Security & privacy

A bank statement is the most sensitive document your customer will ever send you. Here is exactly what happens to it. Specifics, not badges.

Encryption

  • TLS on every connection — web app and API. HSTS enabled; no plaintext fallback.
  • Password-protected PDFs are unlocked in memory only — the password is never written to disk, logs, or the database.
  • Uploads and outputs sit on our own server only long enough to process and download them.

Retention & deletion

  • Uploaded statements and generated files are deleted automatically after 24 hours.
  • A saved analysis is readable for 24 hours, then removed with everything else.
  • Nothing you upload is used to train models, and statement data is never sold.

Data handling

  • Files are processed on our own host. No advertising trackers on this site.
  • An optional AI pass runs through OpenRouter, and only on OCR files or when balances fail to reconcile. Only the statement text that pass needs is sent. Digital statements that reconcile skip it entirely.
  • We store your email and a salted, hashed password — never the password itself. A session cookie lets this browser see its own work.

What we don't claim

  • We're not a credit bureau and don't make lending decisions — you do, using these signals plus your own policy.
  • We don't display certifications we haven't earned. No SOC 2 badge, no ISO logo.
  • We don't offer an API or webhooks, and we keep no analysis history beyond the 24 hours described here.
  • Read the output before you rely on it. Most anomalies have a perfectly ordinary explanation.

Questions from your risk team? Send them to Contact. We answer in plain English, usually within one business day.

Also see: Privacy · Terms · Analyzer

Security — Encryption, Retention & Data Handling — Bank Statement Analyzer