Last updated: 2026-09-23
This policy explains what personal information Glysten Books handles, and what we as the Provider do and do not see. It forms part of the Terms of Service.
Almost every answer below depends on which deployment you have:
The Provider of Glysten Books, as identified in the Terms of Service. Contact details are in Section 14.
Our public website describes the product. It has no forms and collects nothing from you: it sets no cookies, runs no analytics, advertising or tracking, and makes no requests to anyone else's servers — its fonts are served from our own.
Glysten Books sets one cookie: a session cookie that keeps you signed in. It is HttpOnly and SameSite=Strict, it is not readable by scripts, and it is not sent to other sites. It is strictly necessary to use the application.
We set no advertising, analytics, or tracking cookies anywhere, so there is nothing here to opt out of.
Whether this reaches us depends on your deployment (Section 1). In either case, a Glysten Books installation stores:
| What | Why |
|---|---|
| Username (an email address) and display name | To identify who is signed in and label their entries |
| A hash of the password — never the password itself | To sign you in |
| Two-factor secrets and recovery codes, if enabled | To protect the account |
| Role, and per-entity access grants | To decide what each person may see |
| Session records: a token hash, IP address, browser user-agent, timestamps | To keep you signed in and let you end a session |
| Known sign-in locations: IP addresses, when first and last seen, any label | To recognise a familiar device and hold an unfamiliar one for approval |
| Held sign-in attempts: IP address, browser user-agent, time, outcome | To let an account owner approve or refuse an unrecognised sign-in |
| Failed sign-in counts and lockout times | To slow down password guessing |
| An audit log of actions taken in the books | So an account owner can see who changed what |
| Each acceptance of these terms: which revision, when, IP address, browser user-agent | To show who agreed to which terms |
| Your choice about letting the Help assistant read the books, and when you made it | So it reads them only if you said it may |
| How many questions you asked the Help assistant each day, and what they cost | To apply usage limits |
| Keys you create for AI apps — stored only as a hash — and when each was last used | So you can see every connection and revoke it |
Glysten Books sends no usage analytics or telemetry to us in either deployment. What its AI features send, and to whom, is in Sections 8 and 11.
This one deserves saying plainly. Your books can contain personal information about people who are not Glysten Books users and have never heard of us — customers, vendors, tenants, employees, partners and shareholders. Depending on what you use, that can include names, addresses, bank transaction detail, receipts and statements you attach, and taxpayer identification numbers, including Social Security numbers — for partners and shareholders if you produce Schedules K-1, and for the people you pay if you record W-9s to prepare Forms 1099.
Taxpayer identification numbers from W-9s are held apart from the rest of the books, shown on screen only as their last four digits, and used in full only to build a 1099 file. They are never sent to an AI provider or to an AI app you connect. A record of each 1099 file Glysten Books prepares is kept permanently, as a tax record.
Given what this data is, keep the access grants in Glysten Books narrow, and treat an export of your books as the sensitive document it is.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use your books to train artificial-intelligence or machine-learning models. We have never done so.
A current list of subprocessors is available on request.
For a Hosted Deployment, in the United States. We will not move Your Data outside the United States without notice to you.
Glysten Books automates bookkeeping, so it is fair to ask what it decides by itself.
Nothing in Glysten Books posts to your books, files anything, or moves money on its own — not the rules, and not the AI. Every one of those is a person clicking a button. We do not make automated decisions that produce legal or similarly significant effects about anyone — no credit scoring, no eligibility decisions, no profiling for advertising — and we do not use your books to train artificial-intelligence or machine-learning models. The Terms of Service, Section 13, set out the AI features in full.
For a Hosted Deployment we use commercially reasonable safeguards, including encryption in transit and at rest, access controls, and limiting staff access to those who need it. Passwords are stored only as hashes. Two-factor authentication is available and we recommend it.
No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you without undue delay, and notify regulators where the law requires.
For a Self-Managed Deployment the security of the machine, the database and the backups is yours. Glysten Books gives you the tools — hashed passwords, two-factor, held sign-ins, per-entity access, an audit log — but it cannot secure a server you have left open.
Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, to limit how we use it, and not to be discriminated against for exercising any of those rights. California residents have these rights under the CCPA as amended by the CPRA; several other states provide similar ones.
You may also withdraw consent where we relied on it, and complain to a data protection authority in the place you live if you think we have handled your information badly. You do not have to come to us first, though we would rather hear from you and fix it.
We do not sell or share personal information for advertising, so there is no opt-out to offer.
To exercise a right, contact us at Section 14. We will verify your identity before we act, and respond within the time the law allows.
If your information is in someone else's books — you are a vendor, tenant, customer or partner of a Glysten Books customer — then that customer, not us, controls it, and you should contact them. If you contact us about a Hosted Deployment we will pass your request on to them. In a Self-Managed Deployment we have no access to their books and cannot help beyond telling you so.
Privacy questions and rights requests: [ADD CONTACT EMAIL AND POSTAL ADDRESS]
Glysten Books is business software and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, tell us and we will delete it.
We may update this policy. For material changes we will give notice through the product or by email before they take effect, and the "Last updated" date above tells you which revision this is. Prior revisions are available on request.