Skip to content
Free Bank Statement Converter

Security & verification

Your statements stay on your device by default

A privacy policy asks you to trust a promise. This page explains how the tool is built so you can check the promise instead, and exactly where the one optional exception (AI scan) changes things.

Verify it in 60 seconds

Test 1: the Network tab

  1. Press F12 and open the Network tab.
  2. Convert a statement.
  3. You will see no request carrying your file. Apart from Google Analytics page-view pings, the only requests are for the site's own code.

Test 2: the live privacy receipt

Under the converter, the receipt lists requests to other servers made since the page loaded. It is read from your browser's performance log, not reported by us. Expect only Google Analytics; nothing should carry your documents.

How the tool is built

1. Local-only processing

PDF text is extracted with PDF.js, and scanned pages are read with an OCR engine, both running in Web Workers in your tab. The OCR engine and fonts are served from our own origin, not a CDN. The website is a set of static files with no database. The only server-side code is the optional AI scan function described below.

2. A strict Content Security Policy

The page ships with a policy that limits where it can load code from and connect to: our own origin, plus Google Analytics (page-view counts) and Cloudflare's bot check, which is used only if you start an AI scan. We use no ads or tracking pixels, and analytics never sees your documents.

3. No persistence

Statement contents and PDF passwords are held in memory only; a password is cleared as soon as its file is processed. We write nothing about your documents to cookies, localStorage or IndexedDB. The only thing stored is your light/dark theme choice. The Wipe everything button clears the session instantly; closing the tab does too.

4. Optional AI scan

For scanned statements you can choose between private on-device OCR and AI scan. AI scan renders the pages as images and sends only those images (not the PDF, not its password) over HTTPS to our processing function, which passes them to Anthropic's Claude API and returns the result. We do not store the images or output. Anthropic processes data under its own terms. You must tick a consent box every time, and the privacy receipt records that it happened.

5. Safer exports

  • Account numbers are reduced to their last four digits and are not included in downloads unless you opt in.
  • Text that starts with =, +, - or @ is neutralised so a malicious statement description cannot run as an Excel formula.
  • Each Excel and JSON export records a SHA-256 fingerprint of the source PDF, giving accountants an audit trail from document to spreadsheet.

6. Hardened hosting

The site is meant to be served over HTTPS with HSTS, X-Content-Type-Options, Referrer-Policy: no-referrer, a locked-down Permissions-Policy, frame-blocking and cross-origin isolation headers. Dependencies are kept minimal and pinned by a lockfile.

What we can't protect against

Be aware of the limits: browser extensions you have installed can read any page, malware on your device can read your files, and a shared or public computer should not be used for financial documents. Use a trusted device and a browser profile without unneeded extensions.

Report a vulnerability

If you find a security problem, please tell us through our contact page.