Privacy
Last updated 12 August 2026
What we keep, and for how long
- Uploaded PDF files are deleted within 1 hour of upload. A sweep runs every half hour and takes everything already due, so the deletion always falls inside that hour — usually well inside it. They are stored in a private bucket in the meantime and are never public. This does not apply to a statement you have filed into a case, which is kept for as long as that case says — see the next point.
- Parsed transaction data and generated exports are deleted within 24 hours of upload. After that the job row keeps only non-financial metadata (bank name, page count, whether it reconciled) for support and abuse handling. This does not apply to a statement you have filed into a case, which is kept for as long as that case says — see the next point.
- Cases keep statements for as long as you choose, and only if you make one. A case is something you create deliberately, for work that needs several statements read together — finding charges worth asking a bank about, putting together proof of income, or going through an account you look after. When you create one you choose how long its statements are kept: 30 days, 90 days, a year, or until you delete them. Both the PDF and the parsed data are kept for that long, which is the point of it: the work is impossible against documents that have already gone. You can shorten that window at any time, and deleting the case deletes its statements. Nothing is kept this way unless you build a case — everything else follows the two rules above.
- If you have an account, we keep your email, plan, and page-credit balance for as long as the account exists. If you signed in with Google or Apple, that is where the email came from: we ask those providers only for your name, email address, and profile picture, we never receive a password, and we never ask for access to anything else in the account — no Gmail, no Drive, no contacts, no calendar. That data identifies your account and is used for nothing else: we do not sell it, share it, or use it to train anything.
- If — and only if — you switch on “Remember my category corrections” in your account, we keep the merchant names your bank printed alongside the categories you chose for them, so the same merchant is filed the same way next month. Only your own corrections are stored, never our guesses. No amounts, dates, balances, or bank names go with them, and each one expires after 400 days. The setting is off until you turn it on, and turning it off deletes everything it stored. You can also delete them all at any time from your account page.
- Counts of how well statements parse. When a statement is exported we add one to a weekly tally: the currency, the bank name printed on the statement, how many pages it had, whether the balances reconciled, and whether you corrected any date or amount before exporting. That is the whole of that record. There is no link to you, no link to the statement, and no date more precise than the week — a row says “twelve statements like this parsed cleanly” and cannot say whose they were or what was on them. We use it for one thing: to find out which countries and banks the parser genuinely handles, so we can say so honestly instead of guessing.
- A second tally: counts of what looked wrong. Every time a statement is parsed — not only when one is exported — we add one to a separate weekly tally: the currency, the bank name, whether the balances reconciled, and, if something looked off, which of four fixed checks noticed and whether the gap was the size of one row or of several. Never an amount, never a row, never a description. The checks read the parsed result back against what the document says about itself, because a parse can drop an entire account and still add up perfectly. Counting at parsing rather than at export means the statements people gave up on are counted too, and those are the ones worth fixing. Until at least five statements from the same bank fall in the same week, that bank is recorded as “other”, so no row here can ever be about a single document.
- Statements that don’t parse cleanly, blanked out. If a statement does not come out right and you have not switched this off in your account, we keep a copy of its layout with every digit replaced by 9 and every letter by x — so a line reads
99/99/9999 Xxxxxxxx XXX Xxxx -9.99 999.99. No name, amount, date, account number or merchant survives it, there is no key and nothing to reverse, and two different statements with the same layout produce identical copies. A statement is only kept when something said it came out wrong — one of our own checks, or you telling us so — each is deleted after 180 days, and switching it off in your account deletes the ones already kept. It is on unless you turn it off, because what it keeps is not about you — the merchant setting above stores real names and stays off until you ask for it. Nothing is kept from statements uploaded without an account. - Anything you write in “Something wrong with this statement?”. That box is the only place in StatementSnap where you decide what is kept, so it is the only thing here we have not built to be meaningless: whatever you type is stored as you typed it, alongside which of our own checks had already fired. We keep it for 180 days and use it to fix the parser. It is never sent anywhere else and it is never used to contact you unless you put an address in it yourself.
Those five are the only things about your statements that outlive the 24-hour window above. Separately, we measure site traffic — described next. A case is a further exception: statements you file into one are kept for as long as you chose for that case, and the choice is yours to shorten.
Traffic measurement
We use Google Analytics to understand how people find and move around this website, and to see which of our advertising actually brings anyone here: which pages were visited, which site referred you, the rough location Google derives from your IP address, and your device and browser type. Google sets cookies (named _ga and similar) so it can tell a returning visitor from a new one. This starts on your first page view, and the banner appears alongside it rather than before it — so measurement has already begun by the time you see the choice. Choosing “Stop measuring” ends it and deletes the cookies Google has set; “OK” only closes the banner, because nothing was waiting on it. Your choice is remembered for a year.
