निNivritee
Why NivriteeHow it worksFeaturesFor familiesAbout us
Sign inStart your plan
Why NivriteeHow it worksFeaturesFor familiesAbout usSign in

Privacy Policy

Last updated: 26 September 2026

In short

  • Nobody at Nivritee opens your plan, your holdings or your conversation with Niv. The screen to do it was never built.
  • We do not sell data, show ads or connect to your bank.
  • No email we send contains a figure from your plan.
  • A summary of your plan goes to Anthropic, from our server, so that Niv can answer you. Nothing is used to train models.
  • Analytics run only if you agree.
  • Delete my account, in the app, permanently deletes your data.

Contents

  1. Who we are
  2. What this policy covers
  3. What we collect
  4. What we do not collect or do
  5. How we use it
  6. Who can see your data
  7. Service providers
  8. Emails
  9. Cookies and browser storage
  10. Where your data is stored
  11. How long we keep it, and deleting your account
  12. Security
  13. Your rights
  14. Children
  15. Changes to this policy
  16. Contact

1. Who we are

Nivritee (nivritee.com) is a self-serve financial independence planner. It is founded and operated by Amit Goel, based in Kuala Lumpur, Malaysia, who is responsible for your personal data under this policy. In this policy “Nivritee”, “we” and “us” mean that operator.

You can reach us about anything in this policy at amit@penome.com.

2. What this policy covers

This policy covers the public website at nivritee.com, the signed-in app at nivritee.com/app and /learn, the emails we send, and the people you invite to see or share your plan. It does not cover other websites you reach from ours, or the services of the providers listed in section 7 when you use them directly.

3. What we collect

Your account

  • Your name, email address and, if you sign in with Google, your Google profile picture’s address. You can change the name we show and choose initials instead of the picture.
  • If you use email and password, the password is handled by Firebase Authentication (Google). We never store it. While you set it, our server checks it against strength rules and, through Have I Been Pwned, against known breaches — only the first five characters of a one-way hash of it leave our server for that check. It is never logged, stored by us, emailed or put in a web address.
  • When you sign up, reset a password or ask for a verification email again, a Google reCAPTCHA check runs to tell people from automated scripts.
  • Dates: when you signed up, verified your email and last signed in.

Your plan

Everything you type into your plan, which can include:

  • ages, the country you live in now and where you expect to be living later;
  • income, living expenses and their breakdowns, assets, loans and life goals;
  • the rates and assumptions you choose, and the answers you give to questions about your household and spending;
  • details of your partner and family members that you enter — for example their names, how they are related to you, and children’s ages.

We also keep what the service computes from your plan (projections, scores and other readings, and a monthly snapshot of them), recent earlier versions of your plan so that two people editing at once do not overwrite each other, and a record of changes you make to figures through Action Items.

Your investments

Holdings you list (which security, on which exchange), the transactions and regular investment plans you record against them, and deposits you enter, including the bank name and rate. We do not connect to your bank or broker and never ask for statements or account numbers.

Your conversation with Niv

Niv is the app’s automated assistant. We store your conversation with her, the short notes she keeps about you (such as what you would like to be called), and which of her suggestions you applied. You can see and delete each of these in the app.

Sharing and invitations

When you invite somebody, we store the name, email address and role you give them, an optional description and, where asked, their age, together with the invitation’s status and the access you granted. The link we email them is stored only as a one-way hash.

How you use the service

  • Counts and timestamps: for example how many edits, saves or messages to Niv happened on a day, and which screens were opened. We record the names of fields you edited (such as “expenses”), never what you typed into them.
  • For each visit: when it started, how long it lasted and how many screens were opened — not the order you opened them in. We keep your 50 most recent visits and delete older ones automatically.
  • Your device type, operating system and browser, read from your browser’s User-Agent when you sign in. The raw User-Agent is then discarded.
  • Your approximate location (city, region, country), looked up from your IP address in a database stored inside our own server. Your IP address is not sent to any location service.

Technical records

Like any web service, our hosting provider records requests to our servers, including IP address and browser type, to run and secure the service. Our own error logs record where a fault happened, never the content of your plan. To limit abuse, we count requests per IP address and per email address; those counters hold a one-way hash, not the address itself.

4. What we do not collect or do

  • We do not link to bank, broker or card accounts.
  • We do not ask for government ID, tax numbers or account numbers.
  • We do not sell, rent or trade personal data, and we show no advertising.
  • We do not pass your figures, rates or outcome to any marketing, sales or CRM service.
  • We do not use your data to train AI models.

5. How we use it

  • To provide the service — saving your plan, computing your projections and readings, pricing your holdings, running Niv, and letting the people you choose see or edit your plan. This is necessary to perform our agreement with you.
  • To keep accounts secure — verifying email addresses, checking passwords, sending security notices, rate limiting and preventing abuse. This is in our legitimate interest and yours.
  • To understand and improve the product — the usage counts described above, and anonymous distributions across all plans (section 6). This is in our legitimate interest, and is built so that it never shows anybody’s plan.
  • To send you email about your account and the service (section 8).
  • Website analytics, only if you agree (section 9).

