Privacy Policy
Effective 2026-09-07
bankstatement.dev ("we", "us") converts PDF bank and credit-card statements into spreadsheets. This policy explains what we collect, what we do with it, and — importantly — what we don't do.
The short version
- Your statement file is processed in memory and is not stored. We don't keep your PDF.
- We never train models on your identifiable data.
- We store your account and a lightweight history of your conversions (filename, size, date, and whether it verified) — not the transactions inside.
What we collect
- Account data: your username and a hashed (scrypt) password. We never store your password in plain text.
- Conversion history & usage: for each conversion we store the filename, file size, timestamp, and the verdict (verified / not, confidence, number of transactions, detected bank type). We do not store the extracted transactions or any amounts. This powers your history and usage meter.
- Anonymous conversions: you can convert one statement a day without an account. To enforce that limit we set a random, opaque id in a cookie and keep a salted one-way hash of your IP address for 48 hours. Neither is linked to a name or email; we keep no file content and not even the filename — anonymous runs are logged under that opaque id only as size, timestamp, and verdict, for the same aggregate statistics as account conversions.
- Log & analytics data: standard server logs and privacy-friendly, aggregate usage analytics (no sale of personal data).
Your statement files
When you upload a statement, we extract the text and transactions in memory to produce your spreadsheet, then discard the file. We do not persist the PDF or its contents.
For statements our built-in parsers can't read, the extracted text may be sent to our AI provider (via Vercel AI Gateway) under zero-data-retention terms, solely to extract the transactions for you. It is not used to train models.
For a statement our parsers can't yet fully read, we keep a de-identified copy of its layout so we can add support for that format. Before storing, we strip the real values (amounts, dates, and account and card numbers) and keep only the structure. We hold it only until we've added support for that format and then delete it, and we use it solely to improve format coverage, never to train models. You can also choose to share a copy when a conversion fails to verify.
Sub-processors
We use trusted infrastructure providers to run the service: Vercel (hosting), MongoDB Atlas (account and history storage), Vercel AI Gateway (LLM extraction, zero data retention), and Google Ads (advertising conversion measurement). Each processes data only to provide the service.
Cookies
We use an essential session cookie to keep you signed in, and an essential bs_anon cookie (a random id) to count anonymous conversions. We also run Google Ads conversion tracking, which sets Google advertising cookies to measure whether visitors who arrive from our ads go on to sign up or express interest in a paid plan. We use these solely to measure our own advertising — we don't sell your data, and we don't run cross-site ad targeting. You can block them with a browser setting or a tracking blocker; the converter still works normally.
Data retention & your rights
Account and history data is kept while your account is active. You can request access to, or deletion of, your data at any time by contacting us. Uploaded files are never retained.
Security
Data is encrypted in transit (HTTPS). Passwords are hashed. Statement files are not stored, which is the strongest protection of all.
Changes
We may update this policy; we'll revise the effective date above. Continued use after a change means you accept it.
Contact
Questions or requests: support@bankstatement.dev.