The iOS app measures the same steps by a different route. There is no Google software in it. The app sends the same fixed list of events to our own server, which passes them on to the same Google Analytics property, so the website and the app are one picture rather than two. No cookies are involved, because an app has none: instead it invents a random identifier the first time it runs, keeps it on the device, and sends that, so one sequence of steps can be told apart from somebody else's. It is not your account id, it is never sent alongside one, and deleting the app deletes it. There is no measurement banner in the app and no way to switch this off from inside it. What does hold there is everything below about statement contents.
We also record which steps people reach, so we can see where the product fails them: that a statement was uploaded, how many pages it had, how long it took, whether the balances reconciled, whether it failed and in which of a handful of fixed categories (for example “password protected”), how many rows were corrected, which export format was chosen, whether an export was refused and why, and that a signup or purchase happened. Purchases carry the amount you paid us and its currency.
Nothing about the contents of your statements goes to Google Analytics. Not the file, not a transaction, not an amount on it, not a bank name, not the name of anything you download, not an error message — only a category for it, because the message itself can quote your statement. What we send is counts, yes-or-no answers, and words from a fixed list. There is no field on anything we send that could carry a merchant, a balance or an institution, and our page addresses never reference your statement either.
Google processes this under its own privacy policy, and describes how it uses data from sites that use its services here. You can opt out for every site you visit with Google’s browser add-on, or by blocking cookies for this site — neither affects your ability to convert a statement.
Error monitoring and session recording
When something breaks, we send the error to Sentry, a third-party service that collects crash reports so we can find and fix faults. A report says what went wrong, on which page or app screen, in which browser or on which kind of phone, and — if you are signed in — your account's internal id. Every number in an error message is replaced with a # before it is sent, because an error can quote the thing it choked on, and on this product the thing it choked on is a line off your statement. Request bodies, cookies, and the web addresses' query strings are removed entirely rather than masked.
Sentry also records a replay of the page when an error happens — a reconstruction of what was on screen, so we can see the fault rather than guess at it. This happens on the website only. Nothing in the iOS app is ever recorded, and no screen recording is made on your phone under any circumstances. Three things about that are worth stating plainly, because together they are the whole reason it is acceptable on a product like this one:
- Your transaction table is never recorded. Not blurred, not starred out — excluded, so the recording contains a blank placeholder where the table was. That covers every row, every amount, every balance, every merchant, every category, and the shape of the table itself.
- All other text on the page is masked before it leaves your browser, including anything you type. The recording shows layout, clicks and navigation, not words.
- Recordings are only made when something goes wrong. A visit where nothing failed is not recorded at all.
We also send Sentry timing information about our own operations — how long a parse took, how many pages it had, which internal step was slow — together with our own server log lines, which are counts and fixed event names such as “cleanup ran” or “parse failed”. This carries no statement content, on the same rule as everything else above.
Sentry processes this as our data processor under its own privacy policy, and deletes it on a fixed schedule.
Who sees your statements
Statement text (or page images, for scanned statements) is sent to Anthropic’s API to be read into a transaction table. It is not used to train models. Nobody at StatementSnap reads your statements as part of normal operation.
The reconciliation check runs in our own code, not in the model, so a green “Balances reconcile” badge is arithmetic we performed — not something a model asserted.
Payments
Payments are handled by Paddle.com Market Ltd, which acts as the merchant of record — it is the seller shown on your invoice and card statement, and it collects any VAT, GST or sales tax due. Your card details go to Paddle, never to us: we never see or store a card number.
We store the Paddle customer id attached to your account, and a row per purchase recording what was bought and the amount, so we can answer billing questions and grant the right number of pages. You can cancel a subscription yourself at any time from the billing portal linked on your account page. Refunds are covered by our refund policy.
Review invitations
After a purchase, Trustpilot sends you an invitation to review StatementSnap. To do that we copy them on your purchase confirmation, so they receive your email address — and nothing else. They never receive anything about your statements, and nobody who has not bought anything is ever invited.
Every customer is invited, not a selected few, which is what makes the resulting rating worth reading. Declining is handled on Trustpilot’s side, and never affects your account or the emails we send you about it. If you would rather not be invited at all, email support@statementsnap.net and we will exclude you.
Anonymous use
To enforce the free daily limit without accounts, we store a salted hash of your IP address and a date — never the raw address.
Deleting your data
Statement files and parsed data expire on their own within 24 hours. Remembered merchant categories, if you switched that on, can be deleted immediately from your account page — either with “Delete them all” or by switching the setting off, which does the same thing. To delete an account and everything attached to it, use Delete account at the bottom of your account page, or the same control in the iOS app. It removes your profile and everything you uploaded immediately, and cancels any subscription with it — there is nothing to email us about. We keep only a one-way fingerprint of the email address — never the address itself — so the free trial cannot be claimed repeatedly. Statements in a case are kept until the date you chose when you created it; you can shorten that date, or delete the case and its statements, at any time from the case itself.
Who we are
StatementSnap is operated by Sheba Media LLC. For anything about this policy, or to exercise a right you have over your data, write to support@statementsnap.net. Our terms of service and refund policy cover the rest of the relationship.