Privacy Policy

What we process, what we don't keep, who touches your data, and how to exercise your rights.

Last updated September 10, 2026

This policy is the binding document. The security page walks the same data flow in plain language, and the data processing agreement is the Article 28 contract your firm can put on file without writing to us first.

1. Who we are and who is responsible

StatementTable ("we") is operated from Türkiye. Postal address on request, and on any agreement we countersign for you. Contact for anything in this policy: support@statementtable.com. We are the data controller for the processing described here, and the processor for the contents of the statements you upload, which remain your data throughout.

Payments are processed by Polar Software Inc., our merchant of record. Polar is the seller of record for every purchase and an independent controller for the billing data it collects, under its own privacy policy.

Questions about this policy, requests to exercise a right, and requests to name a provider all go to the same address: support@statementtable.com.

2. How we process your files

When you upload a statement, we do three things: we read the pages, we send the page text or page images to an AI document-processing provider that returns the transactions in a structured form, and we check the result against the balances printed on your statement before showing it to you.

We don't keep your file. It is held in the memory of the single request that converts it. It is never written to disk, never queued and never copied into a bucket or a database, and it goes when that request ends, whether the conversion succeeded or failed. The same applies to the page images we prepare from it and to the transactions extracted from it. We do not write your statement, its pages or its contents to a log. A conversion takes minutes at most, and nothing survives an hour under any circumstance. The hosting platform keeps its own operational request logs, which record what a request was and how it ended, never what was in it; they are in the retention table in section 7.

The AI document-processing provider we use is located in the United States. It is bound by a data processing agreement and standard contractual clauses that prohibit it from using your data to train its models, and it deletes the inputs it receives from us within 30 days. It receives only the document you uploaded, not your email address, your account or your payment details.

The service is fully automated. Nobody at StatementTable reads your statement.

3. What we process, and on what legal basis

Article references are to the UK GDPR and the EU GDPR, which use the same numbering. Where we rely on legitimate interests, the interest is stated in the row and is the ordinary operation of a paid service: delivering the conversion, keeping the free tier from being consumed by automated abuse, answering the person who wrote to us, and keeping accurate service statistics.

What we process, and the legal basis for each
DataWhy we process itLegal basis
The statement you upload and the transactions extracted from itTo perform the conversion you asked forPerformance of a contract, Article 6(1)(b)
A salted hash of your IP address and the number of pages converted todayTo enforce the free tier and stop automated abuseLegitimate interests, Article 6(1)(f)
Anonymous usage counters: page count, document type, native or scanned, success or failure, whether the balance check passed, processing costService statistics and capacity planning. These counters carry no personal data and no file names.Legitimate interests, Article 6(1)(f)
Page-view counts. We count page views without cookies or identifiers: the page path, the referring site's hostname, and a campaign tag when the link carries one. Nothing in that record identifies you.To see which pages are read and where visitors arrive fromLegitimate interests, Article 6(1)(f)
Your email address, if you create an accountTo create your account, send you a sign-in code, hold your credit balance and send receiptsPerformance of a contract, Article 6(1)(b)
Sign-in codes: a hash of the six-digit code, its expiry and the number of attemptsTo sign you in, and to stop code guessingContract and legitimate interests, Articles 6(1)(b) and 6(1)(f)
Your credit balance and the ledger behind it: purchases, deductions, refunds, subscription renewalsTo show what you have and to honor refundsPerformance of a contract, Article 6(1)(b)
Your conversion history: date, page count, document type, whether the balance check passed. We do not record file names, bank names, account numbers or anything from inside your statement.To show you what you have used, and to support youPerformance of a contract, Article 6(1)(b)
Name, email, billing country and purchase detailsSelling you credits and plans, issuing invoices, collecting VAT and sales taxContract and legal obligation, Articles 6(1)(b) and 6(1)(c). Collected by Polar as merchant of record.
Messages you send through the contact form or by emailTo answer youLegitimate interests, Article 6(1)(f)

We process no special-category data deliberately. A bank statement can incidentally reveal, for example, a payment to a hospital or a political party; we neither look for that nor derive anything from it, and the file is deleted when the conversion ends.

Whether you have to give us anything. Nothing here is a statutory requirement. Uploading a statement is what the conversion is made of, so without a file there is nothing to convert. An email address is needed to hold a credit balance and to send a receipt, so an account cannot exist without one. Everything else is optional, and leaving it out costs you nothing but a reply.

