1. Scope
This Privacy Policy applies to the StatementForge website, converter, account features, and related pages. It does not replace the privacy terms of third-party websites you choose to visit.
“Statement contents” means the source document, OCR text, extracted rows, transaction descriptions, dates, amounts, balances, and account identifiers contained in or derived from your statement.
2. What stays in your browser
PDF reading, local image-to-text, transaction parsing, row editing, and export generation run in your browser. StatementForge is designed so those operations do not require sending statement contents to its application backend.
- Source PDFs are not intentionally uploaded to StatementForge for conversion.
- Extracted transaction rows are not intentionally stored in a StatementForge account.
- Statement contents are not used to train models, build advertising profiles, or sell data.
- Closing or refreshing the workspace can remove unsaved work; download any export you need to keep.
Converter files and extracted rows remain in memory in the active tab rather than local or session storage. The app may keep your analytics choice and best-effort entitlement or authentication-change signals in local storage. Clearing browser data can remove that local information.
3. Information handled outside the converter
4. How limited information is used
- Authenticate users and connect paid entitlements to the correct account.
- Process purchases, maintain subscriptions, prevent billing abuse, and provide receipts.
- Operate, secure, debug, and improve the website and converter.
- Measure broad product performance, such as whether parsing or an export succeeded.
- Respond to support, privacy, refund, or security requests.
- Meet legal obligations and protect users, the service, and third parties.
5. Service providers
StatementForge relies on providers for functions that cannot happen entirely inside the converter. Their own terms and privacy policies govern their processing:
- Cloudflare for hosting, content delivery, network security, the Job Pass entitlement ledger, and associated traffic measurement.
- Google when you choose Google authentication and, only after consent, for optional Google Analytics.
- Stripe for checkout, payment processing, subscriptions, and billing management.
- Discord or Slack, only if the operator enables the optional support-queue webhook, for a generic operational alert that does not include customer contact information, request contents, a support reference, or a private status token.
StatementForge does not authorize these providers to receive source documents for conversion.
6. Cookies and browser storage
Authentication uses cookies or equivalent session technology to keep you signed in. Stripe may use its own cookies during checkout. Converter files, extracted rows, and temporary review state stay in active-tab memory rather than local or session storage. Local storage may hold your analytics choice and best-effort cross-tab entitlement or authentication-change timestamps. The free real-statement export requires sign-in, and its monthly usage is recorded server-side against the signed-in account. Google Analytics does not load until you allow it. You can reopen “Analytics settings” at any time to change that choice; declining after previously allowing reloads the current page to stop analytics for the session. Paid Job Pass usage is checked against the server-side entitlement ledger using an HttpOnly identity cookie. Browser settings can remove or block this data, although account or paid features may stop working correctly.
7. Retention and security
StatementForge retains account, billing, security, and support records only for as long as reasonably needed for the purposes described above, legal requirements, dispute handling, and fraud prevention. Providers may apply their own retention schedules.
No internet service can promise absolute security. The most important safeguard in StatementForge is data minimization: statement contents are designed to stay on your device rather than being stored in a conversion database.
8. Your choices and requests
You can avoid Google account processing by using features that do not require sign-in. You can also:
- clear browser storage and cookies through your browser settings;
- manage or cancel an eligible subscription through the Stripe billing portal;
- request access, correction, or deletion of account information where applicable; and
- ask a question about this policy through the current method on the Contact page.
Do not attach a bank statement or paste transaction data into a privacy request. Visit the Contact page for the safe details to include.
9. Policy changes
This policy may change as the product, providers, or legal requirements change. The “last updated” date will be revised when material text changes. Continued use after a change means the updated policy applies from its effective date, subject to rights that cannot legally be waived.