Privacy Policy
Last updated: March 21, 2026
Herbert (“we,” “our,” or “us”) is designed to help individuals and businesses organize, understand, and operate more effectively. We are committed to protecting your privacy and handling your data with care, restraint, and transparency.
1. Our Data Philosophy
Herbert is built on a principle of minimal intervention and maximum user autonomy.
We collect and process data only when it provides clear, direct value to the user. We minimize unnecessary data exposure and avoid centralized data collection where possible.
We do not and will never sell user personal or financial data.
2. Information We Collect
a. Account Information
- Name, email address, login credentials
- Business or organization details (if applicable)
b. Usage & Activity Data
- Interactions with Herbert features
- System logs and performance data
- Audit trails of user actions for operational visibility
c. Financial & Business Data
If you connect third-party services (e.g., QuickBooks), we may access:
- Transactions, invoices, and payment records
- Financial account metadata
Access is granted only with your explicit authorization.
d. Device & Technical Data
- IP address
- Browser and device information
3. How We Use Your Information
We use your data to:
- Provide and improve Herbert's functionality
- Enable integrations (e.g., QuickBooks API)
- Organize, analyze, and present your data
- Personalize your experience
- Maintain security and prevent fraud
- Maintain audit logs for system integrity and operational insight
- Communicate important updates or support responses
We do not use your data for unrelated advertising or resale.
4. AI Usage & Human-in-the-Loop Design
Herbert may use AI systems to assist with:
- Data organization
- Insights and recommendations
- Workflow suggestions
Herbert is designed to assist, not replace, human decision-making.
- Users retain full control over all actions
- Any automation is user-authorized
- AI outputs may not always be accurate
Herbert does not initiate financial transactions or execute critical actions without user involvement.
5. Third-Party Integrations
Herbert integrates with third-party services such as QuickBooks.
When you connect an integration:
- You authorize Herbert to access specific data required for functionality
- We request only the minimum permissions necessary
- Authentication is handled via secure OAuth flows
Herbert does not store third-party service credentials (e.g., QuickBooks login details).
You may revoke integration access at any time through your account settings or directly through the third-party provider.
We are not responsible for third-party privacy practices.
6. Data Sharing
We may share data only:
- With trusted service providers (e.g., hosting via Supabase, infrastructure, analytics)
- To comply with legal obligations
- To protect rights, safety, and system integrity
All providers are required to safeguard your data.
7. Data Storage & Security
Herbert stores data using secure infrastructure providers, including Supabase.
We implement industry-standard safeguards, including:
- Encryption in transit (HTTPS)
- Encryption of sensitive tokens and credentials at rest
- Secure authentication systems
- Role-based access controls
Access to user data is restricted to authorized personnel and only when necessary for system operation, maintenance, or support.
While no system is completely secure, we take reasonable measures to protect your information.
8. Data Retention
We retain data only as long as necessary to:
- Provide Herbert's services
- Meet legal and regulatory requirements
- Maintain system integrity and audit trails
- Resolve disputes
You may request deletion of your data at any time.
We respond to verified data deletion requests within a reasonable timeframe (typically within 30 days).
9. Data Portability
We aim to provide users with the ability to export their data in a structured, commonly used format where feasible.
10. Your Rights
You may:
- Access your data
- Request correction or deletion
- Disconnect integrations
- Request export of your data
To exercise these rights, contact: herbert@herbert.wiki
11. Cookies & Tracking
We use minimal cookies or similar technologies to:
- Maintain secure sessions
- Improve system performance
We do not use invasive cross-site tracking or sell behavioral data.
12. Incident Response
In the event of a data breach affecting user information, we will take reasonable steps to notify affected users in accordance with applicable laws.
13. Data Location
Herbert is operated in the United States. By using the service, you understand that your data may be processed and stored in the United States.
14. Age Restrictions
Herbert is intended only for individuals 21 years of age or older. We do not knowingly collect data from individuals under 21.
15. Changes to This Policy
We may update this Privacy Policy periodically. Continued use of Herbert constitutes acceptance of updates.
16. Contact
Herbert herbert@herbert.wiki