Privacy
Privacy Policy
How OnNest collects, uses, stores, protects and shares your information — in plain language. Version 1.2, effective September 8, 2026.
Version 1.2 · Effective September 8, 2026 · Questions: support@getonnest.com
1. Introduction
OnNest is a financial wellness, education, planning and decision-support service. It helps you understand your relationship with money, see where you stand today, set goals, and think through decisions before you make them.
This Privacy Policy describes how OnNest collects, uses, stores, protects and shares personal information, and the choices you have over it. It is written in plain language on purpose.
OnNest is not a bank, lender, credit bureau, payment processor, insurer or registered investment adviser, and does not provide legal or tax advice. OnNest does not guarantee financial outcomes. OnNest makes no claim to any security certification: it is not SOC 2, ISO 27001 or PCI DSS certified, and has not undergone an independent security audit or third-party penetration test.
2. Information you provide directly
Everything in this section is information you choose to enter:
- Account information — your email address, and your name if you give one.
- Authentication information, handled through the managed authentication service OnNest uses. OnNest does not store your password itself.
- Money Relationship questionnaire responses.
- Household information you choose to enter.
- Income, living expenses, debt information including balances and payments, and savings information.
- Financial goals and goal-related details, including milestones.
- Financial planning inputs, What If? scenario information, Decision Check information, and Build My Path plans and progress.
- Anything else you voluntarily enter, including messages you send to support.
OnNest does not ask for or collect Social Security numbers, and OnNest does not perform credit pulls or obtain credit reports.
3. Connected financial information
Connecting a financial institution is optional. OnNest works fully on figures you enter yourself.
OnNest is designed to use Plaid, a financial-data provider, to let you connect supported financial accounts. Connected financial functionality is not currently live. OnNest has not been activated for Plaid production access, and no member financial institution is connected today.
When connected financial-data functionality is made available:
- You choose the institution and authorise the connection yourself.
- You sign in with your institution through Plaid. OnNest does not receive or store your online banking username or password.
- OnNest may receive the financial information made available through that connection — which may include account information, account balances, transaction information, recurring transaction information and liability information — depending on what you authorise.
- Plaid handles the information it processes under its own privacy policy in addition to this one.
4. How OnNest uses information
- Providing the OnNest service you asked for and displaying your financial picture.
- Supporting financial education, tracking goals and showing progress over time.
- Identifying information that may need your review.
- Supporting member-directed financial planning.
- Providing deterministic personalised guidance — personalisation changes wording and emphasis, never the arithmetic.
- Maintaining security, preventing fraud, abuse and misuse.
- Troubleshooting problems and responding to support requests.
- Complying with applicable legal obligations.
OnNest does not make lending, credit, insurance or investment decisions about you, and does not use your information to do so.
5. OnNest's connected-data philosophy
OnNest owns the financial model. Providers supply source data.
- Provider-derived information enters OnNest as observations, stored separately and labelled as coming from your institution.
- Connected information never silently overwrites the Financial Reality figures you entered yourself.
- Where a connected observation appears to match something you entered, OnNest asks you. You decide whether it becomes part of your authoritative financial picture.
- Correcting a figure keeps its origin recorded, so an observation stays an observation.
6. How information is protected
- HTTPS/TLS for information in transit.
- Encryption-at-rest protections provided by the managed infrastructure OnNest runs on.
- Authenticated application routes for all member areas.
- Database row-level security and member-level data isolation, so your records are reachable only by your signed-in account.
- Privileged operations performed only in server-side code.
- Protected provider credentials; provider access tokens are stored so they are inaccessible to browsers and member sessions.
- Multi-factor authentication on administrative accounts where supported.
- Security-event logging for security-relevant account activity, recorded without passwords, banking credentials or provider tokens.
- Vulnerability and security scanning, plus automated security regression tests.
OnNest does not currently implement application-level field encryption beyond the protections described above. No security system can guarantee absolute security, and OnNest does not claim that it can. Read more on the Security & Data Protection page.
7. How information is shared
OnNest does not sell consumers' personal financial information. OnNest does not use advertising networks, advertising pixels or behavioural-advertising providers, and does not share information with them.
Information is shared only with service providers necessary to operate OnNest:
| Category | Purpose |
|---|---|
| Hosting and application platform | Running and deploying the OnNest application |
| Managed database, authentication and storage infrastructure | Storing member data and signing members in |
| Email delivery | Account and authentication messages, and the newsletter if you subscribed |
| Plaid | Financial institution connectivity, when connected financial functionality is used |
Providers receive only what their function requires. Information may also be disclosed where required by law or where necessary to protect the rights, safety or security of OnNest or its members.
8. Financial institution connections
- Connecting an institution is optional.
- A connection is created only with your authorisation.
