Closebook · Legal
Privacy policy
What personal data Closebook holds, why we hold it, where it lives, how long we keep it, and what you can ask us to do about it. Closebook sets no cookies and runs no third-party analytics.
Last updated 10 September 2026
Who we are, and which hat we wear
[REGISTERED ENTITY NAME], Inc., [STREET ADDRESS], [CITY], DE [ZIP], United States, operates Closebook at closebook.io. For privacy questions write to privacy@vizio.ai.
Which role we hold depends on the data, and the distinction matters:
- For your workspace's financial data — the transactions, invoices and counterparties you import — we are a processor. You decide what goes in and why; we act on your instructions. The data processing addendum governs that relationship.
- For your own account and our website — your name, email, the demo form, support mail — we are a controller, and this policy is our notice to you.
What we collect
Account data. Your name, email address, hashed password or the identity provider you signed in with, your workspace memberships and role, and the timestamps of your sign-ins.
Workspace content. Whatever you import or enter: transactions, statements and the files you upload, invoices, counterparties, mapping rules, notes. Financial records routinely name people, so we treat all of it as potentially personal data.
Connection credentials. API keys and OAuth tokens for the sources you connect, encrypted at rest with AES-256-GCM and never displayed back to a browser.
Operational records. An audit log of who changed which record and when, sync run outcomes and their errors, and server logs.
If you contact us. What you put in the demo form or an email, plus the page you submitted from and your browser's user-agent string, so we can prepare properly and reply.
What we do not collect: no advertising identifiers, no cross-site tracking, no third-party analytics, no behavioural profiling. See the cookie page — Closebook sets no cookies at all.
Why we process it, and on what basis
- To provide Closebook — importing, mapping and reporting your data. Necessary to perform our contract with you.
- To keep it secure and working — authentication, audit logging, fault diagnosis, abuse prevention. Our legitimate interest in a service that is safe and reliable.
- To support you — answering your messages. Contract, and our legitimate interest in being useful.
- To bill you — invoicing and the records that back it. Contract, and our legal obligation to keep financial records.
- To reply to a demo request — our legitimate interest in responding to someone who asked us to get in touch.
We do not use your workspace content for advertising, and we do not use it to train machine learning models.
The AI mapping assistant, specifically
Closebook can propose a category for a transaction. When you ask it to, the transaction's description and amount are sent to a model provider so it can suggest a mapping. This is worth stating plainly:
- it happens per request, when a person asks for it — not as a background sweep;
- only the fields needed for the suggestion are sent, not your ledger;
- every suggestion is reviewed and approved by a person in your workspace before it changes any record;
- the provider is named on the sub-processors page, and we use it under terms that prohibit training on our submissions.
If you would rather no data went to a model provider at all, tell us and we will disable the assistant for your workspace.
Where it lives, and international transfers
The application runs in Frankfurt, European Union (Vercel, region fra1). The Postgres database is hosted by Supabase in Frankfurt, European Union (Supabase, eu-central-1). Both are named, with everything else we depend on, on the sub-processors page.
We are a US company, so our staff in the United States access that data to operate the service, and some sub-processors are US-based. Where personal data of people in the EEA, UK or Switzerland moves out of those regions, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) and take account of the destination's laws.
How long we keep it
- Workspace content — while your workspace is open, then thirty days after termination so you can export it, then deleted. Ask in writing and we delete it sooner.
- Account data — while your account exists, then up to thirty days.
- Connection credentials — deleted immediately when you disconnect a source.
- Audit and security logs — twelve months, because a shorter window makes an incident impossible to reconstruct.
- Invoices and billing records — seven years, as tax law requires.
- Demo requests and support mail — twenty-four months, then deleted.
Your rights
Depending on where you live you may have the right to access your personal data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw consent where consent was the basis.
If you are in the EEA, UK or Switzerland, those are your GDPR rights, and you may complain to your local supervisory authority.
If you are a California resident, you may request the categories and specific pieces of personal information we collected, request deletion or correction, and you will not be treated differently for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but you may still ask, and we will confirm it in writing.
Write to privacy@vizio.ai. We reply within thirty days, and we may need to verify who you are first. If your data sits in someone else's Closebook workspace, we will point you at that organisation, since they decide what happens to it.
Security
Tenant isolation is enforced in the database with row-level security rather than in application code; credentials are encrypted at rest; access to production is limited and logged. The security page sets out the detail, including what we do not have — we hold no SOC 2 or ISO 27001 certification. Report a concern to security@vizio.ai. If a breach affects your data we will tell you without undue delay and, where the law sets one, within the stated deadline.
Children
Closebook is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, write to us and we will delete it.
Changes to this policy
We will update this page when our practices change, and the date at the top is always the date of the current version. For a material change we will email workspace owners rather than relying on you to notice.