Last updated: August 15, 2026
This service ("YNAB MCP Server") is a personal-use connector that lets an AI assistant (Claude) read and manage data in a user's own YNAB (You Need A Budget) account on their behalf, via YNAB's official API and OAuth. This page explains what data the service accesses, how it is handled, and how it is secured.
When a user connects their YNAB account, the service is granted access to that user's YNAB data through YNAB's own API - budgets, accounts, categories, transactions, payees, and scheduled transactions - to the extent needed to carry out the actions the user asks the assistant to perform (for example, listing transactions, creating a transaction, or updating a category's budgeted amount).
The service stores only the OAuth credentials (access and refresh tokens) needed to make authenticated requests to the YNAB API on the user's behalf. It does not maintain a separate copy or database of a user's budget, account, or transaction data - that data is fetched from YNAB's API when needed to respond to a request, and is not retained by the service afterward.
Data fetched from the YNAB API is used solely to respond to the requests the user makes through their own Claude conversation. It is not used for analytics, advertising, profiling, or any purpose other than carrying out the user's own request.
Data obtained through the YNAB API is not sold, shared, or otherwise disclosed to any third party, with one exception inherent to how this service works: the data is returned to the Claude conversation the user themself initiated, so that Claude can use it to answer the user's question or complete the action the user asked for. That conversation, and any data within it, is controlled by the user and subject to Anthropic's own privacy policy. We do not provide YNAB data to any other party, service, or use.
All communication with this service happens over HTTPS. OAuth tokens are stored server-side only and are never exposed to the browser or to any party other than this service and YNAB's own API.
Stored tokens are retained only for as long as a user's connection remains active. A user can revoke this service's access at any time from YNAB's own Account Settings → Authorized Applications page, which immediately invalidates its access to their data. To request deletion of any data this service holds about you, contact j.grasso87@gmail.com.
If this service begins accessing a type of YNAB data not described above, or changes how it uses a user's data, this page will be updated first and users will be asked to consent to the change before that access begins.
Questions about this policy or this service's handling of your data can be sent to j.grasso87@gmail.com.