Privacy Policy
What we process, what we don't keep, who touches your data, and how to exercise your rights.
Last updated September 10, 2026
This policy is the binding document. The security page walks the same data flow in plain language, and the data processing agreement is the Article 28 contract your firm can put on file without writing to us first.
1. Who we are and who is responsible
StatementTable ("we") is operated from Türkiye. Postal address on request, and on any agreement we countersign for you. Contact for anything in this policy: support@statementtable.com. We are the data controller for the processing described here, and the processor for the contents of the statements you upload, which remain your data throughout.
Payments are processed by Polar Software Inc., our merchant of record. Polar is the seller of record for every purchase and an independent controller for the billing data it collects, under its own privacy policy.
Questions about this policy, requests to exercise a right, and requests to name a provider all go to the same address: support@statementtable.com.
2. How we process your files
When you upload a statement, we do three things: we read the pages, we send the page text or page images to an AI document-processing provider that returns the transactions in a structured form, and we check the result against the balances printed on your statement before showing it to you.
We don't keep your file. It is held in the memory of the single request that converts it. It is never written to disk, never queued and never copied into a bucket or a database, and it goes when that request ends, whether the conversion succeeded or failed. The same applies to the page images we prepare from it and to the transactions extracted from it. We do not write your statement, its pages or its contents to a log. A conversion takes minutes at most, and nothing survives an hour under any circumstance. The hosting platform keeps its own operational request logs, which record what a request was and how it ended, never what was in it; they are in the retention table in section 7.
The AI document-processing provider we use is located in the United States. It is bound by a data processing agreement and standard contractual clauses that prohibit it from using your data to train its models, and it deletes the inputs it receives from us within 30 days. It receives only the document you uploaded, not your email address, your account or your payment details.
The service is fully automated. Nobody at StatementTable reads your statement.
3. What we process, and on what legal basis
Article references are to the UK GDPR and the EU GDPR, which use the same numbering. Where we rely on legitimate interests, the interest is stated in the row and is the ordinary operation of a paid service: delivering the conversion, keeping the free tier from being consumed by automated abuse, answering the person who wrote to us, and keeping accurate service statistics.
| Data | Why we process it | Legal basis |
|---|---|---|
| The statement you upload and the transactions extracted from it | To perform the conversion you asked for | Performance of a contract, Article 6(1)(b) |
| A salted hash of your IP address and the number of pages converted today | To enforce the free tier and stop automated abuse | Legitimate interests, Article 6(1)(f) |
| Anonymous usage counters: page count, document type, native or scanned, success or failure, whether the balance check passed, processing cost | Service statistics and capacity planning. These counters carry no personal data and no file names. | Legitimate interests, Article 6(1)(f) |
| Page-view counts. We count page views without cookies or identifiers: the page path, the referring site's hostname, and a campaign tag when the link carries one. Nothing in that record identifies you. | To see which pages are read and where visitors arrive from | Legitimate interests, Article 6(1)(f) |
| Your email address, if you create an account | To create your account, send you a sign-in code, hold your credit balance and send receipts | Performance of a contract, Article 6(1)(b) |
| Sign-in codes: a hash of the six-digit code, its expiry and the number of attempts | To sign you in, and to stop code guessing | Contract and legitimate interests, Articles 6(1)(b) and 6(1)(f) |
| Your credit balance and the ledger behind it: purchases, deductions, refunds, subscription renewals | To show what you have and to honor refunds | Performance of a contract, Article 6(1)(b) |
| Your conversion history: date, page count, document type, whether the balance check passed. We do not record file names, bank names, account numbers or anything from inside your statement. | To show you what you have used, and to support you | Performance of a contract, Article 6(1)(b) |
| Name, email, billing country and purchase details | Selling you credits and plans, issuing invoices, collecting VAT and sales tax | Contract and legal obligation, Articles 6(1)(b) and 6(1)(c). Collected by Polar as merchant of record. |
| Messages you send through the contact form or by email | To answer you | Legitimate interests, Article 6(1)(f) |
We process no special-category data deliberately. A bank statement can incidentally reveal, for example, a payment to a hospital or a political party; we neither look for that nor derive anything from it, and the file is deleted when the conversion ends.
Whether you have to give us anything. Nothing here is a statutory requirement. Uploading a statement is what the conversion is made of, so without a file there is nothing to convert. An email address is needed to hold a credit balance and to send a receipt, so an account cannot exist without one. Everything else is optional, and leaving it out costs you nothing but a reply.
