Security
Converting a statement means uploading it. These are the concrete rules around that upload — no vague reassurances.
Encrypted in transit
Statements are uploaded over HTTPS only. The conversion path is a server-side upload by design — that is how extraction works.
Third-party recognition, disclosed
Files are processed by us and third-party document-recognition services, which receive the file only to perform the extraction.
Deleted under a stated policy
Uploaded statement files you do not contribute as samples are kept for account download, then deleted under the file retention period on the privacy page. Processing logs exclude statement contents.
No credentials, ever
We never ask for bank logins or accounting-software credentials. You download Excel, CSV, or a separate QBO result; what you do with it happens in your own accounts.
Bulk files stay independent
A bulk selection creates separate conversion jobs. One file failure does not turn successful files into a failed batch or hide their individual status.
Failures stay honest
Files that cannot be reliably parsed return a clear failure status — never a blank or fake-success CSV — and failed conversions never count against your quota.
Minimal analytics
Behavioral events only. Statement contents, account numbers, and transaction descriptions are never sent to analytics tools, and error logs never contain statement text.
Found a security issue? Email hi@statementtobooks.com — we take these reports seriously and respond quickly.