PRIVACY POLICY
Last Updated: July 23, 2026
This Privacy Policy explains how Pearl Tech Inc., a Delaware corporation ("Company," "we," "us," or "our"), collects, uses, discloses, and safeguards personal information in connection with the Pearl mobile application (the "App"), our website https://joinpearlai.com (the "Site"), and related services (collectively, the "Services"). Pearl is a personalized financial coaching, education, and organization tool offered in the United States. By using the Services, you agree to this Privacy Policy. If you do not agree, do not use the Services.
Contact: pearl@pearltech.xyz (email only). Our registered business address 701 Brazos St, Austin, Texas USA does not accept postal mail.
Financial Privacy (GLBA/Reg P). Financial Privacy (GLBA/Reg P). Because Pearl provides financial coaching and organization tools that handle your financial information, certain information we collect is nonpublic personal information (NPI) governed by the Gramm-Leach-Bliley Act and Regulation P. Where GLBA applies, state consumer privacy laws (e.g., CCPA/CPRA) generally do not apply to that NPI. This Policy covers both GLBA-covered NPI and non-GLBA data, and explains the difference.
1. SCOPE; AVAILABILITY; ROLES
- Territory. The Services are intended for individuals located in the United States. We do not offer the Services in other jurisdictions; if we expand, we will publish the required jurisdiction-specific notices and transfer mechanisms first.
- Adults. The Services are intended for adults (18+). App Store and Google Play age settings also apply (see the Children's Privacy section).
- Role. For most processing we act as a business/controller. Where we process information on behalf of a financial institution or partner, we act as a service provider/processor.
2. CATEGORIES OF INFORMATION WE COLLECT
What we collect depends on how you use the Services. We practice data minimization — we ask for a small amount of information directly, and most financial detail comes only if you choose to link a bank account.
A. Information You Provide
When you sign up and use Pearl, you provide a limited set of information:
- Account. Your mobile phone number, which you verify with a one-time code at sign-in. (We use phone-based sign-in; we do not require a password.)
- Profile. Your first name and date of birth, and — only if you choose to add them in your profile — your email address, city, state, employer, and employment type (for example, employed or self-employed).
- Coaching inputs. Your financial goals (which you describe in your own words), whether taxes are withheld from your pay, your chosen Pearl coaching personality, and similar preferences.
- Support & feedback. Messages you send us through in-app chat or email, and information you choose to share when you contact support or give feedback.
- Consents & settings. Records of your notification choices, cookie/ad preferences, and privacy settings.
B. Financial Account Information (Optional; Read-Only via Plaid)
Pearl works best when you connect a financial account, but it is your choice. If you link an account through Plaid, Inc. ("Plaid"), we receive read-only financial data that you authorize, which may include:
- Account metadata & balances. Institution name, account type, masked account identifiers, and current/available balances.
- Transactions. Merchant/payee, amount, date, category, and description, plus standardized enrichment fields.
- Investments/holdings (if your account includes them). Security identifiers, quantities, and valuations; limited cost basis where provided.
- Liabilities (if applicable). Balances, interest rates, minimum payments, and due dates, including loan terms made available through the API.
- Recurring transactions. Detected recurring inflows (such as paychecks) and bills.
C. Information Collected Automatically
- Device & log data. IP address, coarse (IP-derived) location, device and operating-system type and version, app version/build, language, time zone, and crash, error, and diagnostic logs.
- Usage analytics. Screens viewed, taps, navigation, feature usage, and referral/UTM parameters.
- Cookies, local storage, and mobile SDKs. Used for authentication, preferences, analytics, and — on the Site — advertising/measurement (see the Cookies section).
D. Sensitive Information — What We Do Not Collect
Your linked financial-account information is sensitive and is treated as NPI under GLBA. We do NOT collect your Social Security number, government-issued ID number, driver's license, precise geolocation, or biometric data, and we never receive your bank login credentials (those go to Plaid and your bank — see the Financial Data Connectivity section). If a future feature ever requires additional sensitive data (for example, identity verification for money movement), we will provide just-in-time notice, obtain consent where required, and limit use to that purpose.
