Privacy Policy

Version: 2026-08-08

Effective Date: August 8, 2026

This Privacy Policy is effective as of August 8, 2026 and supersedes all prior versions. We reserve the right to update this policy as our Services evolve — see Section 12 for how we tell you when we do.

Introduction

Glean IP Holdings Inc. ("Glean," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our personal finance application and related services (collectively, the "Services").

By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.

Our Core Privacy Principles:

  • We never sell your financial data. Period.
  • We don't use your data for advertising. We don't serve ads or share your data with advertisers.
  • You control your data. Download a full copy, or delete your account entirely, from your settings — no request, no waiting.
  • Nothing to steal. Glean has no passwords, and the credential that reads your bank is encrypted by us before it is ever written down.

1. Information We Collect

1.1 Information You Provide to Us

Account Information:

  • Name
  • Email address
  • What the setup questions ask for, and nothing else: your age range, your household size, and the goals you select

We do not collect a password, because Glean does not use one — see Section 6.3.

Financial Account Connection Information:

When you connect your financial accounts through our third-party service provider (Plaid Inc.), we receive:

  • Financial institution name
  • Account type (e.g., checking, savings, credit card)
  • Account nickname
  • Last four digits of account number
  • Account balance
  • Transaction history (merchant name, amount, date, category, location)
  • Account holder information associated with your financial accounts

IMPORTANT: We do NOT store your bank login credentials (username and password). These credentials are handled securely by Plaid and are never transmitted to or stored by Glean.

User-Generated Content:

  • Custom merchant names
  • Transaction notes
  • Tags and categories
  • Card nicknames and workspace names
  • Comments and feedback
  • The questions you type into Glean's AI agent, and the conversation they belong to. These are saved so you can return to them, and are visible only to you — not to other people in your workspace, even though your spending data is. You can delete any conversation at any time, and deleting your account deletes all of them. We do not store the underlying rows a question was answered from; those stay in your transactions

1.2 Information Collected Automatically

Usage Information:

  • Pages visited within the Services
  • Features used
  • Time spent on the Services
  • Interaction with charts and visualizations
  • Search queries within the Services

Device Information:

  • Device type (computer, mobile device, tablet)
  • Operating system and version
  • Browser type and version
  • IP address
  • Device identifiers
  • Time zone and language settings

Location Information:

  • We may collect approximate location information from your IP address to provide localized services (e.g., merchant information, currency formatting)
  • We do NOT collect precise GPS location data

1.3 Cookies and Tracking Technologies

What We Use:

  • Essential Cookies: Required for authentication and core functionality
  • Your privacy choice (glean_consent): a single cookie recording what you answered about analytics and recordings. It holds three digits and a date, nothing else — no identifier, no visit history. It is set whether you accept or decline, because remembering a decline is the only way to stop asking. It expires after 12 months, at which point we ask again
  • Performance Cookies: Help us understand how users interact with our Services, including masked session recording. Where the law requires us to ask first — the EEA, the UK, and anywhere we have no lighter rule for — these do not run until you say yes. Where it does not, they run from the first page and Privacy choices stops them
  • Preference Cookies: Remember your settings and preferences

What We DON'T Use:

  • Advertising cookies
  • Cross-site tracking for marketing purposes
  • Third-party advertising networks

Your Control: Privacy choices, in the footer of every page and in Settings, opens the panel where analytics and session recordings are switched on and off. Changing your mind there takes effect immediately and takes exactly as many clicks as agreeing did. You can also control cookies through your browser settings; note that disabling the essential ones may affect how the Services work.

Analytics: We use PostHogto understand how Glean is used — which pages and features people reach, and where they get stuck. PostHog is a third-party provider: the events and recordings it collects for us are processed and stored on PostHog's US Cloud, in the United States (see Section 11 if you are outside the US). We also use Sentry for error monitoring, configured to leave out cookies, IP address and user identity, so a crash report tells us what broke without telling us whose session it was. Vercel and Supabase, which host the application and the database (Section 5), produce server-side request and error logs as a normal part of running the Services. We do not use Google Analytics, and we do not use advertising or ad-network analytics anywhere in the Services.

