Privacy Policy

Last updated: September 3, 2026

GreenBooks is a web app, so your data is stored on our servers rather than only on your own machine. Keeping it private and secure is one of our highest priorities, and the sections below set out exactly how.

1. What we collect

What you type in. Accounts, transactions, categories, budgets, payees, and notes. You own this data.

Your account. An email address and a password, which is hashed with bcrypt and never stored in a form we could read.

Your subscription status. Whether you are on a trial, active, or lapsed, and the Stripe identifiers needed to keep that in sync.

Page views. Which pages get visited, and which link or search brought you here. This never includes anything about your finances.

2. Where your data lives

Your data is stored in a Postgres database hosted by Heroku, a Salesforce company, on servers in the United States. It is encrypted in transit and encrypted at rest. Access to the production database is limited to the developer who runs GreenBooks and is protected by two-factor authentication.

If you are outside the United States, using GreenBooks means your data is transferred to and stored there.

3. Bank connections are optional

GreenBooks works without a bank connection. Many customers never use one, and enter or import their transactions by hand.

If you do connect one, that connection runs through Plaid, a regulated provider of bank connections. Two things to be clear about:

  • Your bank username and password go to Plaid, never to us. We never see them, never receive them, and have no way to store them.
  • — What we receive back is read-only transaction and balance data. Nothing in GreenBooks can move money.

You can disconnect a bank at any time in Settings, and we will stop receiving anything from it.

4. Payments

Subscriptions are billed through Stripe. Your card number never reaches our servers; it goes directly to Stripe. What we keep is your subscription status and the identifiers needed to manage it, so we know whether your account is active.

5. Who can see your data

You, and anyone you give your login to. Couples share a book in GreenBooks by sharing a single login, so whoever has your password can see everything in your account.

Us, when you ask. We do not browse customer accounts, and there is no internal tool for reading your books. The exception is when you write in with a problem that cannot be diagnosed otherwise and you give us permission; we then look at what is needed to fix it.

Nobody else. We do not sell, rent, trade, or share your personal or financial data. The exceptions are the companies listed below, which process data on our behalf so the service can run, and a valid legal order such as a court order or subpoena. If we receive one and are permitted to tell you, we will.

6. The companies that touch your data

These are the companies that handle your account or financial data, what each does, and what it can see. Nobody outside this list receives any of it.

CompanyWhat it doesWhat it can see
Heroku (Salesforce)Runs our servers and databaseYour account and financial data, encrypted at rest
VercelServes the web app itselfStandard web request logs. No financial data
PlaidBank connections, only if you use themYour bank credentials and the transactions you import
StripeProcesses paymentsYour card details and billing address
Postmark (ActiveCampaign)Sends our emailYour email address and the contents of those messages

When we build GreenBooks, we choose the companies behind it carefully. Each one is long established, widely used across the industry, and vetted by us before it handles anything of yours.

Their security is audited by outside firms, not just claimed. Heroku holds SOC 1, 2, and 3 attestation reports and ISO 27001 certification. Stripe is certified as a PCI Service Provider Level 1, the highest level defined for handling card data.

7. Analytics and cookies

We use two analytics providers. Plausible counts page views. It sets no cookies and collects no personal data. DataFast tells us which links, searches and campaigns bring people to GreenBooks, so we know where to spend our effort. It does set a cookie in order to do that.

DataFast is switched off inside the app. It runs only on our public pages. Nothing you do in your account — the transactions you enter, the accounts you hold, the reports you run — is sent to it. Plausible does count page views inside the app, but it records only which page was opened, never what was on it, and it cannot connect that to you.

There are no advertising cookies and no ad networks. Apart from analytics, the only cookies and local storage we use keep you logged in and remember your display preferences.

8. Taking your data, and deleting it

Export. You can export your transactions to CSV or QIF at any time from within the app. The file is a copy on your own computer, in a format other software can read.

Deletion. Deleting your account removes your data from our live database. Because the database is backed up, copies can remain in encrypted backups for a short period before those backups rotate out. They are not restored into the live service or used for anything else.

If you would prefer that we delete your data and confirm when it is done, write to support@greenbooks.app.

9. If GreenBooks is ever sold, or shuts down

GreenBooks has operated since 2011. If the service were ever sold or shut down, we will notify you by email beforehand, you will have at least 30 days to export your data, and your data will not be transferred to anyone whose use of it would conflict with this policy. It will not be sold separately from the service.

10. Your rights

You can access, correct, export, and delete your data at any time from inside the app. Depending on where you live, you may also have statutory rights to request a copy of the data we hold, ask for corrections, or object to processing. Write to us and we will honor those requests.

11. Changes to this policy

When this policy changes, we update it here along with the date at the top. If a change materially affects how your data is handled, we will also tell you in the app or by email.

12. Contact

Questions about this policy go to support@greenbooks.app.