Skip to content

Privacy policy

What we collect, and what we never see

Most privacy policies describe how carefully a company handles your data. This one is mostly a list of things we never receive. Conversion runs inside your browser, so your statement is never uploaded — there is no copy of it for us to protect, sell, lose or be compelled to hand over.

Last updated 27 September 2026.

What never reaches us

  • Your bank statements, or any part of them
  • Transactions, balances, dates, descriptions or amounts
  • Account numbers or sort codes
  • Passwords for protected PDFs
  • Any copy, backup, cache or archive of the above
  • The names of the files you convert

You can verify this: open your browser's network tab while converting a statement. No request carries the file.

What we do collect

Nothing here is required to convert a statement. It exists so an account can hold a plan.

Your Google account identifier, email address, name and profile picture

Why: To sign you in and attach a plan to an account, so what you buy works on any device.

When: Only if you choose to sign in. Anonymous conversion needs none of it.

The email address you give Stripe, if you buy credits without signing in

Why: To record whose purchase it is, and so we can reunite you with your credits if your browser’s data is cleared before you move them to a Google account.

When: Only if you buy Pay As You Go credits without signing in.

If you convert without signing in: a random browser identifier, a one-way hash of your network address, and how many free pages were used

Why: So the free page cannot be reset by clearing your browser or opening a private window. The address itself is never stored; the hash cannot be turned back into it without our secret key. Nothing about your statement is part of it.

When: Only when you use the converter without an account. Records are deleted after two days.

A Stripe customer identifier

Why: To link your account to your billing history without us handling card details.

When: Only if you start a purchase.

Your plan, its status and renewal date

Why: To know what you are entitled to. Written only by Stripe’s webhook, never by your browser.

When: Only while you hold a subscription.

A ledger of page credits bought and spent

Why: So non-expiring credits can be counted, and a disputed charge can be answered.

When: Only if you buy credits.

A count of pages and files you have converted

Why: To meter your allowance. It is a number, not a record of what you converted.

When: Only while signed in.

Anonymous product measurements: how many files you selected, how many pages converted, how long it took, whether the balance check passed, and which bank the layout was recognised as

Why: To find out which statements this tool handles badly and fix them, and to see where people give up. Filenames, rows, amounts, balances and account numbers are never part of it — only counts and the parser’s own verdict.

When: On every visit, unless your browser sends “Do Not Track” or Global Privacy Control, in which case nothing is sent at all.

Who else is involved

Google

Sign-in only. We receive the identity details listed above when you choose to sign in. We never send Google anything about your statements.

Stripe

Payments. Card details go directly to Stripe and never reach us. Stripe tells us that a payment succeeded and for which plan, and - for a purchase made without signing in - the email address you entered at checkout.

Cloudflare

Hosting and the database holding the account records above. Statements never reach it, because conversion happens on your device.

PostHog

Product measurement. It receives the anonymous counts described above and nothing else. No analytics library is loaded into this site, so there is no session recording and no automatic capture of what is on your screen — each measurement is a short list of numbers sent deliberately.

We do not sell or share your data with anyone else. There are no advertising networks and no third-party AI providers involved in this site. The one measurement service listed above receives counts about conversions, never their contents.

Cookies and browser storage

Two cookies. s2s_session is set when you sign in, or when you return from buying credits without signing in; it holds a signed session identifier and exists solely to keep you signed in. s2s_anon is set when you use the converter without an account; it holds a random identifier and exists solely to count your free page. Both are HttpOnly, so scripts cannot read them. There are no tracking or advertising cookies, which is why this site has no cookie banner.

Your light or dark theme preference is kept in your browser's own storage and is never transmitted.

A second value there, s2s_anon_id, is a random identifier used to group the anonymous measurements above so that one visit is not counted as several. It identifies a browser, not a person, is not set at all if your browser asks not to be tracked, and is discarded when you sign out.

How long we keep it

Account records are kept while your account exists. Billing and usage records are kept for as long as tax and accounting rules require us to be able to explain a charge.

There is no retention period for your statements, because there is nothing to retain. Closing the tab ends their existence.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and everything attached to it. Email [email protected] and we will action it within 30 days.

Deleting your account removes your identity, plan and usage records. Records Stripe holds about completed payments are subject to their own retention rules and to the accounting obligations above.

If you are in the UK or EU, our basis for holding account records is performing the contract you entered into when you signed in or purchased, and for billing records it is a legal obligation. You may complain to your local data protection authority.

Changes and contact

If this policy changes materially we will update the date above and, for anyone with an account, say so by email. Questions go to [email protected].

See also our terms of service and the security overview.