Session Recording:

PostHog also records your sessions inside Glean. A recording is a replay of how the interface behaved while you used it, so we can see where the product is confusing without asking you to describe it. Recordings are linked to your Glean account, so a problem you report can be matched to the session it happened in.

Everything is masked by default. As the recording is made, every piece of text on the page and the contents of every form field are replaced with blocks. Text is only ever visible in a recording if we have deliberately marked that specific element as safe to show, and we only do that where the element contains nothing of yours — a navigation label or a button that reads the same for every user. So a recording does not contain:

  • Account nicknames, institution names, or the last four digits of an account
  • Balances, transaction amounts, or totals
  • Merchant and vendor names, including custom merchant names you have set
  • Your tags, notes, categories, or the insights Glean generated for you
  • Anything you type, in any field, on any screen

What a recording does show is layout and interaction: the shape of the page, where the blocks of masked text and the controls sat, what you clicked, where you scrolled, how you moved between screens, and how long things took. Charts keep their shape — a bar stays tall or short — but their labels and figures are masked like all other text. It is a wireframe of your session, not your statement. The masking happens in your browser, before anything is sent: the unmasked text never reaches PostHog, and is not something we scrub afterwards.

One thing masking does not cover:the address of the page itself. Glean's addresses are plain paths like /transactions and /vendors, but they also carry the filters you have applied — including a term typed into a search box. Assume a search term is recorded, even though the box you typed it into is masked.

How long we keep recordings: recordings are deleted after 30 days. To have yours deleted sooner, email support@glean.fyi with "Delete my recordings" in the subject line.

How to opt out: we honour Do Not Track and Global Privacy Control. If your browser sends either signal — most offer one or both under privacy settings, and some send GPC by default — PostHog is never started: no session recording, and none of the product events described above. The check runs before anything loads, so it is not a request we pass on to PostHog, it is data that is never collected. Blocking us.i.posthog.com with a content or ad blocker has the same effect. None of this changes how the Services work.

And if you send no signal, what happens depends on where you are, because the rules do. If you appear to be in the EEA, the UK, or anywhere else we have no lighter rule for, nothing non-essential runs at all until you answer the panel — PostHog is not merely switched off, its code is never downloaded. If you appear to be in the United States, where no prior opt-in is required, product analytics and masked session recording start with the page, and Privacy choices in the footer turns either or both off. We work from the country your IP address appears to be in, which is a guess and is sometimes wrong — so if it guesses wrong in a way you mind, the panel is the fix, and it is on every page.

We would rather be plain about that than bury it: in the US we record first and let you stop us, because that is what the law there allows and because a product that cannot see where people get stuck cannot fix it. What makes it a fair trade is the masking described above — the recording is a correctly-shaped page of asterisks, not your spending. If that is not a trade you want to make, one click in Privacy choices ends it, and we keep no recording made after that.

2. How We Use Your Information

We use your information for the following purposes:

2.1 Providing and Improving Our Services

  • Create and manage your account
  • Sync and display your financial transactions
  • Categorize transactions automatically
  • Provide spending analytics and insights
  • Generate charts, reports, and visualizations
  • Detect and alert you about recurring subscriptions
  • Identify vendors and merchants
  • Provide month-over-month spending comparisons
  • Answer the questions you put to our AI agent, which requires sending them and the spending data needed to answer them to an AI provider — Section 4.3 describes exactly what leaves

2.2 Communication

  • Send you transactional emails (sign-in codes, account verification, and similar)
  • Respond to your support requests
  • Send important service updates and security notifications
  • Send optional product updates and tips (you can opt out)

2.3 Security and Fraud Prevention

  • Detect and prevent fraudulent activity
  • Monitor for security incidents
  • Verify your identity
  • Protect the rights and safety of Glean and our users

What We DON'T Do:

  • ❌ We do NOT use your financial data for advertising purposes
  • ❌ We do NOT sell or rent your personal information to third parties
  • ❌ We do NOT share your data with marketers or advertisers
  • ❌ We do NOT train AI or machine learning models on your data
  • ❌ We do NOT share your data with data brokers

One clarification, because the fourth line is easy to over-read: it means we do not train models on your data. Glean has no models of its own to train. It is not a statement about what the AI providers behind our AI agent do with what we send them, so here is what each of them publishes for an account like ours — we are not on a specially negotiated agreement with any of them. Anthropic does not train its models on inputs or outputs submitted through its API. OpenAI does not train on API data unless the customer opts in, and keeps abuse-monitoring logs for up to 30 days. OpenRouteris a router rather than a model provider; it forwards the request to an upstream provider, and that provider's own policy then applies. These are their published terms as checked on 4 August 2026, and we re-check them whenever this page is revised.

