Private by architecture.
Financial documents deserve narrow access, limited retention, and safeguards that are easy to understand.
Private storage and access
Source statements are stored in private cloud storage rather than a public bucket. Application data uses row-level access controls, and every document, conversion, feedback, and download request is checked against its owner. Short-lived signed links are used only where needed, and privileged credentials stay on the server.
Document processing
Only pages covered by the current preview or plan allowance are submitted for extraction. Locked pages are not submitted. Larger inputs may use a temporary provider file, which StatementMint requests to delete after processing. The customer-facing spreadsheet contains Date, Description, and signed Amount; users should compare it with the source PDF before relying on it.
Application safeguards
StatementMint validates file type, size, PDF structure, page count, ownership, and allowance before processing. We use HTTPS, provider encryption at rest, private storage, server-side credentials, schema validation, signed anonymous sessions, rate limits, and guarded background jobs. CSV and Excel files are generated on demand after an ownership check and returned with no-store response controls.
Monitoring and logs
Operational logs and error monitoring are designed to capture status, timing, counts, and sanitized error categories—not statement bodies, extracted transactions, filenames, form contents, or private document URLs. Product analytics excludes statement content and disables session replay, click and form autocapture, and heatmaps.
Optional feedback and parser improvement
A statement is included with a negative feedback report only when the user selects the separate checkbox. The review copy is private, limited to authorized personnel, and deleted within 30 days or sooner with the conversion or account. Parser improvement is also off by default and uses only a data-minimized structural layout record after an explicit account opt-in; it does not use the PDF or transaction contents.
Retention and deletion
Conversions and their active source files, extracted data, review records, optional feedback attachments, and opted-in layout records expire within 30 days. Scheduled cleanup removes expired data. Users can delete conversions sooner, turn off parser participation, or request account deletion from Plan & usage. Provider backups, security records, billing records, or legally required records may take longer to expire.
Report a concern
No internet service can guarantee absolute security. If you believe an account or document was accessed improperly, signed-in customers should use account support; use the public contact form if you cannot sign in. Include a conversion ID, not the statement itself.