Automated decision-making. Extraction and the balance check are automated, but they produce a spreadsheet for you to review. We take no decision about you by automated means that produces a legal effect or similarly significantly affects you, within the meaning of Article 22. We do not profile you and we do not build a behavioral record of your use.
4. Recipients and sub-processors
We keep the supply chain deliberately small. These are the recipients of personal data, in full:
| Recipient | What they do | Where |
|---|---|---|
| AI document-processing provider | Reads the uploaded document and returns structured transaction data. Contractually barred from training on it; deletes inputs within 30 days. | United States, under a data processing agreement and standard contractual clauses |
| Cloudflare, Inc. | Serves the website, terminates TLS, blocks automated abuse, runs the code that performs the conversion, routes email. | Global edge network; company established in the United States |
| Polar Software Inc. | Merchant of record: sells you credits and plans, takes payment, issues your invoice, handles VAT and sales tax. An independent controller for your billing data under its own privacy policy. | United States |
| Resend, Inc. | Outbound transactional email: sign-in codes, purchase receipts and replies to your support messages. Receives your email address and the content of the message we send you. | United States |
This is the complete list. We use no analytics provider, no advertising network, no session recording, no CRM and no data broker. We do not sell or share personal information. If this list changes, it changes here first and the "last updated" date moves; account holders are told by email before a new sub-processor starts work, as set out in the data processing agreement.
We will tell you exactly who our providers are if you ask. Email support@statementtable.com and we will name the AI document-processing provider and send you a copy of the transfer safeguards we rely on. The data processing agreement we sign with business customers names every provider individually.
We disclose personal data to a public authority only where the law of a jurisdiction that binds us requires it, and we tell the affected account holder unless we are legally barred from doing so.
5. Cookies and local storage
We set no tracking cookies. There are no advertising pixels, no third-party analytics scripts, no session recording and no cross-site trackers on this site. That is why you have never seen a cookie banner here: under the ePrivacy Directive and UK PECR, consent is required for non-essential cookies, and we use none.
Two things can be stored in your browser. This is the complete list.
| Cookie | Set by | What it does | How long it lasts |
|---|---|---|---|
__Host-st_session | Us | Keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, it carries a random value that means nothing outside our database, and it is set only if you create an account and sign in. Browse the site or use the free tier without signing in and it is never set. | 30 days, or until you sign out |
cf_chl_*, Cloudflare's challenge cookies | Cloudflare, on the converter and the sign-in page | We use Cloudflare Turnstile there to tell a person from a script. If it has to show you a challenge, Cloudflare stores a short-lived value so you are not asked again on the next page. Nothing in it identifies you to us, and we cannot read it. | About an hour, set only when a challenge appears |
Neither one needs your consent, because both are strictly necessary for the service you asked for within the meaning of Article 5(3) of the ePrivacy Directive and regulation 6(4) of PECR: the first delivers the sign-in you requested, and the second is how the free tier survives contact with automated traffic. Cloudflare classifies its challenge cookies the same way. Neither is used for advertising, neither builds a profile of you, and neither is shared with anyone.
We store nothing else in your browser: no local storage, no session storage, no fingerprinting of our own, and no cookie at all on the pages you can use without an account.
6. International transfers
StatementTable is operated from Türkiye. Our providers process data in the United States and on a global edge network. Personal data is therefore transferred outside the UK, the EEA, Australia and Canada.
Where we transfer personal data out of the UK or the EEA to a provider in the United States, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, or on the provider's certification under the EU-US Data Privacy Framework where it holds one. We carry out a transfer risk assessment for each provider and apply supplementary measures: encryption in transit for every hop, no statement contents in logs, and a contractual bar on training. You can request a copy of the safeguards that apply to a given transfer at support@statementtable.com.
- Customers in Australia: we are likely to disclose personal information to overseas recipients located in the United States and Türkiye.
- Customers in Canada: your information may be processed outside Canada, including in the United States, and while it is there it may be accessible to the courts, law enforcement and national security authorities of that country under that country's laws.
- Customers in Türkiye: transfers abroad are made on the basis of Article 9 of Law No. 6698 (KVKK), relying on appropriate safeguards or on your explicit consent, as applicable.