3. How We Share Your Information

We share your information only in the following limited circumstances:

3.1 Service Providers (Sub-Processors)

We share information with third-party companies that process it on our behalf so we can run Glean — hosting, the bank connection, payments, email, error monitoring, analytics, and the AI behind our AI agent. Section 5 lists every one of them by name, says what each receives, and says why. That list is the complete one: if a company is not on it, it does not get your data.

What limits each of them: no provider receives everything. Stripe sees a payment and never a transaction; Sentry sees a crash and never a balance; PostHog sees a masked recording and never the words in it. Each gets the narrowest slice its job needs, which is a limit that holds whatever any contract says.

Beyond that, what each provider is permitted to do with what it receives — retention, and whether anything may be used for its own purposes — is set by our agreement with that provider. In every case that agreement is the provider's published standard terms; none of them is specially negotiated for Glean, and we would rather say so than imply otherwise. Section 7.1 lists the retention period each one applies, checked on 4 August 2026.

3.2 Other Users (With Your Permission)

Glean is built around workspaces that can hold more than one person, with owner, editor and viewer roles. Inviting someone is not available yet — there is no way today to add another person to your workspace, so no other user can see your financial data. When invitations ship, this is how it will work:

  • Members of your workspace can view shared financial data
  • Each workspace member signs in as themselves
  • You control who has access to your workspace

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal process (subpoena, court order, etc.)
  • Government or regulatory requests
  • Requests from law enforcement
  • To protect the rights, property, or safety of Glean, our users, or the public
  • To enforce our Terms of Service

4. Third-Party Services

4.1 Plaid Inc.

We use Plaid Inc. to connect to your financial institutions and retrieve your financial data. When you link a financial account:

  • Plaid handles your bank credentials securely – We never see or store your bank login credentials
  • Plaid accesses your financial data – Account balances, transactions, and account details
  • Plaid's security – Plaid uses bank-level encryption and security measures
  • Plaid's privacy policy applies – Your interactions with Plaid are governed by Plaid's End User Privacy Policy, available at https://plaid.com/legal/

Important:Plaid is certified under industry security standards (SOC 2, ISO 27001). You can revoke Plaid's access at any time through your bank or through Glean. Plaid does not sell or rent your personal financial information.

4.2 Supabase

We use Supabase for database hosting, authentication, and cloud infrastructure:

  • Your data is encrypted at rest using AES-256 encryption
  • Data is encrypted in transit using TLS 1.2+
  • Supabase Auth is also what emails you a one-time sign-in code, so it handles your email address for that purpose
  • Supabase's privacy policy is available at https://supabase.com/privacy

4.3 AI Providers (the "Ask" assistant)

Our AI agent lets you put a question about your spending in your own words. Answering it requires a large language model, and we do not run one — so when you use Ask, your question and the spending data needed to answer it are sent to an AI provider outside Glean. This is the one place in the Services where your transaction data leaves our own infrastructure in the ordinary course of using a feature, so it is worth reading carefully.

What is sent:

  • The question you typed, and the earlier questions and answers in that conversation
  • The results of the lookups the assistant runs against your own data to answer it. These are real rows and real figures: merchant and vendor names, amounts, dates, categories, which card, and the insights Glean has generated for you
  • Your plan and the date range it covers, so the assistant cannot quote a figure from outside it

What is not sent:

  • Your name or email address
  • Your bank credentials, or the access token we hold for a bank connection
  • Your account numbers

Who receives it. Requests go to Anthropic first. If Anthropic is unreachable or fails, the same request is retried at OpenAI, and if that also fails, at OpenRouter — which serves the same Anthropic model and may itself route it through Amazon Bedrock or Google Vertex AI. So on a bad day for our suppliers, one question can be seen by more than one of them. All three are in the United States.

