← Glysten Books

Glysten Books Privacy Policy

Last updated: 2026-09-23


1. Scope, and the one thing that decides everything else

This policy explains what personal information Glysten Books handles, and what we as the Provider do and do not see. It forms part of the Terms of Service.

Almost every answer below depends on which deployment you have:

2. Who we are

The Provider of Glysten Books, as identified in the Terms of Service. Contact details are in Section 14.

3. Our website

Our public website describes the product. It has no forms and collects nothing from you: it sets no cookies, runs no analytics, advertising or tracking, and makes no requests to anyone else's servers — its fonts are served from our own.

4. Cookies

Glysten Books sets one cookie: a session cookie that keeps you signed in. It is HttpOnly and SameSite=Strict, it is not readable by scripts, and it is not sent to other sites. It is strictly necessary to use the application.

We set no advertising, analytics, or tracking cookies anywhere, so there is nothing here to opt out of.

5. What Glysten Books stores about the people who use it

Whether this reaches us depends on your deployment (Section 1). In either case, a Glysten Books installation stores:

WhatWhy
Username (an email address) and display nameTo identify who is signed in and label their entries
A hash of the password — never the password itselfTo sign you in
Two-factor secrets and recovery codes, if enabledTo protect the account
Role, and per-entity access grantsTo decide what each person may see
Session records: a token hash, IP address, browser user-agent, timestampsTo keep you signed in and let you end a session
Known sign-in locations: IP addresses, when first and last seen, any labelTo recognise a familiar device and hold an unfamiliar one for approval
Held sign-in attempts: IP address, browser user-agent, time, outcomeTo let an account owner approve or refuse an unrecognised sign-in
Failed sign-in counts and lockout timesTo slow down password guessing
An audit log of actions taken in the booksSo an account owner can see who changed what
Each acceptance of these terms: which revision, when, IP address, browser user-agentTo show who agreed to which terms
Your choice about letting the Help assistant read the books, and when you made itSo it reads them only if you said it may
How many questions you asked the Help assistant each day, and what they costTo apply usage limits
Keys you create for AI apps — stored only as a hash — and when each was last usedSo you can see every connection and revoke it

Glysten Books sends no usage analytics or telemetry to us in either deployment. What its AI features send, and to whom, is in Sections 8 and 11.

6. Personal information about other people, inside your books

This one deserves saying plainly. Your books can contain personal information about people who are not Glysten Books users and have never heard of us — customers, vendors, tenants, employees, partners and shareholders. Depending on what you use, that can include names, addresses, bank transaction detail, receipts and statements you attach, and taxpayer identification numbers, including Social Security numbers — for partners and shareholders if you produce Schedules K-1, and for the people you pay if you record W-9s to prepare Forms 1099.

Taxpayer identification numbers from W-9s are held apart from the rest of the books, shown on screen only as their last four digits, and used in full only to build a 1099 file. They are never sent to an AI provider or to an AI app you connect. A record of each 1099 file Glysten Books prepares is kept permanently, as a tax record.

Given what this data is, keep the access grants in Glysten Books narrow, and treat an export of your books as the sensitive document it is.

7. How we use information, and why

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use your books to train artificial-intelligence or machine-learning models. We have never done so.

8. Who else is involved

A current list of subprocessors is available on request.

9. Where information is held

For a Hosted Deployment, in the United States. We will not move Your Data outside the United States without notice to you.

10. How long we keep it

11. Automated decisions, and where a person is still required

Glysten Books automates bookkeeping, so it is fair to ask what it decides by itself.

Nothing in Glysten Books posts to your books, files anything, or moves money on its own — not the rules, and not the AI. Every one of those is a person clicking a button. We do not make automated decisions that produce legal or similarly significant effects about anyone — no credit scoring, no eligibility decisions, no profiling for advertising — and we do not use your books to train artificial-intelligence or machine-learning models. The Terms of Service, Section 13, set out the AI features in full.

12. Security

For a Hosted Deployment we use commercially reasonable safeguards, including encryption in transit and at rest, access controls, and limiting staff access to those who need it. Passwords are stored only as hashes. Two-factor authentication is available and we recommend it.

No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you without undue delay, and notify regulators where the law requires.

For a Self-Managed Deployment the security of the machine, the database and the backups is yours. Glysten Books gives you the tools — hashed passwords, two-factor, held sign-ins, per-entity access, an audit log — but it cannot secure a server you have left open.

13. Your rights

Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, to limit how we use it, and not to be discriminated against for exercising any of those rights. California residents have these rights under the CCPA as amended by the CPRA; several other states provide similar ones.

You may also withdraw consent where we relied on it, and complain to a data protection authority in the place you live if you think we have handled your information badly. You do not have to come to us first, though we would rather hear from you and fix it.

We do not sell or share personal information for advertising, so there is no opt-out to offer.

To exercise a right, contact us at Section 14. We will verify your identity before we act, and respond within the time the law allows.

If your information is in someone else's books — you are a vendor, tenant, customer or partner of a Glysten Books customer — then that customer, not us, controls it, and you should contact them. If you contact us about a Hosted Deployment we will pass your request on to them. In a Self-Managed Deployment we have no access to their books and cannot help beyond telling you so.

14. Contact

Privacy questions and rights requests: [ADD CONTACT EMAIL AND POSTAL ADDRESS]

15. Children

Glysten Books is business software and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, tell us and we will delete it.

16. Changes

We may update this policy. For material changes we will give notice through the product or by email before they take effect, and the "Last updated" date above tells you which revision this is. Prior revisions are available on request.