Security & privacy, in plain English
Three sentences matter most: Your files are never uploaded for the standard converter. We never train models on your data. A DPA is available for accountants and firms.
Local-first by architecture, not by promise
The standard converter runs entirely in your browser. Your PDF is read by JavaScript on your device, parsed in memory, and the result is rendered back to you — at no point is the file transmitted to our servers. This isn't a policy we could quietly change: it's how the software is built.
You can verify it yourself: open your browser's developer tools, watch the Network tab, and convert a statement. You will see no file upload.
Never used for training
We do not use your statements — or any data derived from them — to train models. Because the in-browser converter never sends us your files, there is nothing to train on.
The optional cloud AI feature for scanned statements (early access, strictly opt-in per file) processes documents under zero-retention API terms with our model providers: inputs are not stored and not used for training.
Deletion schedule for the optional cloud feature
If you opt into cloud extraction for a scanned statement: the file is processed in memory, the original is deleted immediately after processing completes, and generated export files are deleted within 24 hours. Deletion events are written to an audit log that contains no file contents.
A scheduled sweeper runs hourly to force-delete any object older than 24 hours — even if a deletion event somehow failed.
DPA for accountants and firms
If you handle client statements, your compliance framework (FTC Safeguards Rule, IRS Publication 4557) expects a Data Processing Agreement with your vendors. We publish a ready-to-sign DPA and countersign within two business days.
For the in-browser converter, most processor obligations are satisfied by design — client data never reaches our systems in the first place.
Infrastructure & transport
The website is served over TLS 1.2+ (HTTPS everywhere, HSTS enabled). Any transient cloud storage used by the opt-in features is encrypted at rest (AES-256) with private buckets and short-lived, randomized object keys.
We do not claim SOC 2 certification today — it's on our roadmap, and this page will say so plainly when it happens. Until then we won't borrow credibility we haven't earned.