What each provider is permitted to retain, and whether any of them may use what we send for model training, is set by that provider's published standard terms — we are not on a negotiated agreement with any of them. As checked on 4 August 2026: Anthropic does not train on API inputs or outputs; OpenAI does not train on API data unless the customer opts in, and retains abuse-monitoring logs for up to 30 days; OpenRouter forwards the request to an upstream provider whose own policy then governs it. We do not ask any of them to store a conversation, and none of the three is sent your name, your email address or your account numbers. If you would rather none of this happen, do not use the AI agent — every other part of Glean works without it, and nothing is sent to an AI provider unless you ask a question.

5. Sub-Processors

These are the companies that receive your information in order for Glean to work. This is the complete list. It is written from the code that does the sending, and we update it in the same change that adds or removes a provider.

Sub-processorWhat it receivesWhy
Plaid Inc.
United States
Your bank login, typed directly into Plaid and never seen by us. From your institution: account type, nickname, last four digits, balance, and transaction history — merchant name, amount, date, category, location.Connecting your accounts and keeping transactions in sync.
Supabase
United States
Everything Glean stores: your account and profile answers, workspaces, connected-institution records, transactions, your custom merchant names, notes, tags and categories, vendors, the insights we generate, and the security log in Section 6.2. Also your email address, to send you a one-time sign-in code.The database, sign-in, and where your data lives.
Vercel
United States
Every request to Glean, and therefore your IP address, browser, and the page addresses you visit — which carry the filters and search terms you have applied. Server logs also record the text of questions you put to the AI agent, so that a disputed answer can be traced back to what was asked.Running and delivering the application.
Stripe
United States
Your email address and your Glean account and workspace identifiers. Your card details go straight to Stripe on its own checkout page — we never receive or store a card number. No transaction or spending data is sent to Stripe.Taking payment for Pro and managing the subscription.
Resend
United States
Your email address and the full content of the messages we send you. Worth being explicit: a spending alert contains what it is alerting you about, so those emails carry merchant names, amounts and the name of the institution in the message body.Delivering alert and service email.
PostHog
United States (US Cloud)
Five product events, none of which has a field that can hold text you or your bank wrote. Page addresses, which do carry filters and search terms. An anonymous identifier for your browser, replaced by your Glean account identifier once you sign in. And session recordings, masked as described in Section 1.3.Understanding which features get used and where people get stuck.
Sentry
United States
Reports about software errors: what broke, where in the code, which browser and operating system, and which release. Configured to leave out cookies, IP address and account identity, and anything credential-shaped is stripped out before the report is sent. An error message can still quote a value that caused it.Finding and fixing crashes.
Anthropic
United States
Only when you use the AI agent: your question, the conversation it belongs to, and the results of the lookups run against your own data to answer it — real merchant names, amounts, dates and categories. See Section 4.3.The AI that answers your questions. First choice.
OpenAI
United States
The same as Anthropic, and only when a request to Anthropic fails.Fallback, so Ask still answers during an outage.
OpenRouter
United States
The same again, and only when both of the above fail. OpenRouter passes the request on to Anthropic's model, which it may reach through Amazon Bedrock or Google Vertex AI.Second fallback.
Google
United States
Only if you choose to sign in with Google. Google handles the sign-in and therefore knows you have a Glean account; we receive your email address and name back. Google is not processing data on our behalf here — it is your identity provider, acting under your own agreement with Google. Signing in with an emailed code instead avoids this entirely.Optional sign-in method.

Two further AI providers, xAI and Fireworks, appear in our code because we measure how well different models answer spending questions. They are not in the path of a user's question, and a question you ask in Ask is never sent to either.

What we do not do: there is no advertising network, no analytics beyond PostHog, no data broker, and no customer-support or chat tool embedded in the Services. Everything with access to your information is in the table above.

