Legal
Privacy Policy
How Statement Converter collects, uses, discloses and retains personal data, and the rights available to you in respect of it.
Last updated 12 August 2026
Summary
- Statements you upload are processed solely to produce the output you request.
- Passwords for protected PDFs are held in memory for a single conversion and are never stored.
- Conversion is done by AI models, which read your statement to extract the transactions. They are contractually barred from training on it.
- We do not sell personal data, serve advertising, or use your statements to train machine-learning models.
- Uploaded statements and the sheets made from them are deleted 90 days after conversion. You may delete them earlier at any time.
- You may request access to, correction of, or erasure of your personal data at any time.
This summary is provided for convenience. The sections below govern.
1. Scope and who we are
Statement Converter, operating from New Delhi, India, provides the Statement Converter bank statement conversion service. In this policy, "we" and "us" refer to that operator, and "you" refers to any person who visits the website or uses the service.
This policy explains what personal data we collect, the purposes for which we process it, how long we retain it, and the rights available to you. It applies to the website, the converter and the API.
In respect of your account data we act as the data fiduciary and determine the purposes and means of processing. In respect of statements you upload we process them on your instructions. Where those statements relate to a third party, such as a client whose books you maintain, you are responsible for having the authority to disclose them to us.
2. Personal data we collect
- Data you provide directly. Your name and email address on registration; a password, which is stored only as a cryptographic hash and cannot be recovered by us; your firm or company name, if supplied; and the contents of any message you send through the contact form.
- Data you upload. Bank statement files and the converted output generated from them. These contain transaction records, balances and account identifiers. Financial information is classified as sensitive personal data under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and is handled accordingly.
- Data received from our payment provider. Confirmation that a payment has been made, the amount, and a transaction reference. Card details are collected by the provider and are not transmitted to or stored by us.
- Data collected automatically. IP address, browser type, device type and request timestamps, recorded in server logs, together with the cookies described in section 11.
3. Purposes and lawful bases
We process personal data only for the purposes set out below, and only on the bases stated. We do not process personal data for any purpose incompatible with these.
| Purpose | Data | Lawful basis |
|---|---|---|
| Running your account | Name, email, password (hashed), plan and billing record | Performing the contract you entered when you signed up |
| Converting a statement | The PDF you upload, the pages sent to an AI model to read it, and the sheet produced from it | Performing the contract — this is the service itself |
| Taking payment | Billing name, email, and a payment reference from our provider | Performing the contract — the invoice and its tax record sit with the merchant of record, not with us |
| Answering you | Whatever you write in the contact form, and your email | Consent — you chose to write to us |
| Keeping the service up and secure | IP address, browser and device, and timestamps of requests | Our legitimate interest in preventing abuse and diagnosing faults |
4. Processing of uploaded statements
Statements you upload are processed for one purpose only: to produce the converted output you have requested, in the format you have selected. Processing is automated throughout; no person reads your statement as a matter of course.
Use of AI models. Extraction is performed by artificial intelligence models, which read the pages of your statement in order to identify transactions, dates, amounts and balances. Where a model is operated by a third-party provider, the pages are transmitted to that provider for that purpose alone, under contract terms that prohibit the provider from using the content to train or improve its models and require deletion after processing. The provider is listed in section 6.
We do not:
- use uploaded statements, or data extracted from them, to train or evaluate machine-learning models, whether our own or a provider's;
- analyse them for marketing, profiling, credit scoring or behavioural advertising;
- disclose their contents to any party other than the processors listed in section 6;
- aggregate them to derive insights about you or about any third party whose statements you upload;
- access individual files manually, except where you request support with a specific conversion. Such access requires your instruction, is limited to the file in question, and is logged.
5. Passwords for protected files
Where a statement is supplied as a password-protected PDF, the password you enter is retained in volatile memory only for the duration of that single conversion. It is not written to persistent storage, is not associated with your account, and is not recorded in logs.
Consequently, the password must be re-entered for each conversion of the same file. This is a deliberate limitation adopted in preference to storing credentials that protect financial records.