3. SOURCES
We do not buy personal information from data brokers.
- You and your devices (sign-up details, profile, coaching inputs, settings, and communications).
- Financial institutions you connect through Plaid.
- Vendors that provide hosting, storage, analytics, crash reporting, communications, payments, and AI functionality.
4. HOW WE USE INFORMATION (PURPOSES)
We process information to:
- Provide & operate the Services: create and secure your account, sync and categorize your financial data, and generate the summaries, organization, and educational coaching Pearl provides.
- Power AI coaching & education features: summarize your finances, spot patterns and changes, answer your questions in chat, and explain general, non-securities ideas — using third-party AI providers (see the AI/ML section).
- Send notifications: deliver the daily or near-daily push notifications, in-app messages, and emails that summarize your finances and surface options you may want to consider.
- Personalize: tailor content, tips, and your chosen coaching personality, and remember your preferences.
- Security & integrity: detect and prevent fraud and abuse, protect accounts, enforce limits, and respond to incidents.
- Analytics & improvement: understand usage and performance, diagnose crashes, and improve quality and reliability.
- Communications: respond to support requests and send service and (where permitted) promotional messages you can opt out of.
- Compliance & legal: meet GLBA/Reg P, consumer-protection, tax, and recordkeeping obligations and respond to lawful requests.
- Research & model improvement: using de-identified or aggregated data to develop, evaluate, and improve our features and the models that power Pearl (see the De-Identification and Account Deletion sections).
5. GLBA vs. STATE PRIVACY LAWS
- GLBA-covered (NPI). The financial information we collect and use to provide the Services — for example, linked-account balances, transactions, holdings, liabilities, and the financial insights derived from that data. This NPI is governed by GLBA/Reg P and is generally exempt from state comprehensive privacy laws.
- Not GLBA-covered. Site/app analytics, cookie and SDK identifiers, marketing contact information, and advertising/measurement data. These may be subject to state privacy laws (see the U.S. State Disclosures section), and we apply the applicable rights and opt-outs.
6. HOW WE SHARE — AND WHAT WE NEVER SELL
We do not sell your personal information, and we never sell or rent your financial-account data. We do not share your financial-account data with third parties for their own marketing or advertising, and we do not provide it to data brokers. We share information only as described here:
- Service providers/processors. Vendors that host, store, secure, and operate the Services on our behalf, under contracts that prohibit them from using your data for any other purpose (see the next section for who they are).
- Financial connectivity (Plaid). To establish and maintain the read-only account connection you authorize.
- AI providers. We send relevant portions of your financial data to third-party AI providers solely to generate Pearl's coaching and educational features for you (see the AI/ML section).
- Connected AI assistants (at your direction). If you choose to connect Pearl to your own account with a third-party AI assistant — for example, connecting Pearl to your Claude account through our Claude connector — we disclose your Pearl data to that assistant at your direction, after you authorize the connection. See the AI/ML section for how this works and whose privacy terms apply.
- Advertising & measurement (non-financial data only). We do not currently use third-party advertising or ad-conversion-measurement tools, and we do not run advertising or retargeting cookies on our Site. If we adopt conversion-measurement technology in the future (for example, a conversions API), it would process only limited online identifiers or hashed contact information — never your financial-account data — we would update this Policy first, and you could opt out (see the U.S. State Disclosures section).
- Legal/regulatory and safety. When required by law or to protect the rights, safety, and security of users, the public, or the Services, including in connection with a corporate transaction (e.g., merger or acquisition), subject to this Policy.
