Security and data handling
Bank statements contain some of the most sensitive data a business has. Here is exactly what happens to yours.
Last updated
In short
- Files travel over HTTPS (TLS 1.2+) and are encrypted at rest with AES-256-GCM using a per-deployment key.
- Original uploads are deleted automatically 24 hours after conversion. Extracted transactions are kept for your plan's history window (1 day on Free, up to 90 days on Business) and can be deleted at any time.
- Statements are processed through the OpenAI API with storage disabled; API data is not used to train models.
- Passwords are hashed with bcrypt. Sign-in with Google or Microsoft is supported, and email addresses must be verified.
- Payments are handled by Polar; we never see or store card numbers.
Encryption
Every uploaded file is encrypted before it touches disk using AES-256 in GCM mode, which also detects tampering. Encryption keys are held in server configuration, separate from the files.
Retention and deletion
A scheduled clean-up job removes original files 24 hours after processing and deletes jobs once your plan's history window ends. Deleting a job removes its file and data immediately; deleting your account (Settings › Delete account) removes everything. See how to delete your data.
AI processing
Text and images from your statement are sent to the OpenAI API only to extract transactions. Requests are made with response storage disabled, and API data is not used for training. See our subprocessors.
Application security
- Strict security headers (HSTS, frame denial, content-type sniffing protection).
- Rate limiting on authentication endpoints, verified email required before uploading.
- Each user can only access their own jobs; every request is authorised server-side.
- Payment webhooks are verified with signed secrets.
Reporting a vulnerability
Email support [at] docuclipper [dot] net with details. We acknowledge reports within two business days. See also security.txt.
Frequently asked questions
Do you use my statements to train AI?
No. Statements are processed via the OpenAI API with storage disabled, and API data is not used to train models. We don't train our own models on customer data either.
How long do you keep my files?
Original files are deleted 24 hours after conversion. Extracted data follows your plan's history window and can be deleted immediately.
Can I self-host?
The application can be deployed on your own server with your own database and API keys, so statements never leave infrastructure you control.
Convert your first statement in under a minute
20 free pages every month. No credit card. Every export format included.