Privacy Policy

bankstatement.dev ("we", "us") converts PDF bank and credit-card statements into spreadsheets. This policy explains what we collect, what we do with it, and — importantly — what we don't do.

The short version

What we collect

Your statement files

When you upload a statement, we extract the text and transactions in memory to produce your spreadsheet, then discard the file. We do not persist the PDF or its contents.

For statements our built-in parsers can't read, the extracted text may be sent to our AI provider (via Vercel AI Gateway) under zero-data-retention terms, solely to extract the transactions for you. It is not used to train models.

If a conversion fails to verify, we may ask you to share an anonymized copy so we can add support for that statement format. This is opt-in. Before storing it we remove the real values — amounts, dates, and account numbers are stripped — keeping only the layout structure.

Sub-processors

We use trusted infrastructure providers to run the service: Vercel (hosting), MongoDB Atlas (account and history storage), and Vercel AI Gateway (LLM extraction, zero data retention). Each processes data only to provide the service.

Cookies

We use a single, essential session cookie to keep you signed in. No advertising or cross-site tracking cookies.

Data retention & your rights

Account and history data is kept while your account is active. You can request access to, or deletion of, your data at any time by contacting us. Uploaded files are never retained.

Security

Data is encrypted in transit (HTTPS). Passwords are hashed. Statement files are not stored, which is the strongest protection of all.

Changes

We may update this policy; we'll revise the effective date above. Continued use after a change means you accept it.

Contact

Questions or requests: support@bankstatement.dev.