6. Data Security

We take the security of your information seriously and employ multiple layers of protection:

6.0 Financial Data Protection Standards

While Glean is not a financial institution under the Gramm-Leach-Bliley Act (GLBA), we recognize the sensitive nature of financial information and implement security safeguards that meet or exceed GLBA requirements. This includes:

  • Technical, ours: encryption in transit, application-level encryption of bank credentials, database-enforced isolation between workspaces, no passwords to steal, and the audit log in Section 6.2
  • Technical, our hosts': encryption at rest, network security, and backups, provided by Supabase and Vercel
  • Physical: the data centres are our hosts' and are covered by their own certifications. Glean operates no facility of its own

Glean is a very small company. That is a real fact about the security model, and it cuts both ways: there are very few people who could access anything, and there is no separate security team. We would rather say that than imply a structure we do not have.

6.1 Encryption

  • Data in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
  • Data at rest: All data stored in our databases is encrypted using AES-256 encryption
  • Bank access tokens: the credential that lets us read a connected account is encrypted by Glean, with AES-256-GCM and a key held outside the database, before it is ever written down. It is never included in a data export

6.2 Access Controls and the Audit Log

  • Every query for your data is filtered by workspace membership in the database itself, so a bug in one page cannot return another workspace's rows
  • Roles — owner, editor, viewer — govern what a workspace member may change
  • Consequential events are written to an append-only, tamper-evident log: each entry is chained to the one before it, so a record cannot be altered or removed without the chain failing a check that runs on a schedule

What that log records:

  • Each time your bank credential was used, and by what — never the credential itself
  • Bank connections created, reconnected or removed
  • Data exports and account deletions
  • Any time our own back-end code ran against a workspace with elevated access
  • Requests that were refused because the requester was not entitled to the data

Each entry holds the time, the type of event, the workspace and user it concerns, and the IP address and browser that made the request. It does not record ordinary reading — opening your transactions is not an event. See Section 7.3 for how long these entries are kept, including after an account is deleted.

6.3 How You Sign In

Glean does not use passwords. You sign in either with Google, or with a one-time code we email you that expires shortly after it is sent. There is no Glean password to be guessed, reused, or leaked in someone else's breach. If you sign in with Google, the security of your Google account — including any two-step verification you have enabled there — protects your Glean account too.

Important: While we implement strong security measures, no system is completely secure. You can help protect your account by:

  • Keeping the email account you sign in with secure, and enabling two-step verification there
  • Never forwarding or sharing a sign-in code we email you
  • Logging out after using the Services on shared devices
  • Keeping your devices and software updated

7. Data Retention

7.1 Active Accounts

We retain your information for as long as your account is active or as needed to provide you with our Services.

Retention Periods:

  • Account information: Retained while your account is active
  • Financial data: Retained while your account is active, or until you disconnect the financial institution. Disconnecting from Settings → Connected Accounts revokes our access at Plaid and deletes that institution's accounts and transactions immediately
  • Transaction history: Retained while your account is active
  • Analytics events (PostHog): 12 months
  • Session recordings (PostHog): 30 days
  • Error reports (Sentry): 90 days
  • Server logs (Vercel), which include the text of questions asked of the AI agent: up to 30 days
  • Questions and answers held by an AI provider (Section 4.3): up to 30 days at OpenAI, in abuse-monitoring logs; Anthropic and OpenRouter apply their own published terms and are not asked to store a conversation. None of the three trains on what we send. Glean itself does not keep a copy of your conversations; they live in your browser for as long as the page is open
  • Email we have sent you (Resend): up to 30 days
  • Your consent choices (analytics and recordings): the record of what you chose is kept as evidence that we asked and what you answered. Your browser stops honouring a choice after 12 months, at which point we ask again

7.2 Deleted Accounts

When you delete your account:

  • Our access to your connected financial institutions is revoked at Plaid first, before any data is deleted
  • Your account information and financial data are permanently deleted from our live systems immediately
  • Some information may be retained for longer if required by law or to:
    • Resolve disputes
    • Enforce our Terms of Service
    • Comply with legal obligations (e.g., tax records, fraud prevention)
    • Protect against fraudulent or illegal activity

Backup Systems: Deleted data may persist in our host's encrypted daily backups for up to 7 days before being permanently purged. That is the retention on our Supabase plan; point-in-time recovery, which would hold a longer window, is not enabled.

