Security
Converting a statement means uploading it. These are the concrete rules around that upload — no vague reassurances.
Encrypted in transit
Statements are uploaded over HTTPS only. The conversion path is a server-side upload by design — that is how extraction works.
Third-party recognition, disclosed
Files are processed by us and third-party document-recognition services, which receive the file only to perform the extraction.
Deleted under a stated policy
Files you do not choose to contribute as samples are deleted under the retention policy on the privacy page. Processing logs exclude statement contents.
No credentials, ever
We never ask for bank logins or accounting-software credentials. You download a CSV; what you do with it happens in your own accounts.
Failures stay honest
Files that cannot be reliably parsed return a clear failure status — never a blank or fake-success CSV — and failed conversions never count against your quota.
Minimal analytics
Behavioral events only. Statement contents, account numbers, and transaction descriptions are never sent to analytics tools, and error logs never contain statement text.
Found a security issue? Email hello@statement-to-books.com — we take these reports seriously and respond quickly.