Automated decision-making. Extraction and the balance check are automated, but they produce a spreadsheet for you to review. We take no decision about you by automated means that produces a legal effect or similarly significantly affects you, within the meaning of Article 22. We do not profile you and we do not build a behavioral record of your use.

4. Recipients and sub-processors

We keep the supply chain deliberately small. These are the recipients of personal data, in full:

Every recipient of personal data, what they do and where they are
RecipientWhat they doWhere
AI document-processing providerReads the uploaded document and returns structured transaction data. Contractually barred from training on it; deletes inputs within 30 days.United States, under a data processing agreement and standard contractual clauses
Cloudflare, Inc.Serves the website, terminates TLS, blocks automated abuse, runs the code that performs the conversion, routes email.Global edge network; company established in the United States
Polar Software Inc.Merchant of record: sells you credits and plans, takes payment, issues your invoice, handles VAT and sales tax. An independent controller for your billing data under its own privacy policy.United States
Resend, Inc.Outbound transactional email: sign-in codes, purchase receipts and replies to your support messages. Receives your email address and the content of the message we send you.United States

This is the complete list. We use no analytics provider, no advertising network, no session recording, no CRM and no data broker. We do not sell or share personal information. If this list changes, it changes here first and the "last updated" date moves; account holders are told by email before a new sub-processor starts work, as set out in the data processing agreement.

We will tell you exactly who our providers are if you ask. Email support@statementtable.com and we will name the AI document-processing provider and send you a copy of the transfer safeguards we rely on. The data processing agreement we sign with business customers names every provider individually.

We disclose personal data to a public authority only where the law of a jurisdiction that binds us requires it, and we tell the affected account holder unless we are legally barred from doing so.

5. Cookies and local storage

We set no tracking cookies. There are no advertising pixels, no third-party analytics scripts, no session recording and no cross-site trackers on this site. That is why you have never seen a cookie banner here: under the ePrivacy Directive and UK PECR, consent is required for non-essential cookies, and we use none.

Two things can be stored in your browser. This is the complete list.

Everything that can be stored in your browser
CookieSet byWhat it doesHow long it lasts
__Host-st_sessionUsKeeps you signed in. It is HttpOnly, Secure and SameSite=Lax, it carries a random value that means nothing outside our database, and it is set only if you create an account and sign in. Browse the site or use the free tier without signing in and it is never set.30 days, or until you sign out
cf_chl_*, Cloudflare's challenge cookiesCloudflare, on the converter and the sign-in pageWe use Cloudflare Turnstile there to tell a person from a script. If it has to show you a challenge, Cloudflare stores a short-lived value so you are not asked again on the next page. Nothing in it identifies you to us, and we cannot read it.About an hour, set only when a challenge appears

Neither one needs your consent, because both are strictly necessary for the service you asked for within the meaning of Article 5(3) of the ePrivacy Directive and regulation 6(4) of PECR: the first delivers the sign-in you requested, and the second is how the free tier survives contact with automated traffic. Cloudflare classifies its challenge cookies the same way. Neither is used for advertising, neither builds a profile of you, and neither is shared with anyone.

We store nothing else in your browser: no local storage, no session storage, no fingerprinting of our own, and no cookie at all on the pages you can use without an account.

6. International transfers

StatementTable is operated from Türkiye. Our providers process data in the United States and on a global edge network. Personal data is therefore transferred outside the UK, the EEA, Australia and Canada.

Where we transfer personal data out of the UK or the EEA to a provider in the United States, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, or on the provider's certification under the EU-US Data Privacy Framework where it holds one. We carry out a transfer risk assessment for each provider and apply supplementary measures: encryption in transit for every hop, no statement contents in logs, and a contractual bar on training. You can request a copy of the safeguards that apply to a given transfer at support@statementtable.com.

  • Customers in Australia: we are likely to disclose personal information to overseas recipients located in the United States and Türkiye.
  • Customers in Canada: your information may be processed outside Canada, including in the United States, and while it is there it may be accessible to the courts, law enforcement and national security authorities of that country under that country's laws.
  • Customers in Türkiye: transfers abroad are made on the basis of Article 9 of Law No. 6698 (KVKK), relying on appropriate safeguards or on your explicit consent, as applicable.

