SageFinSageFin

Connecting an AI app to your data

SageFin can let another app you already use — Claude, Cursor, or something you wrote yourself — read your financial data and answer questions about it. You would do this to ask things in a tool you already have open, or to script something SageFin does not do itself.

It is off until you create a token or sign an app in, and it is worth understanding what you are agreeing to before you do.

This is not the assistant inside SageFin

SageFin has its own chat, and it is a different arrangement. That assistant runs on our side, under the terms in our privacy policy, and what SageFin does with what it finds describes exactly what it sends and when.

What this page is about is the opposite direction: you connecting an app we do not run.

What leaves your household

This is the part worth reading twice, because the answer is genuinely different from everywhere else in SageFin.

When you connect an outside app, the data it reads goes to that app's model, under that company's terms. Your transactions become part of a conversation living in their history, on their retention schedule. Our privacy policy does not reach it, and neither do we — once a request is authorized and answered, we cannot see what the other end did with the answer.

That is not a warning against doing it. It is the same trade as connecting anything to anything, and the tools are worth having. But it deserves a deliberate decision rather than a ticked box, and the question to ask is the one you would ask of any app: do I trust this one with my bank history?

Two things stay true regardless. Nothing is shared with other SageFin households — every request is scoped to yours. And a token can never reach the admin surface, because that permission comes from your sign-in and a token does not carry it.

Read-only until you say otherwise

By default an outside app can read and nothing else.

The write tools — setting a transaction's category, tagging one, hiding one, assigning one to a business, creating a manual expense, handing over a retailer order page — are off behind two independent gates, and both must be open:

Either one closed means every connected app is read-only, whatever the other says.

With both open, a write happens when the app asks for it. SageFin does not stop and ask you first, because the only one it could ask is the app. The check that involves you is the app's own: most ask before they use a tool that changes something, and SageFin labels each of its tools as one that reads or one that changes, so the app knows which to ask about. If yours offers to stop asking, that is the setting that decides how much it can do unattended.

A change an app makes is marked as the app's. A category it sets reads "Set by an AI app you connected", not as your own choice, and the transaction's history names the app: by the name you gave its token, or for an app you signed in, by the site it comes from, such as claude.ai. It does not replace a category you chose by hand unless you ask it to, and it will not undo a split. On its own it does not teach SageFin how to categorize that merchant in future: your own choices do, and so does a batch you accept, below. It cannot write or change a note, and it cannot mark a transaction as reviewed: that says a person looked at it.

An app can rehearse a change first and see what it would do without doing it. Every change that is made is recorded in your audit log. A transaction an app adds says so at the foot of its own history, "Added to SageFin" by that app, and assigning a transaction to a business or changing its tax line shows there too.

None of this can move money. The write tools change how a transaction is filed inside SageFin. SageFin cannot pay, transfer or cancel anything, and a token does not change that.

When an app changes many transactions at once

A change to one transaction happens when the app makes it. A change to many arrives as a batch, and what happens to a batch is a choice you make when you create the token:

Accepting a batch teaches SageFin. For each merchant whose changes you accepted in full, the next charge from that merchant gets the same category without asking the model. A merchant with any change you unticked, or one the batch put in two categories, is not taught, and neither is one whose category you set by hand yourself. A batch applied immediately teaches nothing, because nobody looked at it.

Either way, a batch that was applied can be taken back for 30 days from the same page. Each transaction returns to the category it had, and to whoever had chosen it. A transaction you have edited since is left as it is, and you are told how many were. What the batch taught is undone too, unless you have corrected that merchant yourself since.

Only you can accept a batch. The app that proposed it has no way to, and a batch never changes a category you chose by hand or a transaction that is split.

When an app suggests a rule

An app cannot create a rule. A rule acts on every transaction that arrives from then on, with nobody looking, so it is always yours to make.

What an app can do is suggest one. The suggestion appears at the top of Settings → Rules, with what it would match, what it would do, the app's reason, and how many of your transactions it matched when it was suggested. Review opens it in the rule editor, where you can change anything before saving it as a rule of your own; Dismiss removes it. Until you save it, it is not a rule and it changes nothing.

This is the same under either batch setting above. Apply immediately covers changes to transactions you already have, which you can see and take back. It never lets an app create a rule.

A suggested rule can set a category, hide what it matches, or both. Anything more is yours to add in the editor. The editor's option to also apply the rule to your existing transactions starts unticked for a suggestion.

Grant one job, not the account

A token carries only the permissions you tick when you create it, and they are narrow on purpose: a token that can read budgets cannot read transactions.

That holds for an AI app too. Connecting one needs the MCP permission, and each thing it can then ask about needs its own: account balances need Accounts, budget figures need Budgets, spending, merchants, recurring charges and rule suggestions need Transactions, and income against expenses needs Cash flow. An app asking for something its token was not given is told which permission is missing, so it can tell you, and everything else it was given keeps working. Reading your category list needs Categories.

The words in your notes stay private. An app can see that a transaction has a note. It cannot read what the note says, whichever permissions its token has. SageFin's help articles need no permission beyond MCP, because they contain none of your data.

The point is what a leak costs. A token scoped to one job leaks that one job, rather than everything you have.

Signing an app in instead

Some apps can sign in to SageFin themselves, so there is no token to copy. Claude Code and the Claude desktop app are two. You add SageFin to the app, and it opens a SageFin sign-in page in your browser that asks you to approve it. Only apps SageFin has approved can do this.

An app you sign in appears under Connected apps in Settings → Integrations the first time it is used. It starts able to read only, whatever it asked for when you approved it. Can make changes lets that one app write, and the household setting above still has to be on as well.

Disconnect stops it at once. The app still thinks it is signed in, but SageFin refuses everything it asks, and signing in again does not get past that. Reconnect lets it back in, able to read only.

The iPhone app has the same list in the same place, so an app can be cut off from your phone without getting to a computer.

Tokens, and what to do if one gets out

You see the secret once, when you create it. Store it wherever the app that needs it keeps its configuration, and treat it like a password.

Give it an expiry. A year is the default. A token with no expiry is one you will forget you issued.

If it leaks, revoke it in the same screen. Revoking is immediate and does not affect your other tokens or your own sign-in, so there is no reason to hesitate — revoke first and decide afterwards whether you needed it.

Setting one up

Everything you need is in Settings → Integrations: creating the token, choosing what it can reach, and the configuration to paste into the app you are connecting, already filled in with the right address.

That screen is the reference rather than this page, deliberately — it shows the permissions that actually exist right now, and a list copied into a help article would eventually start lying to you.