What happens to your statement
Bank statements carry account numbers, salaries and spending. You should know exactly where one goes when you upload it, so here's the whole path, in plain English.
A statement you upload is sent over an encrypted connection to our conversion service, read in memory, checked, and the result returned to your browser. The file is not written to a database, storage bucket or backup, and it's never used to train AI. If the PDF is password-protected, the password is used in your browser and never reaches us.
From upload to download
Unlock in your browser
Locked PDFs are opened on your device. The password is never sent.
Sent over TLS
The page content travels encrypted to our conversion service.
Read in memory
Transactions are extracted and checked against the closing balance.
Discarded
The result goes back to you. The file isn't stored anywhere.
What we do, and don't do
Statements aren't kept
No database, no object storage, no backups. Extracted transactions are returned to you and not retained on our servers.
Never used to train AI
Your statements are not used to train any model, ours or anyone else's. We don't sell data either.
No access to your bank
We never connect to your bank. You give us a file; there's no login, no feed, no standing access.
Read-only accounting connections
If you connect Xero or QuickBooks, we can read your organisation details and nothing we do changes your books.
We never see card details
Payments are taken by Dodo Payments as merchant of record. We only learn which plan you're on.
No passwords stored
Sign-in is by Google or an emailed link, so there's no account password to leak. Statement passwords stay in your browser.
What we don't have yet
Export Bank Statement is a small, independent product. We don't hold SOC 2 or ISO 27001 certification, and we don't offer SSO, audit logs or a signed SLA today. If your organisation needs any of those, tell us what you need and we'll give you a straight answer on whether and when.
What we can do today is keep as little data as possible, name every provider that handles it, and answer security questions directly. You're emailing the person who built it.
Responsible disclosure
Found a security issue?
