Privacy Notice
Holy Metal Solutions, LLC · SkaiPilot Platform · Wren Consumer Product · Effective June 23, 2026
1. About This Privacy Notice
This Privacy Notice describes how Holy Metal Solutions, LLC ("Holy Metal Solutions," "we," "us," or "our"), operating the SkaiPilot platform and Wren consumer product, collects, uses, shares, and protects information about you when you use Wren and related services (the "Services").
Because Wren connects to your financial accounts and works with personal financial information, we are subject to the Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule. This notice satisfies the GLBA privacy disclosure requirement.
By using the Services, you acknowledge that you have read and understood this Privacy Notice.
2. Information We Collect
Information You Provide
- Name, email address, state of residence, and contact details
- Goals, preferences, and settings entered in the app
- Communications and support requests you send us
Financial Information via Plaid
When you connect a financial account through Plaid (our account aggregation partner), we receive:
- Account balances and account numbers (last four digits only)
- Transaction history (up to 24 months)
- Income and payroll data (where you authorize it)
- Account type and financial institution information
We access this data only with your explicit permission and only for the purpose of providing the Services.
Usage Information
- Log data: IP address, device type, browser, operating system, and timestamps
- Feature usage and in-app interaction data
- Crash reports and diagnostic information
Insurance Information
If you use Wren's insurance features, we collect information needed to generate coverage recommendations, including household composition, existing policy details, and coverage preferences. This information is handled in accordance with applicable state insurance market conduct regulations.
3. How We Use Your Information
We use your information to:
- Provide, operate, and improve the Services
- Connect financial accounts and analyze household financial data
- Generate Protection Scores and surface opportunity findings
- Execute the financial actions you explicitly approve
- Send you notifications, alerts, and service communications
- Conduct insurance reviews and facilitate policy placement in licensed states
- Comply with applicable legal and regulatory obligations
- Detect and prevent fraud, security incidents, and abuse
We do not use your financial information for targeted advertising. We do not sell your personal information.
4. How We Share Your Information
As required by the Gramm-Leach-Bliley Act, here is a plain-language summary of our sharing practices:
| Does Holy Metal Solutions share? | Can you limit? |
|---|---|
| For everyday business purposes — processing transactions, providing the Services, protecting against fraud | No |
| With service providers that perform services on our behalf (Plaid, Anthropic, hosting infrastructure) | No |
| With insurance partners to facilitate policy placement — only with your prior approval | Yes — you control via approval |
| For our marketing of our own products to you | Yes — opt out anytime |
| For nonaffiliates to market their products to you | We do not do this |
| For joint marketing with other financial companies | We do not do this |
Service Providers
We share data with vendors who help us operate the Services — including Plaid (account aggregation), Anthropic (AI processing), cloud infrastructure providers, and payment processors. All service providers are contractually required to protect your data and use it only for services provided to us.
Legal Requirements
We may disclose information when required by law, court order, or regulatory inquiry, or to protect the rights, property, or safety of Holy Metal Solutions, our users, or the public.
Business Transfers
In connection with a merger, acquisition, or sale of assets, user information may be transferred. We will notify you and you will retain rights under applicable law.
5. How We Protect Your Information
We maintain a written information security program consistent with the FTC Safeguards Rule (16 C.F.R. Part 314) and GLBA requirements. Key safeguards include:
- Encryption of financial data in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication for account access
- Role-based access controls limiting employee access to personal data
- Regular security assessments and vulnerability monitoring
- Documented incident response procedures
No method of transmission or storage is 100% secure. We will notify you of a security incident affecting your personal information as required by applicable law.
6. Your Privacy Rights
Request a summary of the personal information we hold about you.
Request correction of inaccurate personal information.
Request deletion of your account and associated data, subject to legal retention requirements.
Request your data in a machine-readable format where feasible.
Opt out of promotional email communications at any time via the unsubscribe link in any marketing email or by contacting us.
To exercise any of these rights, contact us at info@skaipilot.ai. We will respond within 30 days.
7. State-Specific Rights
California Residents (CCPA / CPRA)
California residents have the right to: know what categories and specific pieces of personal information we have collected; request deletion; request correction; opt out of sale or sharing for cross-context behavioral advertising (we do not sell or share for this purpose); and be free from discrimination for exercising privacy rights. To submit a California privacy request, contact info@skaipilot.ai.
Ohio Residents
Ohio residents have rights regarding personal information under Ohio Revised Code § 1347. We honor reasonable requests for access and correction as described in Section 6 above.
8. Insurance Information
Information you provide in connection with insurance reviews is subject to additional protections under applicable state insurance laws. This information is used solely to evaluate coverage options and, with your approval, to facilitate policy placement through our licensed agent of record. It is not used for any other purpose.
Insurance commissions earned by Bishop & Associates Agency, LLC (the licensed agent of record) on placed policies are disclosed to you before any policy decision, consistent with NAIC model market conduct standards and applicable state producer compensation disclosure requirements.
9. AI and Automated Processing
Wren uses artificial intelligence to analyze your financial data, generate Protection Scores, and surface opportunity findings. You will be informed when you are interacting with an automated system. AI-generated outputs are observations based on available data — they are not advice, and not guaranteed to be complete or error-free.
Wren never executes any action on your accounts without your explicit approval. We do not make legally significant automated decisions about you (such as credit decisions) without human review.
10. Data Retention
We retain your account data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. Financial transaction data may be retained for up to seven years as required by applicable law and regulation.
You may request deletion of your account at any time by contacting info@skaipilot.ai.
11. Children's Privacy
The Services are not directed to children under 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a child under 18, contact us at info@skaipilot.ai and we will promptly delete it.
12. Changes to This Notice
We may update this Privacy Notice from time to time. We will notify you of material changes by posting the updated notice in the app and, where required by law, by providing direct notice. The "Effective" date at the top of this notice reflects the most recent revision. Continued use of the Services after a change takes effect constitutes acceptance of the revised notice.