Privacy & Trust

Your data has one job:
working for you.

We use it to map your benefits, match your transactions, and nudge you before money expires. Never sold. Never used for ads. Shared only with the partners that run Grail — each getting the minimum it needs.

Effective: June 12, 2026 Last updated: September 24, 2026 Grail

Our standing commitment How we use your data changes on this page before it changes in the product.

The facts

How Grail works with your data — today

Plain facts about where AI sits in Grail right now — what it reads today, and what it doesn't.

  • Most of Grail's AI reads card data, not your data. The heavy lifting happens on issuer material — benefit guides, terms pages, fine print — building the catalog of what every card offers. That work reads issuer pages, not your accounts.
  • If you ever connect a bank, transactions are matched by Grail's own deterministic engine. Bank connection is optional and is not offered in the app at launch; Grail works from the names of the cards you carry and what you tell it. When a connection is available and you choose it, activity syncs in via Plaid and gets matched to benefits by rules Grail wrote — code, not a model. There is no AI model in that path.
  • AI processes the content you send to Grail. Forward an email — a gift card, a receipt, a trial confirmation — or text a question, and AI reads that content to do the job you asked.
  • All AI processing happens via API — and API data is not used to train the providers' models.

The word "today" is deliberate. Grail keeps shipping, and future features may put AI to work in more places. When that happens, you'll read it here first: how we use your data changes on this page before it changes in the product.

The partners

Who we work with — and why

Grail doesn't run alone. A small set of partners powers the product, and each one gets the minimum it needs to do its job. Here's the roster:

Partner What it does
PlaidRead-only bank connection, optional and not offered in the app at launch. Grail never sees or stores your bank credentials.
ClerkSecure sign-in.
SupabaseEncrypted data storage.
TwilioThe texts Grail sends and receives.
OpenAIAI that reads card catalogs and processes content you send — via API, not used to train models.
CloudflareHosting and email routing.
RenderBackend hosting.
StripeSubscription payments. Your full card number goes to Stripe, never to Grail.
The feature

Bring your own AI

Your benefits shouldn't be locked inside our app. Grail provides an MCP server — the open standard that lets AI assistants connect to outside tools — so you can plug Grail into the assistant you already use.

Connect Claude or ChatGPT and ask it to check your benefits: which card to use tonight, what's expiring this month. Your assistant reads your Grail data under your own account and permission — and you can revoke that access at any time.

Set-up guide: Connect Grail to your AI.

The policy

The legal details

Everything above, in policy form — what we collect, how we use it, the rights you hold, and how to reach us. This is the full Privacy Policy of Grail.

01

Overview

Grail ("we," "us," or "our") operates the Grail app and website at heygrail.ai. We built Grail to help you find money you've already earned — expiring credits, forgotten gift cards, pending refunds, and unwanted subscriptions.

This Privacy Policy explains what personal information we collect, how we use it, and your choices. By using Grail, you agree to the practices described here.

🔒
The short version: We access your financial data only to provide Grail's features. We never sell your personal information. Bank connectivity via Plaid (read-only — we can never move money on your behalf) is not available in this version of Grail.
02

Information We Collect

We collect information you provide directly, information from your connected financial accounts, and standard technical data from your use of the app.

Category What This Includes How We Get It
Account Info Phone number (verified with a one-time text code); name, if you give one; email address, only if you sign up with email or add one later (for example, to get the weekly email); password, only if you choose password sign-in — stored hashed by our sign-in provider, Clerk, never by Grail You provide it at sign-up or later in Settings
Financial Data Account balances, transaction history, recurring charges Via Plaid, with your consent — not available in this version of Grail
Card & Benefits Credit card benefits, expiring credits, gift card balances Derived from your transactions + your input
Usage Data Features used, pages viewed, session timestamps Automatically collected
Device Info Browser type, OS, IP address, device identifiers Automatically collected
Communications Support emails, feedback you submit You provide it
Forwarded Email Content Receipts, offers, and benefit emails you choose to forward to your personal Grail address, including their text content You forward them to us

We do not collect Social Security numbers, government-issued ID numbers, or full payment card numbers.