6. Disclosure and processors
We do not sell, rent or trade personal data. We engage the processors listed below, each of which acts only on our documented instructions and is bound by contract to confidentiality and to appropriate security measures.
| Processor | Function |
|---|---|
| Cloud hosting | Runs the service and stores uploads and output |
| AI model provider | Reads the pages of an uploaded statement to extract the transactions; contractually barred from training on them |
| Dodo Payments | Merchant of record — takes card and UPI payments and issues the invoice; holds the card details, which never reach us |
| Transactional email | Sends account email — sign-in, resets and billing notices |
We may also disclose personal data where required by applicable law or by a binding order of a court or competent authority. Where we are permitted to notify you of such a disclosure, we will do so.
7. Location of processing
Personal data is processed in India. Where a processor listed in section 6 operates outside India, the transfer is governed by our contract with that processor and by the applicable provisions of the Digital Personal Data Protection Act, 2023.
If you are located in the European Economic Area or the United Kingdom, the GDPR page sets out the additional rights and the transfer safeguards that apply to you.
8. Retention
We retain personal data only for as long as required for the purpose for which it was collected, or for such longer period as applicable law requires. The applicable periods are:
| Category | Retention period | Reason |
|---|---|---|
| Uploaded statement PDFs | 90 days after conversion, then deleted automatically | Long enough to re-download or re-run a conversion, no longer |
| Converted sheets | 90 days after conversion, then deleted automatically | The same window as the file they came from — download them before it closes |
| Passwords for locked PDFs | Never stored — held in memory for one conversion | There is no purpose that needs them a second later |
| Account details | While the account is open, then 90 days | The window lets you reopen an account closed by mistake |
Deletion removes data from the live service immediately. Encrypted backups are overwritten within a further 30 days.
9. Security measures
We maintain reasonable security practices and procedures appropriate to the sensitivity of the data, including:
- encryption of all data in transit using TLS, and encryption at rest for uploaded files and generated output;
- storage of passwords as salted cryptographic hashes;
- access to production systems restricted to authorised personnel, individually authenticated and logged;
- non-enumerable object identifiers, so that files belonging to one account cannot be addressed from another;
- routine application of security updates to systems and dependencies.
No method of transmission or storage is completely secure. Section 13 sets out the procedure we follow in the event of a personal data breach.
10. Your rights
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access — obtain a summary of the personal data we process about you and the processing activities undertaken;
- Correction — have inaccurate or misleading data corrected, incomplete data completed, and data updated;
- Erasure — have personal data erased where it is no longer necessary for the purpose for which it was collected, unless retention is required by law;
- Withdrawal of consent — withdraw consent at any time, with the same ease as it was given, in respect of processing carried out on the basis of consent;
- Nomination — nominate another individual to exercise these rights in the event of your death or incapacity;
- Grievance redressal — raise a complaint through the procedure in section 14.
Requests may be submitted through the contact page. We will respond within 30 days. No fee is charged, and you are not required to give a reason. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
11. Cookies
We use only first-party cookies that are necessary for the service to function: a session cookie to maintain your authenticated session, and a preference cookie to record display choices such as the billing-cycle selection.
We do not use advertising cookies, third-party trackers or cross-site analytics. Blocking cookies in your browser will prevent authentication from working.
12. Children
The service is intended for use by adults in a professional or personal bookkeeping capacity and is not directed at children. We do not knowingly process the personal data of any person under 18 years of age. If you believe a child has registered an account, contact us and the account and associated data will be deleted.
13. Personal data breach
In the event of a personal data breach, we will notify the Data Protection Board of India and each affected person in the form and manner prescribed under the Digital Personal Data Protection Act, 2023. The notification will describe the nature of the breach, the categories of data involved, the measures taken or proposed, and the steps you may take to mitigate any resulting risk.
14. Grievance redressal
Complaints regarding the processing of your personal data may be addressed to our Grievance Officer:
The Grievance Officer
Statement Converter
[email protected]
New Delhi, India
Complaints will be acknowledged within 48 hours and resolved within 30 days of receipt. If you are not satisfied with the outcome, you may make a complaint to the Data Protection Board of India. Nothing in this policy restricts that right.
15. Changes to this policy
We may update this policy from time to time. Where a change materially affects how your personal data is processed, we will update the date shown at the top of this page and notify account holders directly. Where a change requires your consent, we will obtain it before the change takes effect.
16. Contact
Questions regarding this policy may be sent through the contact page.