7.3 One Thing Deletion Does Not Erase

The security log described in Section 6.2 is append-only by design. It cannot be edited or deleted, including by us, because a log that can be quietly changed is not evidence of anything — and its purpose is to be able to answer, after the fact, when a bank credential was used and who exported what. Deleting your account therefore does not remove your entries from it.

What stays, per entry:

  • The time, and the kind of event — for example "bank connection removed", "data exported", "account deleted"
  • The account and workspace identifiers the event concerned. These are random identifiers, not your name or email address, both of which are deleted
  • The IP address and browser that made the request

What never stays: your name, your email address, your transactions, your balances, your merchant names, and your bank credentials. Those are deleted. As for how long the entries themselves last — we will not give you a number we cannot keep. The same mechanism that makes this log tamper-evident is a database rule that refuses every deletion, from us included, so there is no purge today and entries are retained indefinitely. Building a purge that does not quietly destroy the evidence the log exists to hold is a real piece of work, and we would rather tell you it has not been done than publish a period nothing enforces.

8. Your Rights and Choices

You have the following rights regarding your personal information:

8.1 Access Your Information

  • View your account information in your Glean account settings
  • Download a complete machine-readable copy of your personal information at any time — see Section 8.3

8.2 Delete Your Information

Go to Settings → Delete Account in the app and type the confirmation phrase. Deletion is immediate and self-service. When you confirm, we:

  • Revoke Glean's access to every connected financial institution at Plaid, before deleting anything else
  • Cancel any Pro subscription immediately (the remainder of the current billing period is not refunded)
  • Delete your account, transactions, vendors, tags, notes and insights

Deletion cannot be undone, so download your data first if you want to keep it — see Section 8.3. Residual copies in encrypted backups are purged as described in Section 7.2, a small amount of data may be retained where the law requires it, and the security log described in Section 7.3 keeps its entries.

If you cannot sign in, email support@glean.fyi from the address on your account with "Delete my account" in the subject line and we will verify the request and do it for you.

8.3 Get a Copy of Your Data

Go to Settings → Your Data in the app. Two downloads are available immediately, at no charge, with no request to make and no waiting period:

  • Transactions (CSV) — a spreadsheet of your transactions, matching whatever filters you have applied on the Transactions page. It covers the history window your plan displays.
  • Everything (JSON) — a complete machine-readable copy of everything we hold about you, with no history limit applied: your account and workspace information, connected-institution details, transaction history including custom merchant names, notes and tags, vendor/merchant records, and the insights Glean generated for you.

The JSON copy is never limited by your plan. The 60-day window on the free plan governs what the product displays, not what belongs to you. For your security, the copy never includes the access credentials we hold for your bank connections.

If you cannot sign in, email support@glean.fyi with "Data request" in the subject line and we will send you the same copy within 30 days of verifying the request.

8.4 Opt-Out of Communications

  • Spending alerts: use the unsubscribe link at the bottom of any alert email, or your mail app's own unsubscribe button. It takes effect immediately and does not stop service messages about a broken bank connection
  • Marketing emails: Unsubscribe using the link in any marketing email
  • Product updates: Email support@glean.fyi with "Unsubscribe" in the subject line and we will stop sending them

There is no notification-preferences screen in the app yet, so email is the way to change this.

Note: You cannot opt out of transactional or security-related emails (e.g., sign-in codes, security alerts)

9. Children's Privacy

Glean is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@glean.fyi. We will delete such information promptly.

10. US State Privacy Rights

If you live in California, Colorado, Connecticut, Virginia, or another state with a consumer privacy law, you have rights under it. We extend the rights below to every US resident rather than checking which state you are in.

10.1 Right to Know

You have the right to request that we disclose:

  • The categories of personal information we collected about you
  • The categories of sources from which we collected your personal information
  • The business or commercial purpose for collecting your personal information
  • The categories of third parties with whom we share your personal information
  • The specific pieces of personal information we collected about you

Sections 1 and 5 answer the first four of those in advance, and Section 8.3 gets you the fifth yourself, immediately, without asking us.

