Privacy Policy
Last updated: October 2026
StatementConvert.ai is operated by AI Tech Explore LLC, United States (“we”, “us”). This policy explains what data we collect, why, who receives it, how long we keep it, and your rights. Questions: support@statementconvert.ai.
1. What Data We Collect
- Account details — your name, email address and profile picture (if your account has one), received when you sign in with Google. Used to identify your account and pre-fill your email at checkout.
- PDF bank statements — processed entirely in memory. Each page is sent to our AI providers (section 4) to read the transactions, and the file is then discarded. Your PDF is never written to disk or stored in any database by us.
- Plan and usage — your plan, the number of statement pages you convert each month, and your Stripe customer and subscription IDs.
- Payment information — handled exclusively by Stripe. We never see or store your card details.
- Technical data — IP address, browser and request times, used to run the site securely and prevent abuse. Our own logs record sizes, timings and error codes, never statement content.
- Support emails— what you write to us. Please don't email bank statements, passwords or full account numbers.
2. How We Use Your Data
- To provide the bank statement conversion service and the Subscription Finder.
- To process your payment securely through Stripe.
- To let you download your converted statement (Excel, CSV, JSON or XML) within your plan's monthly page allowance.
- To keep the service secure and prevent abuse.
- To answer your support requests.
- To understand which pages and features help, using analytics without statement data.
- We do not sell your personal data, and we do not use it for targeted (personalised or cross-context behavioural) advertising.
3. Data Storage and Retention
- We never store your PDF. Uploaded files are processed in memory, their pages are read by our AI providers (section 4), and the file is then discarded.
- Parsed transaction data is returned to your browser and is not kept on our servers. When you download a file, your browser sends the rows back together with a signed receipt proving they came from your conversion; the receipt holds a fingerprint of the rows, not the rows themselves, and expires after 1 hour.
- Subscription Finder and multi-statement merging.Recurring charges are detected in memory from the rows of the request that carries them. When you merge several statements, your browser sends back each statement's rows with a signed receipt (valid for 24 hours); our server checks the receipts, merges and analyses the rows in memory for that single request, and stores nothing.
- What we do store. A small database containing (a) your plan, Stripe IDs and the number of statement pages you have converted each month, keyed by your email address; and (b) the identifiers of Stripe payment events we have already processed (no personal data). Nothing about the content of your statements is ever stored. Your sign-in session lives in a signed cookie in your browser and is cleared when you sign out.
- How long we keep it. Plan and usage records: while your account exists, and deleted within 30 days when you ask us. Billing records: kept by Stripe for as long as tax and accounting law requires. Support emails: as long as needed to help you and keep a record of the conversation, and deleted when you ask. Preview counters: up to 2 days. AI provider abuse logs: up to 30 days. Google Analytics data: at most 14 months.
4. Third-Party Services
These providers process personal data for us to operate StatementConvert.ai. Email us for the full list of named providers.
| Service | Purpose | Privacy Policy |
|---|---|---|
| Hosting, database, security and email providers | Run the website and the in-memory conversion (with short-lived request logs: IP address, page, time), store your email, plan and monthly usage, count free previews per IP address to prevent abuse (expires within 2 days), count page views without cookies, and hold the support emails you send us. All in the United States; none of them store statement content. | On request |
| OpenAI API | Reads the transactions on each statement page | openai.com/policies |
| Anthropic Claude API | Re-reads a page when our checks find a problem with the first reading | anthropic.com/privacy |
| Google sign-in | Sign-in (the only way to sign in) | policies.google.com |
| Stripe | Payments, invoices and subscription management | stripe.com/privacy |
| Google Analytics 4 | Usage analytics (which pages and steps people use) and measuring whether our Google Ads bring sign-ups. No statement data. Visitors in the EEA, UK and Switzerland are asked first. | policies.google.com |
Statement pages are sent to the OpenAI API, and to the Anthropic Claude API when a page needs a second reading, only to read the transactions. Neither provider uses API data to train its models. Each may keep request logs for up to 30 days to detect abuse, under its own API data policy, and then deletes them. We ask OpenAI not to store responses.
5. Cookies and Analytics
- Essential: sign-in cookies that keep you signed in and protect the sign-in flow. The site cannot work without them, so they need no consent.
- Analytics: Google Analytics cookies, only after you allow them if you are in the EEA, UK or Switzerland. Outside those regions they load by default, and you can turn them off below. Our own page-view counts use no cookies.
We count steps such as “landed”, “previewed a statement” or “clicked a plan”, with page counts, file formats, plan names and the campaign link you arrived from. Statement content, merchant names, amounts, file names and email addresses are never sent to analytics, and we do not use session-recording tools. Your browser keeps a few small values for this: sc_consent (your analytics choice), sc_utm and sc_landed (the campaign link of this visit, cleared when the tab closes) and sc_signed_in_once (so a returning sign-in is not counted as new).
6. Legal Bases (EEA and UK)
- Contract: your account, conversions, downloads and billing.
- Legitimate interests: security, abuse prevention, support, and cookieless usage counts to improve the service.
- Consent: Google Analytics cookies. You can withdraw it any time in section 5.
- Legal obligation: billing and tax records.
7. International Transfers
We are based in the United States, and our providers process data mainly in the United States. When data from the EEA, UK or Switzerland is transferred, we rely on our providers' safeguards, such as the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
8. Your Rights
- Everyone: you can ask for a copy of your data, a correction, or its deletion. Email support@statementconvert.ai from your account's email address so we can confirm it is you. We reply within 30 days, free of charge.
- EEA and UK: you can also ask us to restrict or stop processing, receive your data in a portable format, withdraw consent, and complain to your local data protection authority (in the UK, the ICO).
- United States (including California): you can know, access, correct and delete your personal information. We do not sell or share it for cross-context behavioural advertising, and we will not treat you differently for using your rights.
- Canada: you can access and correct your personal information, and complain to the Office of the Privacy Commissioner of Canada.
9. Security
The site is served only over HTTPS. Statements are never stored. The database is locked down so only our server can read it, and our admin accounts use two-step sign-in. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
10. Children
StatementConvert.ai is not intended for anyone under 18, and we do not knowingly collect their data.
11. Changes
When this policy changes, we update the date at the top. For significant changes we will also show a notice on the site.
12. Contact
AI Tech Explore LLC, operator of StatementConvert.ai.
Email: support@statementconvert.ai