Privacy Policy
Last updated: March 2026
What we collect
When you create an account, we store your email address and basic profile information (name, profile picture if you sign in with Google). We use this to manage your account and send transactional emails (sign-in links, receipts).
Bank statement data
ConvertStatement processes uploaded PDF files entirely in memory. Your bank statement data is never written to disk, stored in a database, or logged. Once processing completes and the result is returned to your browser, the data is deleted from server memory. We cannot access, recover, or share your bank data after processing.
Payments
Payments are processed by Stripe. We do not see or store your credit card number, CVV, or full billing details. Stripe handles all payment data in compliance with PCI DSS. We only store your Stripe Customer ID to manage your subscription.
Cookies and analytics
We use essential cookies to maintain your login session. We do not use third-party tracking cookies or advertising networks. We may use privacy-friendly analytics to understand usage patterns, but no personally identifiable information is shared with analytics providers.
Data security
All data in transit is encrypted using HTTPS/TLS. Authentication is handled via NextAuth with secure, httpOnly session cookies. We follow industry-standard security practices to protect your account information.
Your rights
You can delete your account and all associated data at any time by contacting us at [email protected]. Since we do not store bank statement data, there is nothing to delete beyond your account profile and subscription information.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of ConvertStatement after changes constitutes acceptance of the updated policy.
Contact
Questions about this privacy policy? Email us at [email protected].