Last updated: 16 September 2026
The most secure data is the data you never hand over. Nanvero is designed around that idea: it reads your travel from the confirmations already in your inbox, so there is far less to hold — and far less that could ever be at risk.
We never hold your loyalty passwords
Nanvero does not ask for the passwords to your airline, hotel or card accounts, and it never signs in as you. That means there are no loyalty-program logins for anyone to steal, and no multi-factor prompts for you to approve. Your balances and trips are derived from the emails your programs already send you — not from credentials we store.
You can forward those emails to Nanvero, or connect a mailbox read-only so it reads them for you — either way there are no loyalty passwords and no multi-factor prompts, and a connection can be revoked at any time.
If you connect Gmail, Google grants a read-only permission that covers your mailbox, and Nanvero’s systems are built to inspect only mail from recognized travel and loyalty senders. In plain terms:
- Nanvero can read recognized travel and loyalty emails.
- Nanvero cannot send, change or delete any email, and it never sees the passwords to your loyalty accounts.
The access token Google issues is encrypted at rest and used only to read recognized travel and loyalty mail. It is deleted when you disconnect Gmail or delete your account, so revoking access — in Nanvero or from your Google account — ends our access for good.
How we protect your data
- Encryption in transit. Traffic to and from Nanvero is protected with HTTPS/TLS, so it is encrypted as it travels between your device and us.
- Reputable infrastructure. We run on established cloud providers that encrypt stored data at rest and maintain strong physical and network security.
- Encrypted and access-controlled. Your data is encrypted in transit and at rest, on established cloud infrastructure with strict, least-privilege access.
- Least data, least access. We collect only the travel information needed to run the service, and limit who and what can access it.
- Never sold. Your data works for you. We do not sell it, and we are not in the business of turning you into a product.
Delegated and household access
Household and Executive let people you trust see or manage parts of your Nanvero. Everyone uses their own separate login — a delegate never receives your credentials, and there is no shared password to hand over or rotate. Access is role-based and scoped to exactly the areas you grant: a delegate sees only what you open to them, billing and sign-in settings stay locked to you, and work a delegate does is recorded as theirs. You can revoke access, or remove a household member, in one click at any time.
Payments
Subscription payments are handled by a certified third-party payment processor. Your full card details go to them, not to us — Nanvero never sees or stores your card number.
Does AI read my emails?
Nanvero first reads a forwarded statement with its own deterministic rules. Only when those can’t confidently identify a balance is the relevant part of that email sent to our AI provider, purely to extract the number — and data sent through that API is not used to train AI models. See our Privacy Policy for the detail.
Your part
Because Nanvero reads from your inbox, your email account is the key to keep safe. We recommend you:
- use a strong, unique password on your email, and turn on two-factor authentication;
- stay alert to phishing — we will never ask you for a password or a one-time code, and no genuine message from Nanvero ever will; and
- contact us straight away if you think your account has been accessed by someone else.
If something goes wrong
If we identify a security incident affecting your personal information, we investigate it promptly, act to contain it, and notify affected users where the law requires — without waiting to be asked.
Reporting a vulnerability
We welcome reports from security researchers. If you believe you have found a vulnerability, please email hello@nanvero.com with enough detail for us to reproduce it. Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly, and do not access or modify other people’s data, degrade the service, or run intrusive automated testing. We will not pursue good-faith researchers who follow this.
Contact
Security questions or concerns? Email hello@nanvero.com and we’ll take it seriously.