A narrow, verifiable privacy boundary

Statement contents stayinside the conversion workspace.

PDF parsing, local OCR, transaction editing, and export generation happen in your browser. Account, billing, and optional analytics use separate network requests without statement contents.

Your browserPDF, extracted rows, edits, exports
Account Billing Optional analytics
Statement text and transaction contents do not cross this boundary for conversion.
The data boundary in plain language

What stays local, and what uses the network.

Browser-based does not mean the entire website is offline. It means the sensitive conversion payload is kept separate from the services used to deliver and operate the product.

Stays in the browser

Statement conversion data

  • The statement PDF or pasted statement text
  • Extracted OCR and text-layer content
  • Transaction descriptions, amounts, and balances
  • Edits made in the review workspace
  • Generated CSV, XLSX, JSON, QBO, OFX, and QIF contents
Uses network services

Product operation data

Application delivery

Your browser downloads the application code and may fetch PDF or OCR worker assets needed to run the converter.

Account status

Google sign-in and plan status use network requests. Statement contents are not attached to the account.

Billing

Stripe checkout, subscription status, and the billing portal are networked separately from conversion data. Job Pass limits use an opaque, atomic entitlement record with no statement contents.

Optional analytics

When product analytics are enabled, they can record product events without statement text, transaction rows, balances, or file contents.

Security without decorative badges

Concrete controls are more useful than invented certification claims.

StatementForge describes the architecture it can support today. It does not claim bank affiliation, universal statement compatibility, or a certification that has not been independently earned.

Minimize the sensitive path

The backend is not part of the statement parsing or export path.

Keep review visible

Extracted rows remain visible and editable before a financial file is generated.

Separate identity and billing

Account and subscription records do not need statement contents.

State practical limits

OCR, PDF layouts, and destination import rules can produce results that need correction.

Your side of the boundary

Use a trusted device and review the result.

Local processing reduces server exposure, but it cannot secure an infected device, an untrusted browser extension, or an export shared to the wrong destination.

  • Keep the browser and operating system current
  • Avoid converting documents on a shared or untrusted device
  • Compare generated rows with the source statement
  • Store and share the downloaded export appropriately
Keep the document out of the backend

Convert the statement in a browser-local workspace.

Review the rows before saving or importing the generated file.

Convert a statement Review the workflow