Privacy and your data
Last Updated:
Ansel is a conversational personal assistant operated by Josh Menden. This policy describes the current private beta: an iMessage assistant connected to one YNAB budget per household. For privacy questions or requests, email [email protected]. Please do not email passwords, access tokens, or bank credentials.
What we collect and why
We use your iMessage address, messages, receipt images, conversation participants, household membership, preferences, and message delivery information to identify you, control access, understand requests, and respond. Ansel may infer personal preferences from conversations; shared budget preferences require an explicit request. We record actions and their results to explain changes, prevent duplicates, and support undo where available. We also record AI usage and estimated costs to report operating costs and diagnose failures.
With your authorization through YNAB, we receive OAuth access and refresh tokens and a list of budget names and IDs so you can select a budget. Ansel can then read that budget’s accounts, balances, categories, payees, transactions, scheduled transactions, targets, and other relevant budget details, and make supported changes in response to your requests. YNAB’s grant can cover more than one budget; Ansel restricts its budget tools to the budget you select. We do not request your YNAB password or bank login credentials.
YNAB data is used only to provide these disclosed features. We do not sell it, use it for advertising, or use it to train our own AI models. Authorizing YNAB does not automatically authorize connections to other services.
Who receives data
We will not pass your YNAB data to third parties without your knowledge. The services currently involved are:
- YNAB: receives authenticated requests to read or change your budget.
- OpenAI: processes relevant conversation history, receipt images, preferences, and budget data to interpret requests and generate responses. Account connection tokens are not sent to the AI model. We disable optional storage of AI responses with this provider; service and abuse-monitoring retention may still apply. This is not a promise of zero retention.
- Apple: carries iMessages. Our server-side messaging bridge processes incoming and outgoing messages and can retain separate copies of messages and attachments.
- Cloudflare: handles website traffic, including enrollment and export requests. It can process request content and connection information.
- Google: handles email sent to our Gmail support address. Do not send sensitive budget details unless needed for your request.
The operator may access stored data to run the beta, investigate problems, or fulfill support and deletion requests. These providers also handle data under their own applicable policies.
Households and group conversations
Inviting someone gives them access to the selected budget through Ansel. Only invite people you intend to authorize. Everyone currently in a budget group must have active household access before Ansel discusses the budget. Leaving a conversation does not itself revoke household membership; the household owner can revoke access through Ansel.
Private transcripts and personal preferences are excluded from group context. Household members can ask for aggregate AI costs, including usage from private conversations, without seeing those conversations or a breakdown by person. Group participants can retain or copy information they receive.
Storage, security, and retention
We store data on operator-controlled infrastructure, including messages, preferences, selected budget identifiers, consent and membership records, action history (including budget data needed to record changes), and usage records. Account connection tokens, message bodies, preferences, action details, and temporary export payloads are encrypted in application storage. Attachment files and some metadata, such as addresses, identifiers, budget names, and timestamps, are not covered by that application encryption. Encryption does not prevent authorized operator access or guarantee protection if the server is compromised.
Public website connections and remote API calls use HTTPS. Session cookies support enrollment and verification. Operational logs can contain request metadata and errors. No system can guarantee complete security.
Messages, images, preferences, action history, membership metadata, and AI usage are retained until deletion is requested. YNAB read results may also be retained when included in messages or action history. Connection tokens are kept until disconnection or deletion. Temporary enrollment links expire after one hour; unfinished enrollment credentials are cleared by maintenance after expiry. Export links expire after 20 minutes or one download, and their stored payloads are cleared on use or by maintenance after expiry. Processed webhook records are removed by maintenance after seven days; pending records can remain until resolved.
There is no enabled backup service in this beta. Operational logs and separate server-side messaging copies currently have no automatic retention limit; include them in a deletion request to the operator. We will publish backup retention and deletion procedures before enabling backups.
Your choices, export, and deletion
Text export directly to Ansel for a one-use download of your retained messages, images, personal preferences, action records, and AI usage. Keep the link private. Text delete my data for a confirmation code. Confirming removes your stored content and messaging identity, revokes membership, disconnects budgets you authorized, and removes preferences derived from your deleted messages. Some record links, IDs, timestamps, and status information remain to preserve the integrity of shared history. Other members’ records are not automatically erased.
You can also email [email protected] to request deletion, including remaining metadata, operational logs, and separate messaging copies on our server. We will verify the request using your existing identity and remove the data we control. The in-chat command does not automatically erase those separate copies. We cannot erase messages already delivered to other people’s devices or override providers’ independent retention obligations; we will explain any such limits when handling your request.
Text disconnect to remove the household’s YNAB tokens from Ansel. Also revoke Ansel in YNAB’s account settings to revoke the grant at YNAB. Disconnecting does not erase previously retained data; request deletion for that. Deleting data from Ansel does not delete or undo transactions in YNAB.
Changes to this policy
We will keep this policy accurate as Ansel evolves. Before accessing a new type of YNAB data or changing its use or sharing beyond what you consented to, we will update this policy and ask for your consent before the change applies to your data. Adding a new AI provider is not automatically authorized by the general description of Ansel.
Ansel is not directed to children under 13. It is an independent beta, not an official YNAB product.
Back to Ansel