose beyond app functionality.
Connecting a Bank (Open Banking)
Connecting a bank is optional — Nami works without it, using statements you upload. If you do connect one, the connection is made through TrueLayer, a UK open banking provider authorised and regulated by the Financial Conduct Authority. Here is exactly what happens:
- You authorise it at your own bank. Nami hands you to TrueLayer, which hands you to your bank's own website or app, where you log in and approve the connection. Your banking credentials are entered at your bank and are never seen, handled or stored by Nami.
- What we receive: the names and types of your accounts, their balances, your cards in masked form (the card's name and its last four digits), and your transactions — date, description, merchant name and amount.
- Read-only, and no ability to move money. The access we ask for is account information only. Nami cannot make a payment, move money between accounts, or change anything at your bank — the connection can only read.
- We deliberately do not store the account holder name. Your bank can return the name it holds on file for you; Nami stores that field empty, by design, so it never enters our database.
- How long the connection lasts: around 90 days is the usual ceiling for a UK open banking consent, but it is your bank that sets the actual expiry date on the consent you give it. Nami records whatever date your bank returns and stops syncing when it passes; the connection then shows as needing reconnection in the app. We cannot extend or renew it ourselves — only re-authorising at your bank does that, from Profile → Connected banks → Reconnect.
- Where the keys to the connection live: the access and refresh tokens issued for your connection are held on our server, in a table that no app user and no client can read — only our backend service itself can. They are never sent to your device and never shared with anyone else.
- How to disconnect: Profile → Connected banks → Disconnect. That removes the whole connection from Nami — its accounts and balances, and the stored access and refresh tokens, so nothing further can be fetched from your bank. Transactions already synced stay in your account; deleting your account removes those along with everything else. Disconnecting in Nami does not cancel the consent at your bank's end: your bank keeps its own record of who you have shared with, and you can withdraw it there too.
For how TrueLayer handles the data it passes between your bank and Nami, see the TrueLayer privacy notice.
Third-Party AI Processing
Nami sends transaction data to a third-party AI service to categorise it and to generate the spending insights and category breakdowns you see in the app. This applies to both routes your transactions can take into Nami — a connected bank and an uploaded statement. Here is exactly what happens:
- What is sent from a connected bank: only the transactions our own rules could not categorise on their own, and for each one only five fields — an opaque row reference, the direction ("debit" or "credit"), the amount in pence, the description text, and the merchant name. No name, no email address, no user identifier and no account number ever travels with it.
- What is sent from a statement you upload: the content of that file (PDF or CSV) — including transaction dates, merchant names, amounts, and any surrounding statement text — so the transactions can be read out of it. Your account's name and email address are never added to a request. A statement, though, is sent as it is, so anything printed on it, such as your name or an account number, goes with it.
- What is sent when you ask Nami a question through the in-app assistant ("Ask Nami"): your question, the last few messages in that chat, and the figures, merchant names and date range of the window Home is showing, together with your currency, your monthly budget, your category limits and your category names. When you ask about what you own or owe: your net wealth, your account names and what each one holds, and any repayment plan on them with the date it clears. When you ask about your pay: your employer's name, your pay dates, what you have earned and what your payslips came to, and the start and end times of the shifts read from your calendar (the titles of your calendar events are never sent), along with the name and kind of each income source you have added, whether that is an employer, a source Nami found in your bank transactions or one you entered yourself, how each one is doing, what it is expected to pay you next and what each has paid you this month. A source Nami found in your bank transactions is named after the counterparty on the transaction, which is usually a business.
- How it is sent: through our own secure server. Your device never communicates with the AI provider directly, and the API key stays on our server.
- Purpose: To extract transaction descriptions, amounts, dates and categories, and to generate the personalised spending insights, category summaries and assistant answers Nami shows you.
