Security & privacy
A bank statement is the most sensitive document your customer will ever send you. Here is exactly what happens to it. Specifics, not badges.
Encryption
- TLS on every connection. HSTS enabled; no plaintext fallback.
- Password-protected PDFs are unlocked in memory only — the password is never written to disk, logs, or the database.
- Uploads and outputs sit on our own server only long enough to process and download them.
Retention & deletion
- Uploaded statements and generated files are deleted automatically after 24 hours.
- Nothing you upload is used to train models, and statement data is never sold.
Data handling
- Files are processed on our own host. No advertising trackers on this site.
- Conversion and OCR run on our server. No AI provider or other third party reads your statement.
- We store your email and a salted, hashed password — never the password itself. A session cookie lets this browser see its own work.
What we don't claim
- We're not a credit bureau and don't make lending decisions. We convert; you decide.
- We don't display certifications we haven't earned. No SOC 2 badge, no ISO logo.
- We don't offer an API or webhooks, and we keep no files beyond the 24 hours described here.
- Read the output before you rely on it. Balances reconcile; descriptions are only as clear as the PDF.