Security
Last updated 2026-08-24
A bank statement is one of the most revealing documents you own. It names who you pay, what you earn and what you owe. Asking you to upload one is asking for a lot, so this page sets out exactly what happens to it — where it goes, who touches it, how long it lasts and how to get rid of it early.
What happens to your statement
- Upload. Your PDF is sent to our server over an encrypted connection and written to a directory named by a random identifier. Nothing about that path can be guessed from your name, your email or the file’s name.
- Reading. The statement is read page by page. Pages that already contain text are sent as text; scanned pages are turned into images first. Those pages go to a specialist model provider that transcribes what is on them and returns the rows. That provider is the only third party that ever sees statement content.
- Checking. The transactions we get back are reconciled against the statement’s own printed balances. This happens entirely on our server.
- Files. We write your Excel and CSV files next to the upload, in the same random directory, reachable only by you.
- Deletion. All of it — the PDF, the extracted transactions, the Excel file, the CSV — is deleted within 24 hours, or the moment you press the button, whichever comes first.
Limited retention
Your uploaded statement and every file we generate from it are deleted within 24 hours of the conversion. This is not a policy we intend to follow; it is a job that runs on a timer, removes the files from disk and then removes the database rows behind them. After it has run, the conversion cannot be recovered — not by you and not by us.
What we keep beyond that window is deliberately not your statement: if you have an account, we keep your email address, your credit balance and a ledger of credits earned and spent, because those are what your unspent credits are recorded against. The ledger references conversions by their internal id, never by the name of the file you uploaded.
Delete your files immediately
You do not have to wait for the timer. Every finished conversion has a Delete my files button beneath it that erases the uploaded PDF, the extracted transactions and both generated spreadsheets straight away, along with the records of them. Download links for that conversion stop working the moment it completes.
This is the button to use when you are converting someone else’s statement — a client’s, an employer’s — and would rather not leave a copy sitting anywhere at all.
Encryption
In transit. Every request to Bankredo is served over HTTPS, including the upload itself and every download. The pages we send to our extraction provider travel over an encrypted connection too.
At rest. Files live on a private server that no other service and no public network can reach, in directories named by random identifiers. They are held there for at most 24 hours. We do not claim full-disk encryption on that volume, because we would rather under-state what we do than over-state it.
AI and your data
Bankredo does not train anything on your statements. We have no model of our own and no training pipeline, and we keep nothing past 24 hours that could feed one. Your transactions are used to produce your spreadsheet and for nothing else.
Reading a statement requires a specialist model provider, and the pages go to them to be transcribed. We are not going to make a blanket claim about how that provider uses what it receives until we can point at the exact term that says so — if you need that in writing before you upload client work, email us at the address below and we will tell you precisely who it is and what their terms say.
Third-party processing
Bankredo uses outside services for three things, and only one of them ever touches a statement:
- Reading statement pages. A specialist model provider receives the text of a page, or an image of it for scanned documents, and returns the transactions on it. It sees one page at a time and nothing else: no part of your Bankredo account travels with the request — not your email address, not your IP, not which conversion it belongs to.
- Payments. Handled end to end by Paddle, our merchant of record. Card numbers never reach Bankredo, and Paddle never receives a statement.
- Sign-in emails. Sent through Resend, which receives your email address and the link. No statement content.
Access controls
Uploads and generated files are reachable only through the application, and only by the account or browser session that created them: every download re-checks that before it serves a byte. The file paths themselves carry 96 bits of randomness, so a link cannot be guessed, and it stops working as soon as the conversion is deleted or expires. The server that holds them accepts nothing from the public internet but web traffic and key-based administrative access, which is restricted to us — there are no passwords to guess and no database port open to the world.
We do not read your statements. There is no support tool, no admin screen and no internal report in Bankredo that displays the contents of a customer’s conversion, and our application logs deliberately record page counts and timings rather than any of what was on the page — not the transactions, not the balances, not even the name of the file you uploaded.
Deleting everything
Deleting your account removes your email address, your credit ledger and every conversion attached to it immediately. You can do it yourself from the account page; nothing has to be requested from us.
Questions
If you are evaluating Bankredo for client work and need something in more detail than this page gives, ask — we would rather answer than have you guess. [email protected]
The full legal detail — what we store, the lawful basis, cookies, your rights — is in the Privacy Policy. This page is the plain-language version of the same facts; where you need the binding text, that is the document.