Privacy Policy
Effective 2026-08-15
bankstatement.dev ("we", "us") converts PDF bank and credit-card statements into spreadsheets. This policy explains what we collect, what we do with it, and — importantly — what we don't do.
The short version
- Your statement file is processed in memory and is not stored. We don't keep your PDF.
- We never train models on your identifiable data.
- We store your account and a lightweight history of your conversions (filename, size, date, and whether it verified) — not the transactions inside.
What we collect
- Account data: your username and a hashed (scrypt) password. We never store your password in plain text.
- Conversion history & usage: for each conversion we store the filename, file size, timestamp, and the verdict (verified / not, confidence, number of transactions, detected bank type). We do not store the extracted transactions or any amounts. This powers your history and usage meter.
- Log & analytics data: standard server logs and privacy-friendly, aggregate usage analytics (no sale of personal data).
Your statement files
When you upload a statement, we extract the text and transactions in memory to produce your spreadsheet, then discard the file. We do not persist the PDF or its contents.
For statements our built-in parsers can't read, the extracted text may be sent to our AI provider (via Vercel AI Gateway) under zero-data-retention terms, solely to extract the transactions for you. It is not used to train models.
If a conversion fails to verify, we may ask you to share an anonymized copy so we can add support for that statement format. This is opt-in. Before storing it we remove the real values — amounts, dates, and account numbers are stripped — keeping only the layout structure.
Sub-processors
We use trusted infrastructure providers to run the service: Vercel (hosting), MongoDB Atlas (account and history storage), and Vercel AI Gateway (LLM extraction, zero data retention). Each processes data only to provide the service.
Cookies
We use a single, essential session cookie to keep you signed in. No advertising or cross-site tracking cookies.
Data retention & your rights
Account and history data is kept while your account is active. You can request access to, or deletion of, your data at any time by contacting us. Uploaded files are never retained.
Security
Data is encrypted in transit (HTTPS). Passwords are hashed. Statement files are not stored, which is the strongest protection of all.
Changes
We may update this policy; we'll revise the effective date above. Continued use after a change means you accept it.
Contact
Questions or requests: support@bankstatement.dev.