Legal

Privacy & Terms

Last updated: August 30, 2026

Privacy Policy

This Privacy Policy explains how Granite Reporting LLC (“Granite,” “we,” “us,” or “our”) collects, uses, and shares information. It covers both this marketing website and the Granite application, including the public demo at demo.granitebooks.io (together, the “Service”). Where a section applies only to the website, the application, or the demo, we say so.

Information we collect

From the website. When you visit our site, request a demo, join a waitlist, subscribe to updates, or contact us, we may collect your name, email address, company name, and any message you send. Beta signups are relayed to us by FormSubmit. We use Vercel Web Analytics, which records page views and referrers without cookies and without identifying individual visitors.

From the demo. The demo at demo.granitebooks.io requires no account. Starting it sets a session cookie that identifies your temporary copy of the demo company, and we keep a hashed record of your IP address to rate-limit new sessions. Prompts you send to the assistant are logged for abuse monitoring. The demo company is fictional; do not enter real financial data. Each demo organization is deleted after two hours idle.

From the application. The Granite application is a bookkeeping and financial-close product. To provide it, we collect and process:

  • Account information — name, email, password credentials, organization details, and team-member roles.
  • Financial data — transactions, ledgers, balances, invoices, bills, journal entries, and related accounting records you import or that we retrieve on your behalf.
  • Customer and vendor data — contact and account details about your customers and vendors that appear in your financial records.
  • Integration data — information retrieved from third-party services you connect, via API, OAuth, or CSV upload, including Stripe, Brex, Ramp, Expensify, Silicon Valley Bank (SVB), Deel, Justworks, and custom sources you configure.
  • Credentials for connected services — API keys, OAuth tokens, and similar secrets you provide so we can retrieve data from third-party services on your behalf. These are stored encrypted at rest, used only to perform the synchronization you enable, and never displayed back in full.
  • Usage data — how you interact with the application, including log data, feature usage, and diagnostic information.

How we use information

  • To provide, operate, secure, and improve the Service.
  • To connect to and synchronize data from the third-party sources you authorize.
  • To communicate with you about your account, support requests, and product updates.
  • To send marketing communications, where permitted — you can opt out at any time.
  • To comply with legal obligations and enforce our agreements.

We do not sell your personal information, and we do not use your financial, customer, or vendor data to train machine-learning models for other customers without your explicit permission.

How we share information

We share information only as described here:

  • Service providers / sub-processors — vendors that host our infrastructure, process payments, send email, and provide analytics, acting under contract on our behalf.
  • Integrations you authorize — we exchange data with third-party services (Stripe, Brex, Ramp, Expensify, SVB, Deel, Justworks, and any custom sources) only as needed to provide the connections you turn on.
  • Legal and safety — when required by law, to respond to lawful requests, or to protect our rights, users, and the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

Third-party integrations

When you connect a third-party service through API, OAuth, or CSV upload, your use of that service remains governed by that provider’s own terms and privacy policy. We access only the data needed to provide the features you enable, and you can disconnect an integration at any time from your account settings. Disconnecting stops future synchronization; data already imported is retained per the retention section below.

Data retention

We retain information for as long as your account is active and as needed to provide the Service, then for any additional period required to meet legal, accounting, tax, or reporting obligations. You may request deletion of your data as described below; some records may be retained where the law requires it.

Data security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, per-organization data isolation, access controls, and monitoring. Our infrastructure is hosted by Supabase (Postgres) and Vercel in the United States. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Security incidents. If we become aware of a security incident affecting your data, we will notify the account owner without undue delay, describe what we know, and cooperate with you on any notifications you are required to make.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to opt out of marketing. Residents of the EU/UK (GDPR) and California (CCPA/CPRA), among others, have specific rights. To exercise them, contact us at ben@granitebooks.io. We will respond as required by applicable law.

For data within the application, the organization that owns the account (your employer or client) is generally the controller of that data, and we act as a processor on its behalf; direct individual requests to that organization where appropriate.

Cookies

We use cookies and similar technologies on the website for essential functionality, analytics, and (where applicable) marketing. You can control cookies through your browser settings; disabling some cookies may affect site functionality.

Children

The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal information from children.

International users

We operate in the United States, and your information may be processed in the United States or other countries with different data-protection laws than your own. Where required, we use appropriate safeguards for cross-border transfers.

Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the “Last updated” date; material changes may be communicated by additional notice.

Contact

Questions about this Policy? Contact us at ben@granitebooks.io.

Terms of Service

These Terms of Service (“Terms”) govern your access to and use of the Granite website, the Granite application, and the public demo (together, the “Service”), provided by Granite Reporting LLC. By accessing or using the Service, you agree to these Terms. If you are using the Service on behalf of an organization, you represent that you are authorized to bind that organization.

The Service

Granite provides bookkeeping and financial-close software, including the ability to import and synchronize data from third-party services you connect. We may add, change, or remove features, and we may suspend or discontinue any part of the Service, at any time.