7. How long we keep things

This is the complete retention schedule.

The complete retention schedule
WhatHow longSet by
Your uploaded statement and the transactions extracted from itNot retained. Held in the memory of the request that converts it and gone when that request ends. Nothing survives an hour.Us
The copy held by our AI document-processing providerDeleted within 30 days, and never used for trainingThat provider, under our agreement with it
Salted IP hash and today's free-tier page count48 hoursUs
Anonymous counters, including page-view countsKept indefinitely. They hold no personal data and cannot be linked back to you or your file.Us
Your email address, credit ledger and recent conversion historyUntil you delete your account. Your email address goes, and the ledger entries are pseudonymized: the identifier on them is replaced with a short code that carries no name and no email address, and they are then kept only as accounting records.You, at any time
Sign-in codes10 minutes, then deletedUs
Purchase and invoice recordsKept for the period required by tax and accounting lawPolar, as merchant of record
Support and contact-form messages12 months, then deletedUs
Operational request logs kept by the hosting platform: time, path, response status, error type and page counts, with nothing from inside a statement in themCloudflare's own retention period for platform logs. We neither extend it nor copy the logs anywhere else.Cloudflare

8. Your account

Accounts are optional. If you create one, we store your email address, your credit ledger and a short conversion history: counts and dates, never file contents. You sign in with a single-use six-digit code sent to your email; there is no password. You can delete your account yourself from your account page, or by emailing us. Deletion is immediate and permanent: your email address is removed, and the identifier on your ledger entries is replaced with a short code that carries no name and no email address, so the accounting record survives without you in it. Unused credits are forfeited on deletion, so request a refund first if you are within the refund window.

9. Your rights

Depending on where you live, you have the right to ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we rely on it. Where we process on the basis of legitimate interests, you can object at any time and we will stop unless we have compelling grounds that override yours. You also have the right to be told the identity of the recipients of your personal data: ask, and we will name them.

Because we do not retain statement contents, there is usually nothing to delete from a conversion. Deletion requests concern your account, which you can delete yourself, immediately and permanently, from your account page; your support emails; and the purchase records held by Polar as merchant of record. We pass purchase-record requests on to Polar and tell you what happens.

Email support@statementtable.com. The person who operates the service is the privacy contact accountable for these requests, including under Canadian law. We reply within 30 days, usually within one business day, and we do not charge for these requests. We will never treat you differently for exercising a right.

Complain to us first if you want to. Email support@statementtable.com, or use the contact form and pick "Privacy, security or a data request". We acknowledge a complaint about how we handle personal data within 30 days of receiving it, usually the same day, then look into it and tell you what we find and what we do about it. You can also use the form to ask for a copy of your data, to correct it, or to have it deleted.

Complaints. You can complain to a supervisory authority, in the country where you live, where you work, or where the matter arose. That is the ICO in the United Kingdom, your national data protection authority in the EU and the EEA, the OAIC in Australia, the OPC in Canada, and the Kişisel Verileri Koruma Kurumu in Türkiye. You do not have to come to us first, though we would rather fix it.

10. Security

All traffic is encrypted in transit with TLS, both between you and us and between us and every provider above. Statement contents are never written to logs. Access to production infrastructure requires two-factor authentication. Secrets are held in the platform's encrypted secret store, never in source code. Sign-in uses a single-use emailed code, so there is no password database to lose. Card numbers never reach our systems.

The controls we operate, the path a file takes and the companies involved at each step are set out in full on the security page. The contractual form of the same controls is in the data processing agreement.

If a personal data breach occurs, we notify the supervisory authority within 72 hours where Article 33 requires it, and we notify affected account holders by email without undue delay.

11. Data processing agreement

If your firm needs a written processor agreement before it can upload client statements, our data processing agreement is on this site in full. It takes effect when you use the service, so you can file it and move on. It covers subject matter and duration, the categories of data and data subjects, confidentiality, security measures, sub-processors and change notification, transfers, assistance with data subject requests, breach notification, audit rights, and deletion at the end.

12. Children

The service is intended for adults and businesses. We do not knowingly process the data of children under 16.

13. Changes to this policy

We post changes on this page with a new "last updated" date. Material changes to what we collect or who receives it are announced by email to account holders before they take effect.

Data Processing Agreement · Terms of Service · Refund Policy · Security and data flow