Privacy Policy
Last updated: July 18, 2026
The short version
StatementSheet converts PDF bank and credit-card statements to Excel and CSV. Your PDF is never uploaded: for digital (text-based) PDFs, all parsing, OCR and reconciliation happen inside your browser. Two narrow things do touch our servers, both described in full below: (1) when you export, the parsed rows shown in your preview are sent once, used transiently to generate the .xlsx/.csv, and are not stored; and (2) an unreadable scanned page's image is sent to cloud OCR only if you explicitly approve it.
What we never receive
- Your statement PDF files. The PDF itself never leaves your device.
- A scanned page's image - unless you explicitly approve sending that single page to cloud OCR (see "The one optional exception" below).
What we process transiently but never store
- Parsed rows at export time: when you download your spreadsheet, the transaction rows shown in the preview grid (including your edits) are sent to our server once so it can generate the .xlsx/.csv file. They are used only to build that file and are not stored; our jobs table records metadata only (page count, bank label, row count, timestamp) - never the transactions themselves.
- Approved scanned pages: a page image you explicitly approved for cloud OCR is processed transiently to return the transactions and is not stored.
Everything else - parsing, optical character recognition (OCR) for scanned pages, reconciliation, and editing - runs client-side on your device.
What we do collect
- Account data (only if you create an account): your email address, your plan, your remaining page credits, and a Stripe customer reference if you purchase credits.
- Usage metadata for the free-tier limit: to enforce free daily/monthly limits we store non-content metadata — a page count, a bank label (e.g. "chase"), a timestamp, and a salted, irreversible hash of your IP address for anonymous users. We do not store raw IP addresses, and this metadata never includes statement content.
- Payment data: purchases are processed by Stripe. We never see or store your full card number. See Stripe's privacy policy for how they handle payment data.
- Sign-in: we use one-time email "magic links." We store a short-lived, hashed token to verify the link, and a session cookie to keep you signed in.
The one optional exception: unreadable scanned pages
If on-device OCR cannot extract any transactions from a scanned statement, signed-in users with credits are shown an explicit prompt asking whether to send the images of the unreadable pages to our cloud OCR provider (this costs 1 credit per page, and the prompt states the exact pages and cost). Nothing is sent unless you choose "Send." If you decline or ignore the prompt, the page images stay on your device and no credit is spent. When you do approve, each page image is processed transiently to return the transactions and is not stored. Digital PDFs never use this path, and anonymous (signed-out) use never uploads a page image under any circumstances.
Cookies
We use a single first-party, HttpOnly session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.
Bot protection
We use Cloudflare Turnstile to protect sign-in and conversion endpoints from automated abuse. Turnstile is a privacy-preserving alternative to traditional CAPTCHAs.
Data retention
Account records persist while your account is active. Free-tier usage counters reset on their daily/monthly cycle. You can request deletion of your account and associated data at any time by contacting us.
Your rights
You may request access to, correction of, or deletion of the limited account data we hold. Email us at [email protected] and we'll help.
Contact
Questions about this policy? Reach us at [email protected].