Back to MOX

MOX · Privacy

PRIVACY NOTICE

This notice explains what MOX receives when you create an account, connect a financial institution, or use its financial-planning and AI features. It also explains how to disconnect a bank or delete your data.

Effective and last updated: August 4, 2026

Who operates MOX

MOX is an invite-only personal financial assistant operated by Marlon Ma. Questions or privacy requests can be sent to lm5472@nyu.edu.

Information we collect

  • Account information: your email address, authentication provider, account identifiers, and security/session metadata.
  • Financial information from Plaid: connected institution and account identifiers, account names and types, institution-cached balances, transactions, merchants, categories, and supported liability details. MOX infers recurring patterns and starts its own daily net-worth history after you connect. MOX does not receive your bank username or password.
  • Information you provide: questions, replies, corrections, goals, preferences, plans, check-ins, and other financial-coaching inputs.
  • Technical information: limited request, error, security, and rate-limit metadata needed to operate and protect the service. Server logs are designed not to include authorization headers, Plaid secrets, access tokens, request bodies, or full third-party error objects.

How we use information

We use this information to authenticate you; connect and refresh the bank accounts you request; display balances, activity, recurring obligations, and net worth; answer your questions; create and maintain plans; prevent abuse; diagnose failures; and meet legal, security, and compliance duties. We do not sell personal information or use financial information for targeted advertising.

Service providers and AI

MOX uses Supabase for authentication and database services, Plaid for financial-account connectivity, and Netlify for application hosting and delivery. These providers process data on our behalf under their respective terms and security controls.

When you deliberately use an AI feature, MOX may send your question and the financial context needed to answer it to the AI provider selected for that request. Depending on deployment configuration, that provider may be Google Gemini, Anthropic, OpenAI, or DeepSeek. Do not include information in a question that is unnecessary for the answer. DeepSeek may process data in jurisdictions outside the United States, including the People's Republic of China; MOX should not enable that provider for financial data without a separate privacy and vendor-risk decision.

Security and encryption

MOX uses encrypted network connections, Supabase row-level security, least-privilege server credentials, and restricted production access. Plaid access credentials and any legacy Asset Report token awaiting deletion are sealed by the application with AES-256-GCM before database storage. Mobile authentication material is held in the operating system's secure key store, and the mobile query cache is encrypted with a device-bound key. Financial records that must be filtered or aggregated are protected by the database platform's encryption at rest, access controls, and audit boundaries rather than by searchable application-level ciphertext. No system can guarantee absolute security.

Retention and deletion

MOX's target production policy is a rolling 400-day window for transaction rows, matching the period the product can display. Bank-derived caches and encrypted connection credentials are kept while that bank remains connected. Questions, preferences, goals, and plans are kept while your account remains active or until you delete the relevant item. Short-lived operational and security records are kept only as needed to protect and run the service. Backups and service-provider copies may take additional time to expire under controlled retention schedules.

Disconnecting a bank requests revocation of its Plaid Item and deletes its MOX bank data. The in-app account-deletion control first attempts to revoke every connected Plaid Item, then permanently deletes the MOX account and associated application rows. You may also request access, correction, or deletion by emailing lm5472@nyu.edu. We may need to verify your identity before acting on a request.

Your choices

  • Connect only the institutions you want MOX to use.
  • Disconnect an institution from the Accounts screen.
  • Delete individual memories or conversation history in the product.
  • Delete your entire account from the Accounts screen.
  • Choose whether to use features that send context to an AI provider.

Changes to this notice

We may update this notice when the product, providers, or legal obligations change. The date above will change when the notice does. Material changes will be communicated in the product or by another appropriate channel.