We do not make decisions about you that have legal or similarly significant effects by automated means. The outcomes the app shows are projected estimates for your own use.

6. Who can see your data

Nobody at Nivritee reads your plan

There is no internal screen that displays a plan, a holding, a transaction or a conversation with Niv. It is not a restricted tool — it was never built, and our automated tests fail if a figure from a plan reaches the administrative panel. The database refuses all direct access from browsers; every read goes through our server, for the signed-in person it belongs to.

What the founder can see

  • Account identity and usage: names, email addresses, sign-up and sign-in dates, approximate sign-in locations, devices, the usage counts above, and which emails were sent and delivered.
  • For sharing: who invited whom, the invitee’s name, email address, role and the invitation’s status — never a figure and never the description you wrote.
  • Anonymous distributions across every plan, such as how many households fall in an age band. These carry no name, account or plan identifier, and any group smaller than five households is left out entirely rather than combined.

None of these include an amount, a rate, an age from a plan or the outcome of a plan.

People you share with

A partner who joins your plan signs in with their own account and shares it with you as an equal co-owner; each of you decides whether the other may view or also edit your own side. A viewer — for example a family member, a lawyer, a Chartered Accountant or a trusted friend — sees only the parts of the plan you grant, cannot change anything, and cannot use Niv on your plan. On a plan you share with a partner, a new viewer or wider access needs your partner’s approval too; the approval email shows them the invitee’s name, email address, role, description and age, so that they know who they are agreeing to.

Service providers and the law

The providers in section 7 process data on our behalf, only as needed to run the service. We may disclose data if the law requires it, and would tell you unless we are legally prevented from doing so.

7. Service providers

These are the outside services the product uses, and what each receives.

  • Google Cloud and Firebase (Google) — hosting (Firebase Hosting, Cloud Run), the database (Firestore), sign-in (Firebase Authentication), and the store for our own keys (Secret Manager). Holds all of the data described in this policy.
  • Anthropic — the Claude model behind Niv. When Niv answers you, opens a section with a remark, or writes her short commentary on some pages, our server sends Anthropic a summary of your plan (figures, totals and the names and relationships of family members you entered), your first name, the notes she keeps about you and the conversation so far. This happens only from our server; the key never reaches your browser. It is sent under Anthropic’s commercial API terms.
  • Resend — delivers our email. Receives your email address, your name and the message, which never contains a figure from your plan.
  • Google Analytics — website analytics, only with your consent (section 9).
  • Google reCAPTCHA — runs on the sign-up, password reset and verification-resend forms, and receives information about your browser and use of the page as Google’s reCAPTCHA terms describe.
  • Have I Been Pwned — receives the first five characters of a one-way hash of a new password, and nothing else. It cannot tell what the password is or whose it is.

Market and currency data come from the National Stock Exchange of India and BSE (their daily price files), an independent mirror of AMFI’s published mutual fund prices (run by Tigzig), EODHD (international exchange prices), the European Central Bank and ExchangeRate-API (currency rates). These receive no personal data: we fetch prices for securities, not for people, and they never learn who holds what.

Approximate location comes from a MaxMind GeoLite2 database file stored inside our own server. MaxMind receives nothing.

8. Emails

No email we send carries a figure from your plan — not an amount, an age, a rate or the outcome. Email is forwarded, synced and indexed, and your balance sheet does not belong there.

We send:

  • Account and security email — verifying your address, resetting a password, and telling you when your password changes or a Google sign-in is linked. These are needed to run your account. They contain no tracking image and their links are not rewritten.
  • Sharing email — invitations, approval requests, and notices that access was granted or removed. An invitation email gives the inviter’s first name and the role offered, never a figure.
  • Service email — a welcome once your email is verified, a notice when your plan is ready, one reminder if you signed up but never made a plan, a digest when there are new Action Items, a launch note for a feature you asked to hear about, and occasional product updates. These may contain a small image that tells us whether the email was opened.

To stop Action Items email, turn it off in your profile menu in the app. To stop reminders and product updates, use your mail app’s unsubscribe control or reply with “unsubscribe”. Account and security email cannot be switched off while you have an account.

Our record of an email holds its type, when it was sent and whether it was delivered or opened — never its content.

9. Cookies and browser storage

We keep what your browser stores to the minimum the app needs:

  • Sign-in session — Firebase Authentication keeps you signed in. Necessary.
  • Your analytics choice — whether you agreed to analytics, so we do not ask again.
  • Whether the side menu is collapsed — a display preference.
  • A visit identifier — random, for the current tab only, and deleted when the tab closes. It tells one visit from the next.
  • Where to return after signing in — for example an invitation link, for the current tab only.
  • An older saved draft — plans made before August 2026 were kept in the browser. If one is found it is moved into your account once and deleted from the browser.