7. How long we keep things
This is the complete retention schedule.
| What | How long | Set by |
|---|---|---|
| Your uploaded statement and the transactions extracted from it | Not retained. Held in the memory of the request that converts it and gone when that request ends. Nothing survives an hour. | Us |
| The copy held by our AI document-processing provider | Deleted within 30 days, and never used for training | That provider, under our agreement with it |
| Salted IP hash and today's free-tier page count | 48 hours | Us |
| Anonymous counters, including page-view counts | Kept indefinitely. They hold no personal data and cannot be linked back to you or your file. | Us |
| Your email address, credit ledger and recent conversion history | Until you delete your account. Your email address goes, and the ledger entries are pseudonymized: the identifier on them is replaced with a short code that carries no name and no email address, and they are then kept only as accounting records. | You, at any time |
| Sign-in codes | 10 minutes, then deleted | Us |
| Purchase and invoice records | Kept for the period required by tax and accounting law | Polar, as merchant of record |
| Support and contact-form messages | 12 months, then deleted | Us |
| Operational request logs kept by the hosting platform: time, path, response status, error type and page counts, with nothing from inside a statement in them | Cloudflare's own retention period for platform logs. We neither extend it nor copy the logs anywhere else. | Cloudflare |
8. Your account
Accounts are optional. If you create one, we store your email address, your credit ledger and a short conversion history: counts and dates, never file contents. You sign in with a single-use six-digit code sent to your email; there is no password. You can delete your account yourself from your account page, or by emailing us. Deletion is immediate and permanent: your email address is removed, and the identifier on your ledger entries is replaced with a short code that carries no name and no email address, so the accounting record survives without you in it. Unused credits are forfeited on deletion, so request a refund first if you are within the refund window.
9. Your rights
Depending on where you live, you have the right to ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we rely on it. Where we process on the basis of legitimate interests, you can object at any time and we will stop unless we have compelling grounds that override yours. You also have the right to be told the identity of the recipients of your personal data: ask, and we will name them.
Because we do not retain statement contents, there is usually nothing to delete from a conversion. Deletion requests concern your account, which you can delete yourself, immediately and permanently, from your account page; your support emails; and the purchase records held by Polar as merchant of record. We pass purchase-record requests on to Polar and tell you what happens.
Email support@statementtable.com. The person who operates the service is the privacy contact accountable for these requests, including under Canadian law. We reply within 30 days, usually within one business day, and we do not charge for these requests. We will never treat you differently for exercising a right.
Complain to us first if you want to. Email support@statementtable.com, or use the contact form and pick "Privacy, security or a data request". We acknowledge a complaint about how we handle personal data within 30 days of receiving it, usually the same day, then look into it and tell you what we find and what we do about it. You can also use the form to ask for a copy of your data, to correct it, or to have it deleted.
Complaints. You can complain to a supervisory authority, in the country where you live, where you work, or where the matter arose. That is the ICO in the United Kingdom, your national data protection authority in the EU and the EEA, the OAIC in Australia, the OPC in Canada, and the Kişisel Verileri Koruma Kurumu in Türkiye. You do not have to come to us first, though we would rather fix it.
10. Security
All traffic is encrypted in transit with TLS, both between you and us and between us and every provider above. Statement contents are never written to logs. Access to production infrastructure requires two-factor authentication. Secrets are held in the platform's encrypted secret store, never in source code. Sign-in uses a single-use emailed code, so there is no password database to lose. Card numbers never reach our systems.
The controls we operate, the path a file takes and the companies involved at each step are set out in full on the security page. The contractual form of the same controls is in the data processing agreement.
If a personal data breach occurs, we notify the supervisory authority within 72 hours where Article 33 requires it, and we notify affected account holders by email without undue delay.
11. Data processing agreement
If your firm needs a written processor agreement before it can upload client statements, our data processing agreement is on this site in full. It takes effect when you use the service, so you can file it and move on. It covers subject matter and duration, the categories of data and data subjects, confidentiality, security measures, sub-processors and change notification, transfers, assistance with data subject requests, breach notification, audit rights, and deletion at the end.
12. Children
The service is intended for adults and businesses. We do not knowingly process the data of children under 16.
13. Changes to this policy
We post changes on this page with a new "last updated" date. Material changes to what we collect or who receives it are announced by email to account holders before they take effect.
14. Related documents
Data Processing Agreement · Terms of Service · Refund Policy · Security and data flow