Beta status

Granite is currently offered as a beta. Features may be incomplete, change without notice, or contain defects. You should independently review any figures produced by the Service before relying on them for financial statements, tax filings, investor reporting, or other decisions, and you should maintain your own copies of your source data and books. Beta access may be suspended or ended at any time.

Accounts

You are responsible for maintaining the confidentiality of your credentials and for all activity under your account. Notify us promptly of any unauthorized use. You must provide accurate information and keep it current.

Your data and connected accounts

You retain all rights to the data you submit or that we retrieve from services you connect (“Your Data”). You grant us a limited license to host, process, and transmit Your Data solely to provide and improve the Service. You represent that you have the right to provide Your Data and to authorize the integrations you enable (including Stripe, Brex, Ramp, Expensify, SVB, Deel, Justworks, and custom sources), and that doing so does not violate any third party’s rights or any agreement you have with those providers.

Credentials and API keys

If you provide API keys, tokens, or other credentials for third-party services, you represent that you are authorized to do so and that doing so complies with the provider’s terms. Where a provider offers scoped or read-only credentials, you should use them. We store credentials encrypted and use them only to perform the synchronization you enable. You are responsible for rotating or revoking credentials when a user leaves your organization or if you believe a credential has been compromised, and you may revoke our access at any time through the provider or from your account settings.

Backups and export

You can export your data from the Service at any time, and we maintain routine backups for operational recovery. The Service is a tool for preparing your books; it is not a guaranteed system of record or an archival service. You are responsible for keeping copies of your source data and for any retention obligations that apply to your business.

Acceptable use

You agree not to:

  • Use the Service for any unlawful or fraudulent purpose.
  • Upload data you are not authorized to share, or that infringes others’ rights.
  • Attempt to access, probe, or disrupt the Service or other customers’ data without authorization.
  • Reverse engineer, resell, or build a competing product from the Service, except as the law expressly permits.

Not financial, accounting, or legal advice

Granite is a software tool. It does not provide accounting, tax, audit, financial, or legal advice, and it is not a substitute for a qualified professional. You are responsible for reviewing the accuracy of your books and for your own compliance, tax, and reporting obligations.

Third-party services

The Service integrates with third-party providers. We are not responsible for those services, their availability, or their handling of your data, and your use of them is governed by their own terms.

Fees

Pricing for paid plans is described on our pricing page or in your order. Fees are non-refundable except as required by law or expressly stated. We may change pricing on prospective notice.

Intellectual property

The Service, including its software, content, and trademarks, is owned by us or our licensors and is protected by law. These Terms grant you a limited, non-exclusive, non-transferable right to use the Service; we reserve all rights not expressly granted.

Disclaimer of warranties

THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT DATA WILL BE ACCURATE OR PRESERVED.

Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, Granite Reporting LLC AND ITS OWNERS, EMPLOYEES, CONTRACTORS, AND AFFILIATES WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUES, DATA, OR GOODWILL, OR FOR PENALTIES, INTEREST, OR ADJUSTMENTS ARISING FROM FINANCIAL STATEMENTS, TAX FILINGS, OR OTHER REPORTS PREPARED USING THE SERVICE, OR FOR UNAUTHORIZED ACCESS TO OR ALTERATION OF YOUR DATA OR CONNECTED ACCOUNTS EXCEPT TO THE EXTENT CAUSED BY OUR GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS RELATING TO THE SERVICE WILL NOT EXCEED THE GREATER OF $100 OR THE AMOUNTS YOU PAID US FOR THE SERVICE IN THE 12 MONTHS BEFORE THE CLAIM AROSE. SOME JURISDICTIONS DO NOT ALLOW CERTAIN LIMITATIONS, SO SOME OF THESE MAY NOT APPLY TO YOU.

Indemnification

You agree to indemnify and hold harmless Granite from claims, losses, and expenses (including reasonable legal fees) arising from Your Data, your use of the Service, or your violation of these Terms or applicable law.

Termination

You may stop using the Service at any time. We may suspend or terminate your access if you violate these Terms or to protect the Service or other users. On termination, your right to use the Service ends; you may request export or deletion of Your Data as described in the Privacy Policy, subject to legal retention requirements.

Force majeure

We are not liable for any failure or delay caused by events beyond our reasonable control, including outages or changes at third-party providers whose services the Service depends on.

Governing law and disputes

These Terms are governed by the laws of the State of New York, without regard to conflict-of-laws rules. The parties agree to the exclusive jurisdiction of the state and federal courts located in New York County, New York, and each waives any objection to venue there. Any claim relating to the Service must be brought within one year after it arises.

Changes to these Terms

We may update these Terms from time to time. We will post the updated version here and revise the “Last updated” date; continued use of the Service after changes take effect constitutes acceptance.

Contact

Questions about these Terms? Contact us at ben@granitebooks.io.