Security & privacy

Bank statements are among the most sensitive documents your customers will ever upload. Here's exactly what happens to them — in plain English, because BFSI trust is earned with specifics, not badges.

Encryption

  • TLS on every connection — web app and API. HSTS enabled; no plaintext fallback.
  • Password-protected PDFs are unlocked in memory only — the password is never written to disk, logs, or the database.
  • Uploads and outputs live on our own server only long enough to process and download them.

Retention & deletion

  • Uploaded statements and generated files are deleted automatically after 24 hours.
  • Analyzer previews are not persisted — the report lives in your browser.
  • Nothing you upload is used to train models, and statement data is never sold.

Data handling

  • Files are processed on our own host. There are no advertising trackers on this site.
  • Optional AI verification (Google Gemini) runs only on OCR files or when balances fail to reconcile — and only the statement text needed for verification is sent. Digital statements that reconcile skip it entirely.
  • By default the tools are anonymous: a session cookie lets this browser see its own conversions. If you create an account for larger files, we store your email and a salted, hashed password — never the password itself.

What we don't claim

  • We're not a credit bureau and don't make lending decisions — you do, using these signals plus your own policy.
  • We don't display certifications we haven't earned. No SOC 2 badge, no ISO logo.
  • We don't offer an API, webhooks, or stored analysis history beyond the 24-hour window described here.
  • Review the output before you rely on it; most anomalies have perfectly legitimate explanations.

Questions from your risk team? Send them to contact — typical turnaround is one business day, answered in plain English.

Also see: Privacy · Terms · Analyzer

Security — Encryption, Retention & Data Handling — Bank Statement Analyser