- You can disconnect a connected institution at any time. Disconnecting revokes provider access so nothing new is gathered.
- Disconnecting is a separate action from deletion. Information already gathered remains until it is deleted, subject to the retention targets below.
- Deleting connected financial data removes provider-derived accounts, observations and reconciliation records. It does not delete the Financial Reality information you entered yourself.
9. Google Calendar sync
Putting OnNest Payment Calendar obligations on your Google Calendar is optional. If you choose to connect Google Calendar:
- You sign in to Google and authorise the connection yourself.
- OnNest asks only for the Google Calendar permissions needed to create and manage calendar events and read your calendar list so you can pick which calendar to use.
- OnNest creates all-day events containing only the obligation name and due date; amounts, balances and other financial details are not included in the event.
- OnNest stores a server-side credential handle, not your Google password, and that handle is encrypted and unreachable from the browser or other members' sessions.
- OnNest is always the authoritative source: information flows one way, from OnNest to Google Calendar. OnNest does not read your calendar entries.
- You can disconnect Google Calendar at any time and choose what happens to the events OnNest created: leave them on your calendar, or have OnNest remove them first. Either way, OnNest's access is revoked and your OnNest information is unchanged.
- If OnNest cannot remove an event you asked it to remove, it keeps a minimal private record so it can finish the removal, and deletes that record once the cleanup succeeds.
- Deleting your OnNest account first attempts to remove the future calendar events OnNest created, then disconnects Google Calendar and deletes the synced event records. Deletion completes even if Google is unavailable.
10. Data retention
Retention follows the OnNest Data Retention and Disposal Policy.
| Category | Retention |
|---|---|
| Active member data (profile, Money Relationship answers, Financial Reality, goals, plans, scenarios, decision checks) | Retained while the account remains active and as needed to provide the requested service |
| Provider-derived connected data — you request deletion | Deleted promptly through the connected-data deletion workflow |
| Provider-derived connected data — connection disconnected, no deletion requested | Target deletion 90 days after disconnection, unless you ask to keep it or continued retention is required for a legitimate legal or security purpose |
| Google Calendar synced event records | Deleted when Google Calendar is disconnected or when the account is deleted |
| Security / activity events | 12 months, unless needed longer for an active security investigation or a legitimate legal requirement |
| Financial-data consent records after revocation | 24 months as evidence of consent and its revocation, unless a different period is legally required |
| Newsletter unsubscribe | Only the minimum suppression information needed to honour the unsubscribe |
| Deleted accounts | Member and financial content deleted through the deletion workflow; only a minimal de-identified record documenting completion is retained |
On-demand deletion runs immediately at your request. The time-based targets above are carried out as an operator task at periodic review; OnNest does not currently run an automated scheduled deletion job.
11. Consumer privacy and data rights
| Right | How OnNest provides it |
|---|---|
| Access | Download a machine-readable copy of the information OnNest holds for your account |
| Correction | Update any information you entered yourself, at any time |
| Revocation | Disconnect a connected financial institution or disconnect Google Calendar |
| Connected-data deletion | Delete provider-derived connected financial information without deleting the Financial Reality information you entered |
| Account deletion | Permanently close and delete your OnNest account, which requires typing an exact confirmation phrase |
All of these actions require you to be signed in; there is no unauthenticated deletion or export route. For requests made outside the application, OnNest may need to verify your identity before acting, so that no one else can obtain or destroy your information. See Privacy Choices & Data Rights for how each one works.
12. Newsletter and communications
Account and operational messages — such as email verification, password resets and security notices — are part of the service and are sent to members as needed.
The OnNest Conversation newsletter is separate and entirely optional. Signup is confirmation-based: entering your email address submits a request, and the subscription is only active once it is confirmed. You can unsubscribe at any time using the link in any newsletter email, and OnNest then keeps only the minimum suppression information needed to honour that choice. OnNest does not build a marketing profile about you.
13. Cookies and similar technologies
OnNest uses only the storage and cookie technologies needed to run the service — principally keeping you signed in and maintaining your session. OnNest does not use advertising pixels, behavioural-advertising technology, cross-site trackers or third-party analytics profiling.
14. Children's privacy
OnNest is intended for adults. As stated in the Terms of Use, you must be at least 18 years old to use OnNest. OnNest does not knowingly collect information from children. If OnNest learns that it holds information from someone under 18, that information will be deleted.
15. Changes to this Privacy Policy
OnNest may update this Privacy Policy. The version number and effective date at the top of this page identify the current version. Where a change materially affects how member information is used, OnNest will make that clear on this page.
16. Contact
Email: support@getonnest.com. Website: GetOnNest.com.
OnNest is a small, independent service. This policy describes what OnNest actually does today, and clearly marks connected financial functionality that becomes available once it is enabled.
