← Herbert

Privacy Policy

Last updated June 12, 2026

This Privacy Policy describes how Proof of Concept Solutions LLC (d/b/a Griot) (“we,” “us,” or “our”) collects, uses, shares, and protects information in connection with Herbert, our personal finance visibility application (the “Service”). By creating an account or connecting a financial account, you agree to the practices described in this Policy.

1. Information We Collect

We collect the account and contact details you provide when you sign up, such as your name, email address, and phone number. With your authorization, we also use Plaid to connect to your financial accounts and to access financial information on a read-only basis, which may include account balances, transaction history, recurring transactions, and liabilities such as credit-card and loan details. We do not have the ability to move money or initiate transactions. In addition, we collect the limited technical and log information necessary to operate and secure the Service.

2. How We Use Your Information

We use your information to provide the Service by aggregating and displaying your own financial data in a single place, and to surface insights and proactive notifications such as spending summaries, unused subscriptions, and balance or interest-rate alerts. We also use it to operate, secure, maintain, and improve the Service, and to communicate with you about it. We do not use your information to provide personalized financial advice; we present your own data and leave decisions about it to you.

3. Plaid

We use Plaid Inc. to connect to your financial accounts. Your use of Plaid is governed by Plaid’s own privacy policy, which is available at https://plaid.com/legal. By connecting an account, you also authorize Plaid to access and transmit your financial data in accordance with that policy.

4. Artificial Intelligence Processing

We use a third-party artificial-intelligence service to help generate the insights and summaries presented within the Service. Information shared with that provider is used to process your request and is handled under the provider’s commercial data-processing terms.

5. How We Share Information

We do not sell, rent, license, or otherwise monetize your financial data beyond providing the Service. We share information only with the service providers that help us operate the Service, including our financial-data, artificial-intelligence, database, hosting, and network providers, each of which is bound by confidentiality and security obligations; when required by law, regulation, or legal process, or to protect rights, safety, and security; and in connection with a merger, acquisition, or sale of assets, in which case this Policy will continue to apply to the information involved.

6. Data Retention and Deletion

We retain your information for as long as your account remains active or as needed to provide the Service. You may request deletion of your data at any time, and we will delete it within a reasonable period following your request or the closure of your account, except where we are required to retain it by law. These practices are set out in our Data Retention and Deletion Policy.

7. How We Protect Your Information

We protect your information using encryption in transit (TLS 1.2 or higher) and at rest, least-privilege access controls, multi-factor authentication on critical systems, and ongoing monitoring. While no method of transmission or storage is entirely secure, we maintain safeguards consistent with our internal Information Security Policy.

8. Your Rights and Choices

You may access, correct, or delete the personal information we hold about you, disconnect your financial accounts and revoke Plaid’s access at any time, and opt out of non-essential communications. Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act. To exercise any of these rights, contact us at privacy@trygriot.com.

9. Consent

We collect, process, and store your data only after you have provided consent, including the authorization presented to you when you connect an account through Plaid. You may withdraw your consent at any time by disconnecting your accounts and requesting deletion of your data.

10. Children's Privacy

The Service is not directed to individuals under 18 years of age, and we do not knowingly collect personal information from them.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised version with an updated effective date and, where appropriate, provide notice of material changes.

12. Contact Us

If you have any questions about this Privacy Policy or our handling of your information, please contact us at privacy@trygriot.com.