Data Retention & Disposal Policy
Last updated: September 22, 2026
Introduction
This policy describes how Pane, operated by Real Design, Inc. ("Company," "we," "us," or "our"), retains, manages, and disposes of user data. Pane is a hosted MCP server connecting financial data to AI tools at pane.money. Our data retention practices are designed to balance service functionality with your privacy.
Live deletion follows the cleanup steps below. It does not erase provider-held history, recovery copies, or every temporary counter immediately. Account deletion is support-assisted.
Data Categories and Retention Periods
User Account Data
- Email, name, profile image
- Account creation and update timestamps
Retention: Duration of active account
On deletion: Removed from the live database after support completes external cleanup
Authentication Data
OAuth provider tokens (Google and Apple)
Access tokens, refresh tokens, ID tokens. Retained while account is active. Deleted on account deletion.
Session tokens
Web sessions expire after the configured 30-day maximum; mobile and CLI bearer sessions after 90 days unless revoked earlier. Durable session metadata includes initial/latest IP address and user agent. Expired rows are not automatically erased; user-owned rows cascade on account deletion.
Magic link verification tokens
Expire after use or after their set expiration timestamp. Short-lived by design.
WebAuthn/passkey credentials
Retained while account is active. Deleted on account deletion via cascading delete.
Financial Data (Plaid)
Plaid access tokens
Encrypted (AES-256-GCM) and retained while the institution link is active. Provider revocation or a recognized already-removed item must be confirmed before the token and local source are deleted. Failure retains them for retry.
Financial accounts
Names, types, balances. Retained while associated Plaid item is linked. Deleted from the live database on successful unlink or account deletion.
Transactions
Synced via cursor-based approach, up to 730 days of history from Plaid. Retained while associated account is linked. Deleted from the live database on successful unlink or account deletion.
Recurring transactions
Retained while associated account is linked. Deleted from the live database on successful unlink or account deletion.
Investment holdings
This feature is deferred. Historical cache values, if any, expire after one hour; the current export does not fetch or include provider holdings.
Liability details
This feature is deferred. Historical cache values, if any, expire after one hour; the current export does not fetch or include provider details.
Stored balances
Account balances are stored in PostgreSQL. Net Worth reads those values without a provider refresh; there is no plan-specific balance freshness guarantee.
Transaction sync cursor
Retained with the Plaid item. Deleted on unlink.
Billing Data (Stripe)
- Stripe customer ID and subscription ID
- Subscription status and plan
- Payment details (card numbers, billing address) are NOT stored by Pane. Managed entirely by Stripe.
Retention: Local Stripe identifiers remain until support verifies customer ownership, expires open checkout sessions, cancels subscriptions, and removes the customer. Failures retain identifiers for retry.
API Keys (MCP)
- API key hashes (bcrypt)
- Key usage metadata (lastUsedAt)
- Creation and revocation timestamps
Retention: Until revoked by you or account is deleted. Revoked keys remain in database with revokedAt timestamp (soft delete) for audit purposes. Hard-deleted on account deletion.
Customer Support Data (Crisp, Optional)
Crisp is retired and is not mounted. Historical provider-held transcripts or browser state are not erased by that change.
Analytics Data (PostHog, Optional)
With consent, minimized analytics events are sent to PostHog and subject to its retention. Remote feature-flag evaluation is retired. Withdrawing consent stops new authorized collection; it does not itself erase historical provider data.
Error Tracking Data (Sentry, Optional)
When enabled, bounded error metadata and sanitized stack-frame identifiers are sent to Sentry. Request bodies, URLs, user identity, and free-text errors are removed from the standard event body. Tracing and Replay are disabled. Provider retention and network metadata are separate from these controls.
Application Logs
Structured logs use configured redaction for known credential, financial, and request fields. They can retain pseudonymous identifiers and unrecognized detail fields. Hosting-provider retention is separate from account deletion; this policy does not promise a fixed log-purge interval.
