1. What OpenBooks reads
To do the work, OpenBooks reads only what you connect or hand it:
- Bank transactions and balances, through a read-only aggregation provider.
- Receipts, invoices, and other evidence you upload or point it to.
- Accounting exports and prior filings you provide or that are already public.
- The names, roles, and emails of the people allowed to approve work.
2. What OpenBooks never does
- Never moves money — no ACH, wire, or card charge exists in the product.
- Never sells or licenses your data, and never shares it with data brokers.
- Never trains foundation models on your private data.
- Never stores your bank credentials — connections use a read-only token held by the aggregation provider.
- Never silently modifies a sealed record — corrections are visible amendments on an append-only ledger.
3. Where your data lives
Your data is stored in managed PostgreSQL (Supabase) and served through Vercel, in United States regions. It is encrypted in transit with TLS 1.3 and encrypted at rest with AES-256 by those providers. Connection tokens receive a second layer of AES-256-GCM encryption in our own code before they reach the database. The database is multi-tenant, with row-level security defined on every table and access checked on every request.
4. Who can access it
Your authorized users see your data; that is the default. OpenBooks staff have no routine access to your live data. If you open a support case and ask us to look, that access is time-bounded and logged. We do not use offshore support for access to your live data.
5. Retention and deletion
We retain your data for the life of your account, and for up to seven years afterward where needed for financial-audit and recordkeeping purposes (an industry standard). On a deletion request we remove your data within 30 days, except for records we are required to retain by law for the minimum period required.
6. Your rights
We support the rights of access, deletion, and portability under the GDPR, and equivalent rights under the CCPA, including the right not to have personal information sold (we do not sell it). To exercise a right, contact us and we will verify and respond within the applicable timeframe. HIPAA does not apply to this service, and we do not process payment cards, so PCI DSS does not apply.
7. Cookies and analytics
We use only the essential cookies needed to keep you signed in. We do not use cross-site tracking, and we do not load third-party analytics without your opt-in.
8. Sub-processors
We rely on service providers who process data on our behalf under their own terms: Supabase (database), Vercel (hosting), and, where you connect an account, a bank-aggregation provider (Plaid, Stripe Financial Connections, or SimpleFIN, as applicable). We will keep this list current as our processors change.
9. Security and breach notification
Our security practices are described on our security page. We hold no SOC 2 certification today; a SOC 2 Type II program is planned but not yet in place, and we will not claim it until it is. If a breach affects your data, we will notify you without undue delay and, where the GDPR applies, within 72 hours of becoming aware. Report a concern to security@openbooks.fyi.
10. Changes and contact
We may update this policy; material changes will be posted here with a new date. Questions: hello@openbooks.fyi.
Draft prepared by OpenBooks. Not legal advice. Have this reviewed and finalized by a licensed attorney before relying on it with any customer. Last updated July 18, 2026.