Skip to content
Pane

Data Retention & Disposal Policy

Last updated: September 22, 2026

Introduction

This policy describes how Pane, operated by Real Design, Inc. ("Company," "we," "us," or "our"), retains, manages, and disposes of user data. Pane is a hosted MCP server connecting financial data to AI tools at pane.money. Our data retention practices are designed to balance service functionality with your privacy.

Live deletion follows the cleanup steps below. It does not erase provider-held history, recovery copies, or every temporary counter immediately. Account deletion is support-assisted.

Data Categories and Retention Periods

User Account Data

  • Email, name, profile image
  • Account creation and update timestamps

Retention: Duration of active account

On deletion: Removed from the live database after support completes external cleanup

Authentication Data

OAuth provider tokens (Google and Apple)

Access tokens, refresh tokens, ID tokens. Retained while account is active. Deleted on account deletion.

Session tokens

Web sessions expire after the configured 30-day maximum; mobile and CLI bearer sessions after 90 days unless revoked earlier. Durable session metadata includes initial/latest IP address and user agent. Expired rows are not automatically erased; user-owned rows cascade on account deletion.

Magic link verification tokens

Expire after use or after their set expiration timestamp. Short-lived by design.

WebAuthn/passkey credentials

Retained while account is active. Deleted on account deletion via cascading delete.

Financial Data (Plaid)

Plaid access tokens

Encrypted (AES-256-GCM) and retained while the institution link is active. Provider revocation or a recognized already-removed item must be confirmed before the token and local source are deleted. Failure retains them for retry.

Financial accounts

Names, types, balances. Retained while associated Plaid item is linked. Deleted from the live database on successful unlink or account deletion.

Transactions

Synced via cursor-based approach, up to 730 days of history from Plaid. Retained while associated account is linked. Deleted from the live database on successful unlink or account deletion.

Recurring transactions

Retained while associated account is linked. Deleted from the live database on successful unlink or account deletion.

Investment holdings

This feature is deferred. Historical cache values, if any, expire after one hour; the current export does not fetch or include provider holdings.

Liability details

This feature is deferred. Historical cache values, if any, expire after one hour; the current export does not fetch or include provider details.

Stored balances

Account balances are stored in PostgreSQL. Net Worth reads those values without a provider refresh; there is no plan-specific balance freshness guarantee.

Transaction sync cursor

Retained with the Plaid item. Deleted on unlink.

Billing Data (Stripe)

  • Stripe customer ID and subscription ID
  • Subscription status and plan
  • Payment details (card numbers, billing address) are NOT stored by Pane. Managed entirely by Stripe.

Retention: Local Stripe identifiers remain until support verifies customer ownership, expires open checkout sessions, cancels subscriptions, and removes the customer. Failures retain identifiers for retry.

API Keys (MCP)

  • API key hashes (bcrypt)
  • Key usage metadata (lastUsedAt)
  • Creation and revocation timestamps

Retention: Until revoked by you or account is deleted. Revoked keys remain in database with revokedAt timestamp (soft delete) for audit purposes. Hard-deleted on account deletion.

Customer Support Data (Crisp, Optional)

Crisp is retired and is not mounted. Historical provider-held transcripts or browser state are not erased by that change.

Analytics Data (PostHog, Optional)

With consent, minimized analytics events are sent to PostHog and subject to its retention. Remote feature-flag evaluation is retired. Withdrawing consent stops new authorized collection; it does not itself erase historical provider data.

Error Tracking Data (Sentry, Optional)

When enabled, bounded error metadata and sanitized stack-frame identifiers are sent to Sentry. Request bodies, URLs, user identity, and free-text errors are removed from the standard event body. Tracing and Replay are disabled. Provider retention and network metadata are separate from these controls.

Application Logs

Structured logs use configured redaction for known credential, financial, and request fields. They can retain pseudonymous identifiers and unrecognized detail fields. Hosting-provider retention is separate from account deletion; this policy does not promise a fixed log-purge interval.

Temporary Data & Caching

Selected caches and counters have the expiry periods below. Support deletion clears its supported financial/profile caches and export marker, not every Redis key.

