Where your statement goes
You are about to upload a document with your account number and every transaction you made last month. This page is the whole path, step by step, with every company that touches it named or described.
Last updated September 10, 2026
The data flow, step by step
- You pick a file. It is still on your device. On a phone, photos are shrunk in your browser before upload.
- Upload. The file travels over TLS to our edge worker on Cloudflare and is held in the memory of that one request. It is never written to disk, never queued and never copied into a bucket or a database.
- Pages are prepared. For a native PDF, the text layer is read. For a scan or photo, the page image is prepared for the reader.
- Extraction. Page contents are sent over TLS to our AI document-processing provider, which reads the printed table and returns structured rows. The provider is contractually prohibited from training on our data and deletes inputs within 30 days.
- The balance check runs. Entirely on our side. No external service sees the result.
- Exports are built. XLSX, CSV, QBO, OFX, QFX, QIF and JSON are generated from the extracted rows on request.
- The result is sent to you. You review it and download the formats you need.
- Deletion. When the request ends, the file, the page images and the extracted transactions go with it. A conversion takes minutes at most, and nothing survives an hour under any circumstance. What remains is one row in a counter table: page count, native or scanned, whether the check passed, and the cost. No file name, no account number, no transaction text. Separately, page views are counted without cookies or identifiers: the page path, the referring site's hostname, and a campaign tag when the link carries one.
If you close the tab mid-conversion, the same thing is left behind: a counter. The download you already have is the only lasting copy of a conversion, which is why the result is worth saving before you leave the page.
How the file is protected
- All traffic is encrypted with TLS, both between you and us and between us and every provider below.
- Statement contents are never written to logs, not in errors, not in debug output. Logs record page counts and error types.
- The file lives in the memory of one request. There is no bucket, no queue and no database row that holds it.
- Access to production infrastructure requires two-factor authentication and is limited to the operator.
- Secrets are held in the platform's encrypted secret store, never in source code, and the repository is scanned for secret patterns before every release.
- Sign-in uses a single-use code sent to your email address, so there is no password database. The code is stored as a keyed hash, expires in ten minutes, and the attempt counter rises before the comparison so parallel guessing cannot outrun the limit.
- Session cookies carry 32 random bytes and the database holds only a hash of the token, so a copy of the database cannot be turned into a session.
- Uploads are identified by file signature rather than by the name or content type the browser claims, and size and page limits apply before any expensive work starts.
- Exported spreadsheets are sanitized against formula injection, so a transaction description crafted to execute in Excel cannot.
- Payment runs on Polar's checkout. Card numbers never reach our systems.
The four companies that touch anything
| Who | Role | What they get |
|---|---|---|
| Cloudflare, Inc. (United States) | Hosting, TLS, bot protection, email routing | Network traffic and the file while the request that converts it is running. No copy afterwards. |
| AI document-processing provider (United States) | The model that reads the statement | The page contents, during extraction. Bound by a DPA and standard contractual clauses; no training on our data; deletes inputs within 30 days. Named on request. |
| Polar Software Inc. (United States) | Merchant of record: checkout, invoicing, tax | Your email, billing country and payment details. Card numbers never reach us. |
| Resend, Inc. (United States) | Outbound email: sign-in codes, receipts, support replies | Your email address and the message we send you. |
That is the complete list. There is no analytics provider, no advertising network, no session-recording tool, no CRM and no data broker.
We keep the AI provider's name out of marketing copy on purpose. Email support@statementtable.com and we will tell you exactly who it is.
The paperwork your firm needs
If your practice cannot upload a client's statement without a written processor agreement, it is already written and on this site. Our data processing agreement takes effect when you use the service and needs no signature, so you can file it today and start work.
It sets out the subject matter and duration, the categories of personal data and data subjects, confidentiality, the security measures on this page in contractual form, the sub-processor list with 30 days' notice before it changes, the transfer safeguards, our assistance with data subject requests, breach notification within 48 hours, audit and information rights, and what happens to data at the end.
For a countersigned copy on letterhead, a completed security questionnaire, or the sub-processors named individually, write to support@statementtable.com and you will have it back the same business day.
Cookies
We set no tracking cookies. No advertising pixels, no third-party analytics, no session recording, no cross-site trackers of any kind. That is why you have never seen a cookie banner here.
Two things can be stored in your browser, and that is the complete list:
__Host-st_session, ours: an opaque,HttpOnly,Securesession cookie set only if you sign in, so you stay signed in for 30 days or until you sign out. Use the free tier without signing in and it is never set.- Cloudflare's challenge cookies, on the converter and the sign-in page: we use Turnstile there to tell a person from a script, and when it has to show you a challenge, Cloudflare stores a short-lived value, about an hour, so you are not asked again on the next page. It carries nothing that identifies you to us, and we cannot read it.
Both are strictly necessary for the part of the service you asked for, which is why neither needs your consent. We store nothing else: no local storage, no session storage, no fingerprinting of our own. The legal detail is in the privacy policy.
Reporting a vulnerability
Email support@statementtable.com with "security" in the subject line. The same address is published at /.well-known/security.txt. We reply within one business day, we will not take legal action against good-faith research, and we will tell you what we fixed and when. If you would like public credit, say so and you get it. Incidents affecting account holders are announced by email to those affected.
Retention periods, deletion, account closure and your rights under the GDPR, the UK GDPR and KVKK are set out in the privacy policy. That policy is the binding document; this page is the plain-language companion to it.
Convert one and see
Three pages a day are free, and you don't need an account to run your own statement through it.