Privacy Policy

Your statements, your data.

Last updated: June 2, 2026

We delete uploaded PDFs from storage immediately after processing. We don't sell data, and we never use customer documents to train AI models. Here's exactly what we collect, why, and how long we keep it.

What we collect

  • Email address — only if you create an account. Used for login, verification, and refund-policy emails.
  • Hashed password — stored using bcrypt; the plaintext is never logged or seen by us.
  • Browser fingerprint — for anonymous users only, used to apply the daily-conversion limit. Not linked to any personal information.
  • Conversion metadata — filename, page count, timestamp, success/failure. No transaction-level content from your statements is retained.
  • Payment information — handled entirely by Stripe. We never see or store your card number.

What we DON'T do

  • We don't sell your data to anyone.
  • We don't use uploaded documents to train AI models, ours or anyone else's.
  • We don't share statement contents with third-party advertisers or data brokers.
  • We don't load third-party tracking pixels on the converter page.

How long we keep your data

  • Source PDFs: deleted from storage immediately after the worker finishes processing.
  • Output files (anonymous users): auto-deleted after 24 hours.
  • Output files (registered users): kept in your conversion history until you manually delete them.
  • Account record: kept while your account is open. Closing the account triggers permanent deletion within 30 days.

How we protect your data

  • All traffic is HTTPS (TLS 1.3).
  • Files at rest in object storage are encrypted (AES-256).
  • Passwords are hashed with bcrypt.
  • PDFs are processed inside an isolated worker container and deleted immediately afterwards.
  • We monitor errors with Sentry; the integration redacts user data from stack traces.

Cookies

We use a single first-party cookie to keep you logged in. That cookie is HTTP-only, SameSite=Lax, and Secure-flagged. We don't use third-party cookies. We don't run an ad network. No consent banner is needed because there are no tracking cookies to consent to.

Third-party services we use

Stripe (payments), Resend (transactional email), Sentry (error monitoring, no payload), Cloudflare R2 (file storage), Neon (database), Upstash (queue + rate limiting), Vercel (hosting). Each is bound by their own privacy policy; we share with them only the minimum data needed to provide their service.

Your rights

You can export, correct, or delete your account data at any time. Email us and we'll act on it within 30 days. If you're in the EU, UK, or California, your statutory rights (GDPR, UK-GDPR, CCPA) still apply on top of what's written here.

Reporting a security issue

If you find a vulnerability, email support@accuratebankstatementconverter.com with details. We respond within one business day. We don't have a paid bug-bounty program yet, but we will publicly acknowledge anyone who reports something material (with your permission).

Changes to this policy

If we make material changes, we will email registered users at least 14 days before the change takes effect.

Questions?

Email us and we'll respond within one business day.

support@accuratebankstatementconverter.com

← Back to home