Security & Data Practices
Your financial data is for you.
Policies last reviewed: June 2026
This page brings together our information-security, access-control, and data-retention commitments in plain language.
No login credentials
We never see your bank login information - this is handled entirely by Plaid.
Encrypted
Connections use TLS, and institution tokens receive an additional encryption layer at rest.
In your control
Disconnect an institution or permanently delete your account whenever you choose.
1. What we collect - and what we do not
To provide the product, Navis stores the account details, balances, holdings, transactions, and optional profile information you choose to provide. We use Plaid for connected institutions and request its read-only Transactions and Investments products.
You sign in to your financial institution directly in Plaid Link. Navis never receives or stores your bank login credentials, full account or card numbers, Social Security numbers, or government IDs. We do not sell financial information or use it for advertising.
2. How we protect your information
- All connections between your browser, Navis, and its service providers use TLS.
- Database storage is encrypted at rest by our managed database provider. Financial institution access tokens are also encrypted by Navis with AES-256-GCM before storage.
- Access tokens are decrypted only in memory when needed for a provider call; they are never sent to your browser or included in application logs.
- We use managed hosting and database platforms, review dependencies regularly, and patch identified vulnerabilities according to risk.
3. Who can access data
Each customer can access only their own Navis data. User-owned data is isolated with database roles and Row-Level Security, and normal application requests run with the signed-in user’s identity.
Production administration is limited to the Navis operator and is protected with strong authentication. Automated jobs use separate, scoped credentials and a dedicated non-root system account. We do not use shared administrative accounts, and access, integrations, and credentials are reviewed at least annually and revoked promptly when no longer needed.
4. Retention and deletion
| Data | How long we keep it | What happens on deletion |
|---|---|---|
| Institution tokens | For the active connection | Revoked with the provider and deleted when you disconnect. |
| Accounts, holdings & transactions | For the active account or connection | Removed with the connection or your account. |
| Account & profile | For the life of your account | Removed when you delete your account. |
| Database backups | About 14 days on a rolling basis | Ages out through backup rotation; backups are not used to restore individually deleted data. |
You can disconnect an institution at any time from Accounts. You can permanently delete your account and associated data from Settings → Delete account, or email us at privacy@usenavis.com. Deletion requests are handled promptly, subject to any applicable legal obligations.
5. AI advisor
If you use the optional NavisAi advisor, it receives only the financial data necessary to answer your question. It does not receive any personal identifying information nor does it receive bank credentials, access tokens, account numbers, or personal identifiers - because we never have access to that data.
6. Security incidents and ongoing review
If we suspect a security incident, we investigate its scope, revoke affected financial connections when appropriate, rotate implicated credentials, and notify affected users and relevant partners without undue delay. We review these practices at least annually and when our systems or data flows materially change.
Navis does not currently hold formal certifications such as SOC 2 or ISO 27001. We publish these practices so you can evaluate the protections we have in place today.
For details on collection, sharing, and your privacy rights, read our Privacy Policy. Questions about privacy or security can be sent to privacy@usenavis.com.