Data TypeTTLStorage
Historical investment/liability caches1 hourEncrypted Redis values; features deferred
MCP authoritative sessions30-minute idle timeoutProcess memory, checked every 5 minutes
MCP cross-instance metadata1 hour, refreshed on activityRedis
MCP transport replay5 minutesRedis
Rate-limit and quota counters1 minute to 25 hours, depending on the operationRedis
Settings export marker1 hour after successful exportRedis

Cache is explicitly invalidated when Plaid webhooks indicate data has changed. MCP idle sessions are cleaned every 5 minutes with a 30-minute inactivity threshold.

Data Disposal Procedures

When You Unlink a Financial Institution

  1. Pane verifies the exact owner and linked Plaid item.
  2. Plaid revocation must succeed or identify an already-removed item.
  3. The linked source, accounts, transactions, stored recurring records, and related annotations are removed from the live database; relevant caches are cleared.

A failed provider request leaves local records available for retry. Successful live deletion cannot be undone through the product; provider history and recovery copies are separate.

When You Request Account Deletion

Contact support@pane.money or use the request link in Settings. Support verifies the account and request. The operator workflow checks Apple subscriptions, bans the account and revokes credentials, completes Plaid revocation, removes owned upload and avatar objects, cleans up Stripe subscriptions/customer and supported caches, then deletes the user row last.

If cleanup fails, the account stays banned and local references remain for support to retry; deletion is not reported complete. Active Apple subscriptions must first be canceled through the App Store and become inactive. Pane does not cancel or refund Apple subscriptions.

The user deletion cascades owned accounts, transactions, annotations, API keys, sessions, consent and audit records, AI-usage rows, CLI links, OAuth grants, receipts, and legacy webhook and wallet data. It does not guarantee immediate erasure of provider-held records, public OAuth client registrations, all Redis counters, or recovery copies.

When a Subscription Is Canceled

Subscription access follows the effective subscription status. Data is not automatically deleted after cancellation. The automatic canceled-account purge is retired; there is no 30-day purge promise. Contact support for deletion.

Historical Data and Retired Features

Statement imports, new file uploads, wallet/crypto features, new FinanceKit linking, and new outbound webhook delivery are retired. Previously stored rows and upload objects can remain until support deletion. Owned uploads and avatars are removed from configured storage before deleting their user. Objects outside the supported user namespace are not claimed erased.

Session, consent, CLI, and AI-usage records have no separate age-based purge in the application. Consent records retain the version originally recorded; this content update is not a new consent grant. The mobile app is unreleased.

Encryption at Rest

  • Plaid access tokens: AES-256-GCM with unique IV and auth tag per token
  • API keys: Bcrypt hashed (cost factor 13). Plaintext never stored.
  • Session tokens: JWE encrypted (AES-256-CBC-HS512) with HKDF-derived key from AUTH_SECRET
  • Production uses managed PostgreSQL. Recovery storage and retention follow the hosted provider configuration.

Encryption Key Management

  • ENCRYPTION_MASTER_KEY: 32-byte hex key for AES-256-GCM. Stored in environment variable. Rotation requires re-encryption of all Plaid tokens.
  • AUTH_SECRET: Minimum 32-character secret for JWE. Stored in environment variable. Pinned to Auth.js version.
  • Keys are never logged, committed to version control, or exposed in error messages.

Database Backups

Managed Render recovery history and separately created exports can contain records already removed from the live database. They do not follow immediate per-user deletion. Retention depends on the hosted plan and provider configuration; this policy does not promise a universal seven-day expiry or a repository-managed daily backup.

Your Rights Regarding Data Retention

  • Unlink Plaid institutions; local deletion follows confirmed provider revocation
  • Revoke individual API keys at any time (immediate invalidation)
  • Request support-assisted deletion at support@pane.money, subject to the cleanup and recovery limitations above
  • Adjust per-account privacy scopes, including institution bulk edits, to control supported AI access
  • Download the bounded Settings JSON export once per hour. It contains supported database fields, not every retained record, uploaded file, or provider payload; it is not one atomic snapshot.
  • Contact privacy@pane.money for comprehensive access or retention inquiries

Compliance and Review

This policy is reviewed and updated as data practices change. Material changes will be communicated through the Service or via email at least 14 days before they take effect. Changes are posted at this URL with an updated "Last updated" date.

Contact

Real Design, Inc.

Email: privacy@pane.money

See also: Privacy Policy | Terms of Service