7. SERVICE PROVIDERS & SUB-PROCESSORS
We rely on a limited set of vendors to operate the Services. Each processes information only to provide its service to us, under contractual confidentiality and use restrictions. The principal categories and providers are:
- Cloud, database & infrastructure: Supabase, Amazon Web Services (including AWS Key Management Service for encryption), Cloudflare, and Google Cloud — hosting, storage, security, and serverless functions.
- Financial connectivity: Plaid — read-only linking of the bank accounts you choose to connect.
- AI providers: OpenAI (primary), Anthropic, and xAI — to generate Pearl's coaching and educational features. We send relevant portions of your data to these providers for processing.
- Analytics & crash reporting: Amplitude (product analytics) and Sentry (crash and error reporting).
- Notifications & messaging: Google Firebase Cloud Messaging (push notifications) and Twilio (SMS, including your sign-in verification codes).
- Payments & subscriptions: RevenueCat, which manages subscriptions billed through the Apple App Store and (when available) Google Play; and Stripe, which processes subscription payments made on our Site. Card numbers you enter at checkout go directly to Stripe — we do not receive or store them.
- Market data: Polygon — for market price data. We do not send your personal information to this provider.
8. FINANCIAL DATA CONNECTIVITY (PLAID)
When you choose to link an account, you authorize Pearl Tech Inc., through Plaid, to obtain read-only financial information from your financial institution and provide it to us to deliver the Services. Your bank login credentials go directly to Plaid and your bank through a bank-approved interface — we do not receive or store them. The connection is read-only: Pearl does not move money, initiate transfers, or trade on your accounts; you take every action yourself at your own institution. You can disconnect a linked account at any time in the App's settings; we will stop new retrievals and handle existing data as described in the Retention and Account Deletion sections.
9. AI/ML: HOW WE USE AI, AND TRAINING
- Third-party AI providers. Pearl is built on large language models and other machine-learning systems, including third-party providers (OpenAI, Anthropic, and xAI). To generate features for you, we send relevant portions of your financial data to these providers for processing.
- No training on your data. We use these providers' API/enterprise offerings, under which your inputs and outputs are not used to train their general-purpose models and are retained by the provider only for a limited period (typically up to about 30 days, for trust-and-safety monitoring) before deletion. We do not authorize any provider to use your identifiable data to train its models.
- Improving our own features. We develop, evaluate, and improve Pearl's features and the models that power Pearl using de-identified or aggregated data (see the De-Identification and Account Deletion sections).
- Connected AI assistants (Claude connector). Separately from the AI providers above, you can choose to connect Pearl to your own Claude account (Claude is an AI assistant made by Anthropic) so that Claude can read your Pearl financial data — and, when you ask it to, update items like goals, budgets, and bill settings — inside your own Claude conversations. This connection happens only if you authorize it through a sign-in and consent screen, it is scoped to your data only, and you can disconnect it at any time from the Connectors page in your claude.ai settings. The connector is data access only: it cannot move money, place trades, or take any action at your financial institution. Once your data enters your Claude conversation, it is handled by Anthropic under your own agreement with Anthropic — Anthropic's terms, privacy policy, retention periods, and model-training settings apply, not this Policy. The no-training commitment above covers the providers we send data to on our own behalf; it does not control your own Claude account, so review your Anthropic privacy and training settings before connecting.
- Assistive only; no automated significant decisions. AI output is assistive and may be inaccurate or incomplete; you make your own financial decisions. We do not make decisions about you that produce legal or similarly significant effects solely by automated means.
10. COOKIES, SDKs, AND ONLINE TRACKING
You can manage choices through your device and browser settings. See our Cookie Policy for details.
- Necessary. Authentication, session continuity, security, and fraud prevention.
- Functional. Preferences and settings.
- Analytics. Product usage, performance, and crash diagnostics (e.g., Amplitude, Sentry).
- Advertising/conversion measurement. We do not use advertising or retargeting cookies on our Site, and we do not currently use third-party conversion-measurement tools. If that changes, we will update this Policy and our Cookie Policy first — and we will never use your financial-account data for advertising.