10.2 Right to Correct and Delete

You can correct your information and delete your account from Settings at any time — Sections 8.2 and 8.3. You do not need to make a request, and we do not treat you differently for exercising these rights.

10.3 Right to Opt Out of Sale or Sharing

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Those two phrases have specific meanings under these statutes, and both are answered by the Section 5 list: there is no advertising network, no ad exchange and no data broker in it. There is nothing here to opt out of, because it does not happen.

10.4 Global Privacy Control

We honour Global Privacy Control. If your browser or an extension sends the GPC signal, Glean does not start analytics or session recording at all — see Section 1.3. The check happens in your browser before anything loads, so it is not a request we forward to a third party and then hope is respected; the data is never collected in the first place.

GPC applies per browser and per device, so setting it on your laptop does not carry to your phone.

10.5 How to Exercise Your Rights

Most of these are self-service in Settings. Otherwise:

  • Email: support@glean.fyi with "Privacy Request" in the subject line

We will verify your identity before responding to your request. We will respond to verifiable requests within 45 days.

11. International Users

Glean is based in the United States. If you are accessing our Services from outside the United States, please be aware that:

  • Your information will be transferred to, stored, and processed in the United States
  • The United States may not have the same data protection laws as your jurisdiction
  • By using our Services, you consent to the transfer of your information to the United States

European Economic Area (EEA), UK, and Switzerland:

If you are in the EEA, UK, or Switzerland, the GDPR and UK GDPR apply to our handling of your information. The legal basis depends on what we are doing with it:

  • Contract — running your account, syncing your connected accounts, showing you your spending, taking payment for Pro, and answering questions in Ask when you ask one
  • Legal obligation — the records we have to keep, and responding to lawful requests
  • Legitimate interests — keeping the Services secure and working, including the audit log in Section 6.2 and error monitoring
  • Consent — product analytics and session recordings, and nothing else. This is the only basis we rely on that you can revoke unilaterally, which is why it is the only one with a control attached: Privacy choices, in the footer of every page. Withdrawing stops collection immediately and does not affect anything we did while consent was in force

You have the right to access, correct, delete, restrict, object to and port your information, to withdraw consent where we rely on it, and to lodge a complaint with your local supervisory authority. Sections 8.2 and 8.3 do the first, second, third and last of those immediately, in the app, without a request.

Analytics if you are in the EEA or the UK. Analytics and session recording are not necessary to provide Glean, so the rules there require us to ask before we start them, not to offer you a way to stop them afterwards. We ask.

Until you answer, nothing non-essential runs— and we mean that literally rather than as a setting: PostHog's code is not loaded into the page at all, so there is no recorder present and switched off, there is no recorder. The two questions are separate, because agreeing to be counted is not agreeing to be filmed. Declining is one click, in the same place and the same size as accepting, and we remember a decline so you are not asked again.

A browser sending Do Not Track or Global Privacy Control is never asked and never recorded — an objection already made is not a question to re-open. Section 1.3 describes exactly what a recording contains and what is masked before it leaves your browser. You can change your answer at any time from Privacy choices in the footer, and we ask again after 12 months regardless.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You:

  • We will post the updated Privacy Policy on this page
  • We will give it a new version — the dated string at the top of this page. Every version has one, so you can point at the exact document you read. This one is 2026-08-08
  • For material changes, we will notify you via:
    • Email to the address associated with your account
    • Prominent notice in the Services
    • In-app notification

Your Continued Use: Your continued use of our Services after changes to this Privacy Policy constitutes your acceptance of the updated policy.

Opt-Out: If you do not agree with the updated Privacy Policy, you may delete your account.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Glean IP Holdings Inc.

Privacy and security inquiries reach us at the same address. Putting Privacy or Security at the start of the subject line helps us route it.

Response Time: We will respond to your inquiry within 30 days.

Additional Information

Security Incident Reporting

If you believe you have discovered a security vulnerability, please report it to support@glean.fyi. We take security reports seriously and will investigate promptly.

Accessibility

If you have a disability and need this Privacy Policy in an alternative format, please contact support@glean.fyi.