- Your consent: Nami asks for your consent before any of your data is sent for AI processing, and you must agree before anything is sent. Your agreement is recorded against your account on our server and re-checked there on every single request — for transactions from a connected bank as well as for statements — so no processing can happen without it. The disclosure you agree to describes the statement upload, and you can read it again at any time from Profile → Privacy & Data → AI processing.
- Your right to delete: You can delete every transaction Nami holds, along with your account, at any time from Profile → Privacy & Data → Delete Account. Deletion is permanent and removes your data from our servers.
The AI provider Nami currently uses is Anthropic, PBC, via the Claude API. Anthropic does not use data sent through its API to train its models, and keeps it only for a short period, to check for misuse and to meet its legal duties; we retain the resulting transaction records in your account so they appear when you reopen the app. Anthropic's data processing provides equivalent privacy protections as required by applicable laws. For more information, see the Anthropic Privacy Policy.
Other Third-Party Services
- TrueLayer — the FCA-authorised UK open banking provider that carries the connection between your bank and Nami, if you choose to connect one. It is read-only account information access, described in full in Connecting a Bank (Open Banking) above. TrueLayer Privacy Notice
- Supabase — secure cloud database and authentication. Your data is stored in Supabase and protected by Row Level Security, meaning only you can access your own data. Supabase Privacy Policy
- Apple — Sign in with Apple — used only when you choose this sign-in method. Apple returns an identity token (and on first sign-in, your name and email) which we exchange for a Supabase session. Apple Privacy Policy
- Google Sign-In — used only when you choose to Sign in with Google. Google's iOS SDK handles the OAuth flow and returns an identity token, your email, and your Google account ID, which we exchange for a Supabase session. This is a separate, sign-in-only service and is unrelated to the AI processing described above. Google Privacy Policy
- RevenueCat — used to manage in-app subscription purchases. RevenueCat receives your opaque Supabase account ID — pseudonymous rather than anonymous: it carries no name and no email, but it does identify your account — along with your purchase events from Apple's StoreKit. It does not see your name, email, or transaction data. RevenueCat Privacy Policy
- Merchant logos — the small marks beside shop names. Nami ships a built-in list of UK merchants and their websites, and matches your transactions against it on your device. When a shop is not on that list, the app sends the shop name, and only the shop name, to Nami's own server, which works out the shop's website and fetches its public icon from the site itself or from a public icon service (Google's or DuckDuckGo's), then keeps the icon so it is fetched once for everyone. Your device never contacts those services, and the request that reaches them carries no account, no amount and no user identifier. A shop's website, once found, is stored without any link to you.
- PostHog — used for product analytics (app opens, feature usage, sign-in method). Events are tagged with your opaque Supabase account ID only. That ID is pseudonymous rather than anonymous — it carries no name and no email, but it does identify your account. PostHog never receives your email, your name, or any financial data. PostHog Privacy Policy
Data Storage & Security
Your data is stored in Supabase (EU region) with Row Level Security enforced — meaning no other user can access your data. All data is transmitted over HTTPS. The AI provider's API key is stored server-side and never included in the app binary. The tokens behind a bank connection are held in a separate table that no client can read at all — only our backend service itself can.
Data Retention & Deletion
Your data is retained for as long as you have an account. You can delete your account at any time from the Profile tab inside the app. Deleting your account permanently removes all your data from our servers — including your transactions, any connected bank and the access tokens behind it — and cannot be undone.
Your Rights
You have the right to:
- Access the data we hold about you.
- Delete your account and all associated data at any time, directly in the app.
- Disconnect a bank at any time from Profile → Connected banks, and withdraw the consent itself at your bank.
- Stop AI processing by disconnecting your bank and not uploading statements, or by contacting us.
- Contact us with any privacy-related questions.
Children's Privacy
Nami is not directed at children under 13. We do not knowingly collect data from children.
Changes to This Policy
We may update this policy from time to time. Any changes will be reflected on this page with an updated date. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
If you have any questions about this privacy policy, please contact us at:
contact@meliolabs.io