03

How We Use Your Information

We use your information only to operate and improve Grail. Specifically:

  • Provide the service — Detect expiring credits, track refunds, identify forgotten charges and gift cards, and surface alerts.
  • Personalize your experience — Show your net worth, suggest which card to use, and tailor recommendations to your accounts.
  • Send notifications — Alert you to time-sensitive items like expiring credits or overdue refunds. You can adjust these in Settings.
  • Improve Grail — Analyze usage patterns in aggregate (never linked to individual identities) to improve features.
  • Communicate with you — Respond to support requests and send product updates. You can unsubscribe from marketing at any time.
  • Prevent fraud and abuse — Detect unauthorized access and comply with legal obligations.

We do not use your financial data for advertising, sell it to data brokers, or share it with third parties for their own marketing purposes.

04

Plaid & Financial Data

⏳
Not available in this version of Grail. Bank account connection is not part of the current release. This section describes how it will work if and when we turn it on — you'll see it in the product, and this page will update, before that happens.

When bank connection ships, Grail will use Plaid Technologies, Inc. to connect your bank accounts. Plaid is a trusted financial data network used by Venmo, Robinhood, Coinbase, and thousands of other apps.

🏦
Read-only access only. Grail will have no ability to move, transfer, or withdraw funds from your accounts. We will access transaction history and balances to power Grail's features — nothing else.

When you connect a financial account through Plaid:

  • You will authenticate directly with your bank — Grail will never see your banking username or password.
  • Plaid will transmit your financial data to us using bank-level encryption.
  • Your data will be governed by both this Privacy Policy and Plaid's End User Privacy Policy.
  • You will be able to revoke Plaid access at any time — in Grail under Settings → Connected Accounts, or directly at my.plaid.com.

Financial data retrieved via Plaid will be encrypted at rest (AES-256) and in transit (TLS 1.2+) at all times — the same standard Grail already applies to your account data today.

05

SMS & Text Messaging

When you opt in to receive text messages from Grail, you agree to receive recurring automated benefit reminders and account notifications.

  • Opt-in: You must explicitly opt in inside your signed-in account, on the Notification Settings screen. Consent is given by tapping a button labelled "Turn On Texts", with the full disclosure shown directly above it — there is no pre-selected checkbox anywhere in the flow, and texts stay off until you tap. If your mobile number was already verified when you created your account, that number is shown to you and the tap is all that is required. Otherwise you enter your own number and then confirm it from that device — either by sending a text (such as "START") to Grail's number, or by entering a one-time code we send you. We only send texts to numbers confirmed one of these two ways.
  • Consent language: The disclosure shown directly above the "Turn On Texts" button reads: "By tapping Turn On Texts you agree to receive account & benefit-reminder texts from Grail at this number. Consent isn't a condition of use. Msg frequency varies; Msg & data rates may apply. Reply STOP to cancel, HELP for help." Tapping that button is the affirmative consent act, not a checkbox. Numbers verified through Clerk at sign-up skip the confirmation-text step described above; all other numbers must confirm possession by sending START or VERIFY (or entering the one-time code) before any message is sent.
  • Message Types: We send recurring benefit-reminder texts and account-related notifications.
  • Privacy of Opt-in Data: Your mobile phone number, SMS consent, and text messaging opt-in data will never be sold, shared, or disclosed to third parties for marketing or promotional purposes.
  • Opt-out & Help: You can cancel the SMS service at any time by replying "STOP" to any text message from us. For assistance, reply "HELP". Message and data rates may apply.
06

Sharing Your Information

We do not sell your personal information. We share data only in the following limited circumstances:

  • Service providers — Trusted vendors who help us operate Grail (e.g., cloud hosting, email delivery, analytics). These providers are contractually required to protect your data and may not use it for their own purposes. For more detail on key vendors we work with, see Who we work with above.
  • Plaid — To facilitate bank account connectivity, once that feature is available (see Plaid & Financial Data above). Not active in this version of Grail.
  • Household members (if you choose) — If you invite a household member, they can see shared accounts and joint balances. Private accounts remain hidden. You control what is shared.
  • Legal requirements — If required by law, court order, or to protect the rights and safety of Grail or others, we may disclose information as legally required.
  • Business transfers — In the event of a merger, acquisition, or sale of all or substantially all assets, your data may be transferred. We will notify you via email before your data is transferred and becomes subject to a different privacy policy.
07

Data Retention

We retain your personal information for as long as your account is active or as needed to provide the service. Specifically:

  • Account data is retained for the duration of your account and deleted within 30 days of account closure.
  • Financial transaction data from Plaid, once bank connection is available, will be retained for up to 7 years following account closure to comply with applicable financial regulations. This does not apply today — bank connection is not part of the current version of Grail.
  • Usage and analytics data is retained for up to 24 months in identifiable form, after which it is anonymized or deleted.

You may request deletion of your account and associated data at any time by emailing support@withsavvy.ai. We will process deletion requests within 30 days, subject to any legal retention requirements.

08

Security

We take security seriously. Measures we have in place include:

  • All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • Multi-factor authentication available on every account
  • Role-based access controls — only authorized employees can access production systems
  • Automated dependency and code-security scanning on every change, plus secret-scanning across our repositories
  • Bank-level connectivity via Plaid, when that feature is available (your banking credentials will never be stored by Grail)
⚠️
No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable means to protect your information, we cannot guarantee absolute security. Please notify us immediately at security@withsavvy.ai if you suspect any unauthorized access.
09

Your Rights

Depending on where you live, you may have the following rights regarding your personal information. To exercise any of these rights, email us at support@withsavvy.ai.

👁️ Access

Request a copy of the personal information we hold about you.

✏️ Correction

Ask us to correct inaccurate or incomplete information.

🗑️ Deletion

Request deletion of your personal data, subject to legal retention requirements.

📦 Portability

Receive your data in a structured, machine-readable format.

🚫 Opt-Out

Opt out of marketing communications at any time via unsubscribe link or email.

🔌 Revoke Access

Disconnect bank accounts and revoke Plaid access at any time in Settings, once bank connection is available.

California residents have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of sale of personal information. We do not sell personal information. To submit a verifiable consumer request, email support@withsavvy.ai.

10

EEA & UK Users (GDPR)

If you are located in the European Economic Area or the United Kingdom, the GDPR (and UK GDPR) gives you additional rights, and we process your personal data only where we have a legal basis to do so:

  • Contract: most processing — mapping your benefits, matching transactions, sending the reminders you signed up for — is necessary to provide the service you asked us for.
  • Consent: connecting a bank account via Plaid (not available in this version of Grail), turning on text messages, and forwarding emails to Grail each happen only after your explicit opt-in, which you can withdraw at any time.
  • Legitimate interests: securing the service, preventing abuse, and understanding aggregate usage — always balanced against your rights.

In addition to the rights listed above, you may object to processing based on legitimate interests, request restriction of processing, and lodge a complaint with your local supervisory authority. Grail is operated from the United States, and your data is stored and processed there; where data is transferred from the EEA or UK we rely on our processors' standard contractual clauses and equivalent safeguards.

To exercise any of these rights, email support@withsavvy.ai — we respond to verified requests within 30 days.

11

Children's Privacy

Grail is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at support@withsavvy.ai and we will delete it promptly.

12

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email if you have given us an email address, and otherwise by a notice in the app, and update the "Last updated" date at the top of this page at least 30 days before the changes take effect.

And the standing commitment from the top of this page applies here too: how we use your data changes on this page before it changes in the product.

Your continued use of Grail after any changes constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you may close your account.

13

Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:

  • Email: support@withsavvy.ai
  • Security issues: security@withsavvy.ai

We will respond to all privacy-related requests within 5 business days.