PRIVACY

Privacy Policy

This policy explains the personal and financial-record data processed when you use CloseBook.

Last updated: 29 July 2026

1. Scope

This Privacy Policy applies to CloseBook at closebook.online, including guest use, registered accounts, authentication emails, synchronized books and support requests.

2. Information processed

Guest mode

Guest book content is stored in the browser on the device being used. CloseBook may also record limited technical usage metadata such as a randomly generated guest-browser identifier, a random local book identifier, visit and activity timestamps, page path and feature-event names. This metadata can show that a guest book was created, reviewed, reconciled, closed, reopened or exported, but it does not include the book title, currency amounts, transaction descriptions, receipts, custodian name or reconciliation explanation.

Registered accounts

CloseBook processes the account email address, first and last name, password hash and salt, account status, plan and limits, email-verification records, password-reset records, session records, book data, audit events and basic usage events.

Book content

Book data may include titles, references, responsible-person names, currencies, starting balances, Money in and Money out transactions, categories, invoice numbers, documentation exceptions, reconciliation values, explanations and audit history.

Authorized CloseBook administrators may access account or book information only according to their assigned role for support, security, synchronization investigation, financial-record review or other documented administrative purposes. Access to full financial book content requires a recorded reason.

Administrative access and sensitive exports may generate security and access records containing the administrator, target account or book, time, reason, related support reference, IP address, browser user agent and request identifier. Passwords, authentication tokens and session cookies are not intentionally stored in these logs.

CloseBook does not currently accept or store invoice, receipt or other document files.

3. How information is used

4. Service providers

CloseBook uses Cloudflare infrastructure for website delivery, server functions and database storage. Resend is used to deliver verification, password-reset and password-change confirmation email. Google may be used for account sign-in and, when enabled by the administrator, Google Analytics may process website-usage information. These providers process information as needed to deliver their services.

5. Analytics, online presence, cookies and browser storage

CloseBook uses first-party, privacy-safe product analytics to understand service usage. It may record a random analytics-session identifier, a random guest-browser identifier, signed-in or guest status, approximate country code supplied by Cloudflare, traffic source and referring domain, campaign parameters, page paths, general device and browser family, page-view timestamps and feature milestones. A visitor may appear as “online” in the administrator dashboard when the last activity heartbeat was received within approximately 90 seconds.

CloseBook does not store the visitor's full IP address in this analytics system and does not collect book titles, currency amounts, transaction descriptions, receipts, custodian names, notes or reconciliation explanations for analytics. Raw analytics sessions and page views are retained for up to approximately 90 days and are periodically removed. Browsers that send Global Privacy Control or Do Not Track are excluded from this first-party analytics client.

When Google Analytics is enabled, CloseBook may also send page-view and technical usage information such as the page visited, browser and device characteristics, approximate region and interaction timing to Google Analytics. CloseBook does not send book transaction content to Google Analytics through the site integration.

Registered sessions use a secure, HTTP-only session cookie. Guest books, analytics identifiers and some interface preferences are stored in browser storage. Google Analytics may use cookies or similar identifiers when the integration is enabled. Clearing browser data may permanently remove guest books and reset anonymous analytics identifiers.

6. Retention

Registered-account information is retained while the account remains active and as reasonably necessary for security, support and legal obligations. Expired sessions and temporary verification/reset records may be periodically removed. Guest book content remains on the user's device until the browser removes it or the user clears it. Limited anonymous usage metadata described above may remain in CloseBook administrative records for product health, security and aggregate usage analysis.

7. Sharing

CloseBook does not sell personal data. Information may be disclosed to infrastructure providers, when required by law, to protect the service or users, or during a legitimate business transfer subject to appropriate safeguards.

8. User choices and requests

Users can export book backups. Registered users may request access, correction or deletion through the CloseBook support form. Identity verification may be required before a request is completed.

9. Children

CloseBook is intended for adults and business users. It is not directed to children.

10. Changes

This policy may be updated when the product, providers or legal requirements change. The updated date will appear at the top of this page.

11. Contact

Privacy questions and requests should be submitted through the CloseBook support form.