Effective Date: October 8, 2025
Last Updated: October 8, 2025
This Privacy Policy is effective as of October 8, 2025 and supersedes all prior versions. We reserve the right to update this policy as our Services evolve.
Glean IP Holdings Inc. ("Glean," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our personal finance application and related services (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
When you connect your financial accounts through our third-party service provider (Plaid Inc.), we receive:
IMPORTANT: We do NOT store your bank login credentials (username and password). These credentials are handled securely by Plaid and are never transmitted to or stored by Glean.
Your Control: You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our Services.
Analytics: We use analytics services (such as Vercel Analytics, Google Analytics, and Supabase Analytics) to understand aggregate usage patterns. These services are configured to respect user privacy and do not track individual users for advertising purposes.
We use your information for the following purposes:
We use Plaid Inc. to connect to your financial institutions and retrieve your financial data. When you link a financial account:
Important: Plaid is certified under industry security standards (SOC 2, ISO 27001). You can revoke Plaid's access at any time through your bank or through Glean. Plaid does not sell or rent your personal financial information.
We use Supabase for database hosting, authentication, and cloud infrastructure:
We take the security of your information seriously and employ multiple layers of protection:
While Glean is not a financial institution under the Gramm-Leach-Bliley Act (GLBA), we recognize the sensitive nature of financial information and implement security safeguards that meet or exceed GLBA requirements. This includes:
Our approach to financial data security follows industry best practices established for banks and financial institutions.
Given the sensitive nature of financial data, we provide two-factor authentication (2FA) for all user accounts. We strongly recommend enabling this feature in your account security settings.
Important: While we implement strong security measures, no system is completely secure. You can help protect your account by:
We retain your information for as long as your account is active or as needed to provide you with our Services.
When you delete your account:
Backup Systems: Deleted data may persist in backup systems for up to 90 days before being permanently purged.
You have the following rights regarding your personal information:
Export your data in machine-readable formats (CSV or JSON). Your export includes all data categories:
Access the export feature in your account settings. Exports are generated instantly for accounts with standard transaction volumes.
Note: You cannot opt out of transactional or security-related emails (e.g., password resets, security alerts)
Glean is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@glean.ai. We will delete such information promptly.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
You have the right to request that we disclose:
We do not sell your personal information.
For purposes of the CCPA, "selling" can include certain data sharing for online advertising. We do not engage in this practice with your financial data or personal information.
To exercise your CCPA rights:
We will verify your identity before responding to your request. We will respond to verifiable requests within 45 days.
Glean is based in the United States. If you are accessing our Services from outside the United States, please be aware that:
If you are in the EEA, UK, or Switzerland, we will comply with applicable data protection laws, including the General Data Protection Regulation (GDPR). We rely on the following legal bases for processing your information: Contract, Consent, Legitimate Interests, and Legal Obligation. You have additional rights under GDPR, including the right to lodge a complaint with your local supervisory authority.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Your Continued Use: Your continued use of our Services after changes to this Privacy Policy constitutes your acceptance of the updated policy.
Opt-Out: If you do not agree with the updated Privacy Policy, you may delete your account.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Glean IP Holdings Inc.
Response Time: We will respond to your inquiry within 30 days.
If you believe you have discovered a security vulnerability, please report it to security@glean.ai. We take security reports seriously and will investigate promptly.
If you have a disability and need this Privacy Policy in an alternative format, please contact support@glean.ai.