Privacy Policy

bankstatement.dev ("we", "us") converts PDF bank and credit-card statements into spreadsheets. This policy explains what we collect, what we do with it, and — importantly — what we don't do.

The short version

What we collect

Your statement files

When you upload a statement, we extract the text and transactions in memory to produce your spreadsheet, then discard the file. We do not persist the PDF or its contents.

For statements our built-in parsers can't read, the extracted text may be sent to our AI provider (via Vercel AI Gateway) under zero-data-retention terms, solely to extract the transactions for you. It is not used to train models.

For a statement our parsers can't yet fully read, we keep a de-identified copy of its layout so we can add support for that format. Before storing, we strip the real values (amounts, dates, and account and card numbers) and keep only the structure. We hold it only until we've added support for that format and then delete it, and we use it solely to improve format coverage, never to train models. You can also choose to share a copy when a conversion fails to verify.

Sub-processors

We use trusted infrastructure providers to run the service: Vercel (hosting), MongoDB Atlas (account and history storage), Vercel AI Gateway (LLM extraction, zero data retention), and Google Ads (advertising conversion measurement). Each processes data only to provide the service.

Cookies

We use an essential session cookie to keep you signed in, and an essential bs_anon cookie (a random id) to count anonymous conversions. We also run Google Ads conversion tracking, which sets Google advertising cookies to measure whether visitors who arrive from our ads go on to sign up or express interest in a paid plan. We use these solely to measure our own advertising — we don't sell your data, and we don't run cross-site ad targeting. You can block them with a browser setting or a tracking blocker; the converter still works normally.

Data retention & your rights

Account and history data is kept while your account is active. You can request access to, or deletion of, your data at any time by contacting us. Uploaded files are never retained.

Security

Data is encrypted in transit (HTTPS). Passwords are hashed. Statement files are not stored, which is the strongest protection of all.

Changes

We may update this policy; we'll revise the effective date above. Continued use after a change means you accept it.

Contact

Questions or requests: support@bankstatement.dev.