- DNT/GPC. Browser "Do Not Track" has no common standard, so we do not respond to it. We honor the Global Privacy Control (GPC) as an opt-out of "sale"/"sharing" where required by law.
11. SECURITY
We maintain administrative, technical, and physical safeguards designed to protect your information and consistent with the GLBA Safeguards Rule, including:
- Encryption in transit (TLS) for data moving between your device, our systems, and our vendors. Data stored with our cloud providers is encrypted at rest at the infrastructure level.
- Field-level encryption for the most sensitive data. On top of infrastructure encryption, we apply an additional layer of application-level encryption using AWS Key Management Service (KMS) to specific high-sensitivity fields — your financial-account access tokens (the credentials that maintain your Plaid connection, which never expire on their own) and sensitive profile information. This KMS layer protects those designated fields; it is not applied to every data element we store.
- Per-user data isolation enforced at the database layer (row-level security), least-privilege access controls, and access restrictions for internal systems.
- Vendor oversight, logging, and an incident-response process. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. YOUR PRIVACY RIGHTS
Depending on your U.S. state of residence, you may have rights to access/know, correct, delete, and port your personal information; to opt out of "sale," "sharing," and targeted advertising; to limit certain uses of sensitive data (where applicable); and to appeal a decision. We do not discriminate against you for exercising these rights.
Exercising rights: use the in-app privacy controls or email pearl@pearltech.xyz. You can delete your account at any time in the App's settings or by emailing us (see the Account Deletion section). We verify requests using information we already maintain and use verification data only for that purpose. Authorized agents may submit requests where permitted. Note that GLBA-covered NPI we are required to retain may be exempt from certain state deletion rights.
13. DATA RETENTION
We retain personal information for as long as necessary to provide the Services and for the legitimate, legal, and recordkeeping purposes described below. Representative retention periods and criteria:
| Data Type | Typical Retention |
|---|
| Account & profile | Life of account; deleted or de-identified after account deletion |
| Linked-account data (read-only via Plaid) | While connected and for the life of the account; revoked and removed on disconnect/deletion (subject to legal minimums) |
| Usage/telemetry & security logs | For as long as reasonably needed for analytics, security, and fraud prevention |
| Crash/error logs | Typically 90 days (longer for active incidents) |
| Marketing/consent records | For as long as needed to honor your choices, or as required by law |
| Backups/snapshots | Limited rolling window, then overwritten |
| Payment/tax records (if any) | As required by law (often ~7 years in the U.S.) |
| De-identified/aggregated data | May be retained indefinitely (no longer identifies you) |
14. ACCOUNT DELETION & DE-IDENTIFIED DATA
You can delete your account at any time in the App's settings or by emailing us. When you delete your account, we revoke our access to any linked financial accounts (for example, through Plaid), cancel your access to the Services, and delete or de-identify the personal information we hold about you in our active systems — promptly, and in any event within 30 days — except as described below.
As is standard industry practice, we may retain information that has been de-identified or aggregated so that it can no longer reasonably be used to identify you — for example, to understand how Pearl is used, improve our Services, and develop and improve the models that power Pearl. We maintain and use this information only in de-identified or aggregated form, we do not attempt to re-identify it, and we contractually require anyone who receives it to do the same. De-identified and aggregated information is not "personal information" and is not subject to this Privacy Policy.
We may also retain limited information where required for legal, security, fraud-prevention, or recordkeeping purposes — including a record confirming that we processed and completed your deletion request. Copies of your information may remain in routine backups for a limited period before they are overwritten.
15. FUTURE MONEY MOVEMENT & ADVISORY
- Current state. Pearl is read-only: it reads your data to coach, educate, and organize, and it does not move money, place trades, or provide investment advisory services. You take every action yourself.
- Future state. If we add money movement (e.g., transfers) or registered investment advisory features, we will register as required, provide just-in-time notices, obtain any required consents, implement KYC/AML and other controls, and update this Policy and our Terms before those features are offered.
