Privacy policy.
Plain-English version: we collect what's necessary to run your books, encrypt it, never sell it, and never use it to train models for anyone else or to target advertising. Below is the binding version with the specifics.
01Scope & controller
This Privacy Policy describes how Avo LLC, doing business as BooksGPT ("BooksGPT," "we," "us," or "our"), a Wyoming limited liability company, collects, uses, and protects information when you visit booksgpt.ai or use the BooksGPT application at app.booksgpt.ai (together, the "Services").
BooksGPT is the data controller for personal information you submit to your account. If you connect BooksGPT to a third-party service (for example your bank, through our bank-data providers), the data BooksGPT receives from that service is limited to the scope you authorize.
02Information we collect
We collect three buckets: account info (email, name, business name), books data (transactions, invoices, vendors, receipts), and usage info (pages viewed, features used). We never see or store your bank password: you sign in to your bank directly with our bank-connection provider.
Account data
- Your name and email address. Sign-in is handled by Google Firebase Authentication; we do not store your password.
- Your business or workspace name and business type.
- Billing data: your Stripe customer ID and subscription or purchase status. Stripe holds your card details; we don't.
Books & financial data
- Transactions imported from connected banks or uploaded files (date, amount, merchant, memo, category).
- Invoices, bills, customers, and vendors you create in the product.
- Documents you upload (receipts, statements, exports from other bookkeeping tools).
- Questions you ask the AI assistant and the answers it gives, so you can see your own history.
Usage data
- Pages viewed, buttons clicked, and features used, collected through product analytics tools.
- Device and browser information and IP address.
- Support conversations you have with us through our chat widget.
03How we use information
We use your information for these purposes:
| Purpose | What we do with it |
|---|---|
| Run the Service | Show your books to you, categorize transactions, generate reports, send the emails you've enabled (like the daily digest). |
| Improve the Service | Aggregate usage stats to understand what works. We never use one customer's books to improve another customer's books. |
| Security | Detect fraud, abuse, and suspicious sign-ins. |
| Support | Answer your questions when you contact us. |
| Marketing measurement | Measure whether our own marketing works (for example, whether an ad campaign led to a signup), using tools like Meta's and Google's measurement services on our public marketing pages. |
| Legal compliance | Respond to lawful requests. We will tell you about any government request for your data unless we are legally prohibited from doing so. |
04When we share
We share data only in these situations:
- Service providers. Vendors we use to run the Service, each limited to what their function requires: Stripe (payments, and bank connections through Stripe Financial Connections), Plaid (bank connections), Google Firebase (authentication), Cloudflare (networking and document storage), our hosting providers (servers located in the United States), Resend (transactional email), Crisp (support chat), and product analytics providers (PostHog, Google Analytics). The current list, and what each one holds, is in our Security overview.
- AI model providers. See section 6.
- Advertising partners. Only as described in section 7. Your books data is never shared with advertising partners.
- People you invite. If you invite a teammate or accountant to your workspace, they see the workspace data their role allows.
- Legal compliance. If we receive a valid subpoena or court order. We push back on overbroad requests.
- Corporate transactions. If BooksGPT is acquired, your data transfers to the acquirer under terms at least as protective as these. We will notify you before that happens.
We do not sell your personal information for money. Like most websites that show ads, our public pages may share limited identifiers (cookies, device information) with advertising partners; some US state laws call this "sharing," and you can opt out (see section 7). Your books, transactions, documents, and AI conversations are never part of that.
05Bank & financial data
BooksGPT does not store your bank credentials. Bank connections run through Plaid or Stripe Financial Connections; which one handles a given connection depends on your workspace setting and the institution. When you connect a bank account:
- You authenticate with your bank directly through the provider's interface. Your credentials go to your bank, not to us.
- The provider issues a read-only connection scoped to account balances and transaction data.
- BooksGPT uses that connection to import your transactions into your books.
- We cannot initiate transfers or move money from your accounts. The connection does not grant payment or write access.
You can disconnect a bank at any time from the app's connection settings.
06AI processing & your data
The AI reads your data to do bookkeeping work for you: categorizing transactions and answering your questions. We send only what each task needs to our AI model providers, and we do not use your books to build models for other customers.
- When the AI categorizes a transaction or answers a question, the relevant data is processed by third-party AI model providers strictly to produce that output for you.
- We configure provider settings so that data sent for inference is not used to train the providers' models wherever the provider offers that control.
- We do not use your live transactions, invoices, or documents to train models offered to other customers.
- Your AI conversations and books data are never used to select or target advertising.
07Advertising & cookies
Our public website, and free versions of the product, may show ads (including Google ads). Ad partners use cookies to decide which ad to show. Your books and AI conversations are walled off from all of it, and you can opt out of personalized ads.
We may show advertising on our public marketing pages and in free, ad-supported versions of the Service. Where we do:
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites. Google's use of advertising cookies enables it and its partners to serve ads based on your visits to our sites and other sites on the internet.
- You can opt out of personalized advertising from Google at Google Ads Settings, and from many other vendors at aboutads.info/choices.
- You can read how Google uses information from sites that use its services at policies.google.com/technologies/partner-sites.
- Visitors in the European Economic Area, the United Kingdom, and Switzerland are shown a consent message before any advertising cookies are set, and can decline.
- California and other US state residents can opt out of the "sharing" of personal information for cross-context behavioral advertising by using the opt-out controls above or by emailing us (section 14); we honor these requests for the identifiers we control.
The wall between your books and ads: your transactions, documents, financial reports, and AI assistant conversations are never sent to, crawled by, or shared with any advertising network, and ads are never targeted using your financial records.
08Security
- Encryption in transit: TLS for all connections to the Services.
- Encryption at rest: databases and document storage are encrypted at rest by our infrastructure providers.
- Access controls: production access is limited to authorized personnel, and bank connections are read-only by design.
- Payment isolation: card data is handled entirely by Stripe and never touches our servers.
Our full security posture, including field-level encryption, our subprocessors, and which certifications we do and do not hold, is documented in our Security overview.
No system is perfectly secure. If we discover a security incident affecting your personal data, we will notify affected users promptly and as required by law.
09Retention & deletion
We retain your books data for as long as your account is active. You can request account deletion at any time from within the product or by contacting us; deletion requests are honored on a scheduled basis and remove your data from our production systems.
Some records (billing invoices, records of purchases) are retained as required for tax and accounting compliance even after account deletion.
10Your rights
Depending on where you live (for example US state privacy laws like the CCPA, or the GDPR in the EU/UK), you may have these rights:
- Access: get a copy of the data we hold about you. Much of it is exportable directly from the product.
- Correction: fix anything wrong. You can edit most of your data directly in the product.
- Deletion: see section 9.
- Portability: export your ledger and reports from the product at any time. No lock-in.
- Opt out of sharing for advertising: see section 7.
To exercise any of these, contact us (section 14). We will not retaliate against you or charge you for exercising your rights.
11International visitors
BooksGPT is a US company and the Service is designed for US businesses. Our servers are located in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States.
12Children
The Service is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.
13Changes
We update this Policy when our practices change. If a change is material (it affects how we collect, use, or share your data), we will notify account holders by email before it takes effect. The "Last updated" date at the top of this page always reflects the most recent change.
14Contact
Privacy questions, requests, or complaints:
- Email: [email protected]
- Chat: the support widget on this site or in the app
- Mail: Avo LLC · Attn: Privacy · 5151 California Avenue, Irvine, CA 92617
If you're not satisfied with our response, US customers can file a complaint with the FTC or their state attorney general; EU/UK customers can complain to their data protection authority.