Your plan, its figures and your conversation with Niv are never stored in your browser.

Analytics

We use Google Analytics to learn which screens are used and where people stop. It starts with storage denied: until you choose “That’s fine” it sets no analytics cookie, and Google receives at most signals without a cookie identifier. With your agreement it receives page views and events such as a section being opened, a plan being generated, and the one-word outcome band of a plan (for example “Workable”) — never an amount, a rate, an age, your name or your email address. IP addresses are anonymised, and Google’s advertising features are switched off.

To change your answer, clear this site’s data in your browser; you will be asked again on your next visit.

The sign-in page and the email verification screens load Google reCAPTCHA, which may set its own cookies to tell people from automated scripts.

10. Where your data is stored

Our database and servers run on Google Cloud in the asia-south1 region (Mumbai, India). Google’s sign-in, hosting and analytics services, and our other providers, may process data in other countries, including the United States.

If you live outside India, your data is therefore processed outside your own country. We choose providers that commit to protecting it, rely on their contractual safeguards for international transfers, and send each only what section 7 lists.

11. How long we keep it, and deleting your account

We keep your data while you have an account. Delete my account, in the app, shows you exactly what will go before you confirm, and then permanently deletes your plan and its history, your holdings and every transaction, your conversation with Niv and her notes, your readings and snapshots, your usage and email records, and your sign-in itself. There is no copy kept behind a flag.

Some things are not tied to you and remain:

  • anonymous aggregate distributions (section 6), which never held your identity;
  • security prices and exchange rates, which belong to nobody.

If your plan is shared, deletion works like this:

  • With a partner: your own side of the plan and your own listed investments are deleted. The plan continues with your partner, and anything you held together becomes theirs.
  • With viewers: their access ends and they are told it has been removed.
  • As a viewer: your access to plans others shared with you ends.
  • Invitations you sent that are still open are cancelled. The record of an invitation (the invitee’s name, email address, role and status) is closed rather than erased; ask us at amit@penome.com and we will remove it.

For recovery from failures, our database keeps a rolling seven-day recovery window, and we take occasional backup copies before releasing changes. Deleted data leaves the recovery window within seven days and is removed from backup copies when they are deleted. Backups are used only to restore the service, never to read a plan.

12. Security

  • Data is encrypted in transit and at rest.
  • Browsers cannot reach the database at all; every request goes through our server, which checks a verified sign-in and reads only that person’s data or data they have been granted.
  • An unverified email address cannot use the app. Invitation links work once and are stored only as a hash.
  • Keys for outside services are held in a secret store and never sent to the browser.
  • Automated tests check that one person’s data cannot reach another and that no figure reaches the administrative panel or an email.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities where the law requires, without undue delay.

13. Your rights

Depending on where you live, you may have the right to:

  • see your data — everything in your plan, your investments and your conversation with Niv is visible to you in the app;
  • correct it — edit it in the app, or ask us;
  • receive a copy — there is no export button yet; email us and we will arrange one;
  • delete it — with Delete my account, at any time;
  • object or withdraw consent — to analytics (section 9) or to service email (section 8), without affecting anything else;
  • complain to your data protection authority.

This policy aims to respect the principles of the EU and UK General Data Protection Regulation, India’s Digital Personal Data Protection Act 2023 and Malaysia’s Personal Data Protection Act 2010. We do not claim certification under any of them. To use any of these rights, email amit@penome.com; we may need to confirm it is you, and we aim to reply within 30 days.

14. Children

Nivritee is for adults aged 18 and over, and we do not knowingly hold an account for anybody younger. A plan may include details of your children that you enter, such as their names and ages. You are responsible for entering them, and they are used only to personalise your own plan — for example, when a child might start higher education.

15. Changes to this policy

When we change this policy we will update the date at the top. If a change materially affects how your data is used, we will tell you by email or in the app before it takes effect.

16. Contact

Questions, requests and complaints about privacy: amit@penome.com. Nivritee, operated by Amit Goel, Kuala Lumpur, Malaysia.

निNivritee

Financial independence planning for households in one country or several. Everything you earn, own, owe and spend, projected year by year — with a plain answer about whether the plan holds, where the money should sit, and how what you hold is doing.

Product

Why NivriteeHow it worksFeaturesRetirement TrackerFreedom LadderInvestment PerformanceFreedom IndexFor familiesFor global familiesSign in

Research

All researchiPhone price history

Company

About usOur founderWhat we do not doPrivacy PolicyTerms & ConditionsSitemap

Markets served

United States · Canada · United Kingdom · Europe · Australia · New Zealand · Singapore · Hong Kong · Japan · India · Malaysia

Nivritee is a planning tool for informational purposes only and does not constitute financial, tax, or legal advice. Consult a licensed professional before making financial decisions. All figures are projected estimates, not predictions.

© 2026 Nivritee. निवृत्ति — freedom from obligation.