Temporary Data & Caching
Selected caches and counters have the expiry periods below. Support deletion clears its supported financial/profile caches and export marker, not every Redis key.
| Data Type | TTL | Storage |
|---|---|---|
| Historical investment/liability caches | 1 hour | Encrypted Redis values; features deferred |
| MCP authoritative sessions | 30-minute idle timeout | Process memory, checked every 5 minutes |
| MCP cross-instance metadata | 1 hour, refreshed on activity | Redis |
| MCP transport replay | 5 minutes | Redis |
| Rate-limit and quota counters | 1 minute to 25 hours, depending on the operation | Redis |
| Settings export marker | 1 hour after successful export | Redis |
Cache is explicitly invalidated when Plaid webhooks indicate data has changed. MCP idle sessions are cleaned every 5 minutes with a 30-minute inactivity threshold.
Data Disposal Procedures
When You Unlink a Financial Institution
- Pane verifies the exact owner and linked Plaid item.
- Plaid revocation must succeed or identify an already-removed item.
- The linked source, accounts, transactions, stored recurring records, and related annotations are removed from the live database; relevant caches are cleared.
A failed provider request leaves local records available for retry. Successful live deletion cannot be undone through the product; provider history and recovery copies are separate.
When You Request Account Deletion
Contact support@pane.money or use the request link in Settings. Support verifies the account and request. The operator workflow checks Apple subscriptions, bans the account and revokes credentials, completes Plaid revocation, removes owned upload and avatar objects, cleans up Stripe subscriptions/customer and supported caches, then deletes the user row last.
If cleanup fails, the account stays banned and local references remain for support to retry; deletion is not reported complete. Active Apple subscriptions must first be canceled through the App Store and become inactive. Pane does not cancel or refund Apple subscriptions.
The user deletion cascades owned accounts, transactions, annotations, API keys, sessions, consent and audit records, AI-usage rows, CLI links, OAuth grants, receipts, and legacy webhook and wallet data. It does not guarantee immediate erasure of provider-held records, public OAuth client registrations, all Redis counters, or recovery copies.
When a Subscription Is Canceled
Subscription access follows the effective subscription status. Data is not automatically deleted after cancellation. The automatic canceled-account purge is retired; there is no 30-day purge promise. Contact support for deletion.
Historical Data and Retired Features
Statement imports, new file uploads, wallet/crypto features, new FinanceKit linking, and new outbound webhook delivery are retired. Previously stored rows and upload objects can remain until support deletion. Owned uploads and avatars are removed from configured storage before deleting their user. Objects outside the supported user namespace are not claimed erased.
Session, consent, CLI, and AI-usage records have no separate age-based purge in the application. Consent records retain the version originally recorded; this content update is not a new consent grant. The mobile app is unreleased.
Encryption at Rest
- Plaid access tokens: AES-256-GCM with unique IV and auth tag per token
- API keys: Bcrypt hashed (cost factor 13). Plaintext never stored.
- Session tokens: JWE encrypted (AES-256-CBC-HS512) with HKDF-derived key from AUTH_SECRET
- Production uses managed PostgreSQL. Recovery storage and retention follow the hosted provider configuration.
Encryption Key Management
- ENCRYPTION_MASTER_KEY: 32-byte hex key for AES-256-GCM. Stored in environment variable. Rotation requires re-encryption of all Plaid tokens.
- AUTH_SECRET: Minimum 32-character secret for JWE. Stored in environment variable. Pinned to Auth.js version.
- Keys are never logged, committed to version control, or exposed in error messages.
Database Backups
Managed Render recovery history and separately created exports can contain records already removed from the live database. They do not follow immediate per-user deletion. Retention depends on the hosted plan and provider configuration; this policy does not promise a universal seven-day expiry or a repository-managed daily backup.
Your Rights Regarding Data Retention
- Unlink Plaid institutions; local deletion follows confirmed provider revocation
- Revoke individual API keys at any time (immediate invalidation)
- Request support-assisted deletion at support@pane.money, subject to the cleanup and recovery limitations above
- Adjust per-account privacy scopes, including institution bulk edits, to control supported AI access
- Download the bounded Settings JSON export once per hour. It contains supported database fields, not every retained record, uploaded file, or provider payload; it is not one atomic snapshot.
- Contact privacy@pane.money for comprehensive access or retention inquiries
Compliance and Review
This policy is reviewed and updated as data practices change. Material changes will be communicated through the Service or via email at least 14 days before they take effect. Changes are posted at this URL with an updated "Last updated" date.
Contact
Real Design, Inc.
Email: privacy@pane.money
See also: Privacy Policy | Terms of Service