16. DISCLOSURE MAP (GLBA vs. STATE LAW)
- GLBA/NPI (generally exempt from CCPA/CPRA): linked-account balances, transactions, holdings, liabilities; financial insights derived from your data.
- Non-GLBA (state laws apply): Site/app analytics; cookie/SDK identifiers; marketing contact information; advertising/measurement data; de-identified/aggregated reports.
- Profiling: we do not make solely automated decisions about you with legal or similarly significant effects.
- Sensitive data: we do not collect SSN, government ID, precise geolocation, or biometrics; linked financial data is treated as NPI.
17. CHILDREN'S PRIVACY
The Services are intended for adults and are distributed subject to App Store and Google Play age settings. We do not knowingly collect personal information from children under 18. If you believe a child provided personal information, contact pearl@pearltech.xyz and we will promptly delete it.
18. U.S. STATE DISCLOSURES (CA, CO, CT, DE, FL, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA)
- We do NOT sell your personal information, and we never sell your financial-account data.
- We do not use your financial-account data for targeted advertising. For non-financial marketing and measurement data, you may opt out of any "sharing"/targeted advertising through your device ad settings and the Global Privacy Control (GPC), which we honor where required.
- We do not provide your financial information to data brokers, and we are not a data broker.
- California "Shine the Light": we do not share personal information with third parties for their own direct marketing. To inquire, email pearl@pearltech.xyz with the subject "Shine the Light."
- Appeals: if we decline a request, you may appeal by replying to our decision or emailing us with "Appeal" in the subject; we will respond within the time your state requires.
19. DATA PROCESSING LOCATIONS
We process data in the United States through our service providers. Representative locations:
- Supabase — primary application database and backend (U.S. regions).
- Amazon Web Services — storage and key management (U.S. regions); AWS KMS provides the field-level encryption for high-sensitivity fields described in the Security section.
- Cloudflare — global edge network for performance and security.
- Google Cloud — cloud functions and related services (U.S. regions).
- AI providers (OpenAI, Anthropic, xAI) — process the data we send them primarily in the United States.
20. DE-IDENTIFICATION & AGGREGATION COMMITMENT
Where we use de-identified or aggregated information, we take reasonable measures to ensure it cannot reasonably be used to identify you, we publicly commit to maintain and use it only in de-identified or aggregated form, we do not attempt to re-identify it, and we contractually require recipients to comply with the same restrictions. Consistent with applicable law, such information is not treated as personal information.
21. THIRD-PARTY SERVICES & LINKS
The Services rely on and may link to third-party services with their own privacy policies (for example, Plaid, your financial institutions, the App Store/Google Play, Stripe, AI providers, connected AI assistants such as Claude, and analytics providers). Review their policies before enabling integrations or sharing information; we are not responsible for their practices.
22. CHANGES
We may update this Policy. The "Last Updated" date shows the latest revision. For material changes, we will provide prominent notice (for example, in-app or by email). Please review updates carefully.
23. CONTACT
The best way to reach us about this Policy or your privacy rights is by email. The registered business address shown below is provided for identification only and does not accept postal mail.
GLBA MODEL PRIVACY NOTICE (SHORT FORM)
What does Pearl Tech Inc. do with your personal financial information?
WHY? We use your information to deliver the financial coaching, education, and organization features you request, maintain and secure your account, comply with law, and improve our Services. We do NOT sell or rent your financial data, and we do not share it with third parties for their own marketing.
HOW? We share your financial information only as needed to operate the Services — with service providers under contract (such as cloud hosting and AI processing) and with Plaid to maintain the connection you authorize — and as required by law. We do NOT sell your financial data or disclose it to advertisers, marketers, or data brokers.
TO LIMIT SHARING: Use the in-app privacy settings or email pearl@pearltech.xyz.
QUESTIONS? pearl@pearltech.xyz