Privacy policy
Last updated: 18 August 2026
The short version
You upload a bank statement PDF. We convert it to a CSV, check that it reconciles, and hand the CSV back to you. The PDF and the CSV are deleted immediately after the conversion finishes. We keep no copy of your statement, no copy of the output, and no transaction data. No human reads your statements.
How statement files are handled
- Uploaded PDFs are processed in memory and in temporary storage on the server that performs the conversion. They are never written to a database or long-term storage.
- Temporary files are deleted in the same request that processes them — immediately after the conversion completes, whether it succeeds, fails to parse, or fails reconciliation. Deletion is not a scheduled cleanup job; it happens before the response is sent.
- The converted CSV is returned to your browser in the response and is not stored on our side.
- Statement processing is fully automated. No person views, reads, or has access to the contents of your statements.
- We do not use your statements or their contents to train models, build datasets, or for any purpose other than performing the conversion you requested.
What we do collect
- Operational metadata. Standard server logs (timestamps, IP address, request status) and non-identifying conversion outcomes (e.g. which bank format was detected, whether reconciliation passed) so we can keep the service reliable. These logs never contain statement contents, transaction descriptions, amounts, or account numbers.
- Payment details, when you buy credits. Payments will be handled by Stripe; we will receive your email address and payment status, never your full card details. (Purchasing is not yet live — the service is free while in beta.)
What we don’t do
- We don’t retain statement or transaction data.
- We don’t sell or share data with third parties.
- We don’t require an account to use the converter during the beta.
- We don’t access your bank. You upload a PDF you already have; we never connect to a bank account or ask for credentials.
Data location and security
Conversions run over HTTPS. Because statement files are discarded immediately after processing, there is no stored statement data to breach. Operational logs are access-controlled and retained only as long as needed for reliability and abuse prevention.
Your rights (Australian Privacy Principles)
We aim to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Since we don’t retain your statement data, there is generally nothing personal to access or correct after a conversion — but you can contact us about anything in this policy, and we’ll respond promptly.
Contact
Questions about this policy: privacy@cleanstatements.com. If this policy changes, the date at the top of this page will be updated.