A statement page with a shield drawn over it and a short checklist beside it, two items ticked

· 5 min read

Privacy checklist for statement converters

Questions to ask before uploading client statements to a converter: retention, sub-processors, model training, encryption, logs, account deletion, DPAs.

A bank statement is about as identifying as a document gets: name, address, account number, every payee for a month, and the balances in between. Uploading one to a conversion tool is a disclosure of client information to a third party, and the rules of most professional bodies treat it that way. This checklist is the set of questions to put to any such tool, ours included, before the first client file goes in, with a note on what a good answer looks like and where in a vendor's documents to find it.

Why this is a professional question, not just a technical one

In the US, the AICPA Code of Professional Conduct's Confidential Client Information Rule (ET section 1.700.001) prohibits disclosing confidential client information without the client's consent, and the related interpretation on third-party service providers expects a member who uses one to either have a contractual confidentiality agreement with that provider and reasonable assurance about its procedures, or to obtain the client's consent first. In Australia, the Tax Practitioners Board's Code of Professional Conduct carries a confidentiality obligation and the TPB has published guidance on using cloud services. In the UK and the EU, a practice that uploads client data is a data controller choosing a processor and needs a written contract that meets Article 28 of the GDPR or UK GDPR. Canadian provincial CPA codes and PIPEDA's accountability principle point the same way. Check your own body's wording; the common thread is that you remain responsible for what the tool does with the file, so you need to know.

The checklist

1. What happens to the file after the conversion?

The answer should state how long the file, the page images made from it and the extracted rows exist, with a maximum, and what happens if a job fails or is queued. Wording such as "we may retain uploads to improve our service", or a default that keeps your conversions in an account history for weeks, needs either an off switch or a decision not to use the tool.

2. Who else receives the file?

Every converter uses other companies: hosting, a document-reading or AI provider, payments, email. Ask for the complete list with each one's role and location. A vendor that will not name a provider in public should at least commit to naming it on request and in a signed agreement. "Trusted partners" without a list is not an answer.

3. Is the content used to train models?

Ask this about the vendor and about its AI or OCR provider separately. A good answer is a contractual prohibition on training, stated in the privacy policy, plus the provider's own retention period for the inputs it receives. Silence on training, or "to improve our services" in the clause about the AI provider, is a no.

4. Where is the data processed, and under what transfer mechanism?

For UK, EU, Australian and Canadian clients, a US provider is a cross-border transfer. The vendor should say which safeguards it relies on: standard contractual clauses, the UK addendum, or a Data Privacy Framework certification, and should be able to send you a copy.

5. Is everything encrypted in transit and while it waits?

TLS between your browser and the tool is the minimum. Ask also about the hop between the tool and its AI provider, and whether temporary copies held for long jobs sit in encrypted storage.

6. Do statement contents end up in logs?

Error reports and debug logs are where files leak long after the file itself is gone. A good answer is that logs record page counts and error types and never the contents of a statement. Few vendors say this unprompted; ask.

7. What does an account keep?

Conversion history is useful, but check what it holds. Dates, page counts and whether the check passed are harmless. File names are not, because people name files after clients. Account numbers, bank names or transaction text in the history mean the vendor kept more than it needed.

8. What runs on the upload page?

Analytics scripts, advertising pixels and session-replay tools can capture what is on screen, including a preview of a statement. Open the browser's network tab on the app page and look at which domains are called. A vendor that says it uses no analytics or session recording should be checkable this way.

9. Can you delete the account yourself, and what does deletion do?

Self-service deletion, immediate effect, and a clear statement of what is removed and what is anonymized (billing records usually have to be kept for tax reasons). If deletion means emailing support and waiting, note the promised timing.

10. Will they sign a data processing agreement?

For GDPR and UK GDPR practices this is mandatory; for AICPA members it is the contractual agreement the interpretation asks for. The DPA should name the sub-processors individually, even if the marketing site does not.

11. What is the breach commitment?

Whether the vendor will tell you, and how quickly, if the tool or one of its providers is compromised. Under the GDPR a processor must inform the controller without undue delay; a vendor that serves those markets should say so.

12. What does the free tier record?

A tool that works without sign-in has to stop people abusing it somehow. Ask what it records to do that, typically a hashed IP address and a page count, and for how long.

Reading a privacy policy in five minutes

Search the page for five words: retain, train, third, delete and transfer. Each should land you on a specific sentence with a number or a name in it. Then check the "last updated" date, and compare the privacy policy with the security page: if the two disagree on retention, believe the longer period and ask.

Your side of it

Three habits close the gap that a good vendor leaves open. Put a sentence in the engagement letter that names the categories of tool you use and obtains the client's consent, which is the AICPA route and good practice everywhere. Keep your own copy of every statement, since the tool, if it is behaving, will not. And clear the converted files from downloads folders on shared machines, because the spreadsheet on your laptop is now the longest-lived copy of the client's data. If you redact before uploading, black out account numbers, not balances; a converter that checks its work needs the balance column.

Our answers

Our answers to each of the twelve questions are on the security page and in the privacy policy. Read them with the checklist beside you.

Convert one and see

Three pages a day are free, and you don't need an account to run your own statement through it.