Skip to content

Trust

Security at Statement to Sheets

Last updated: June 20, 2026

Template notice: This page describes our intended security posture. Review and confirm each claim against your actual production setup before publishing.

Bank statements are sensitive. Statement to Sheets is built so your data is handled carefully at every step — from upload, through conversion, to download.

Encryption

  • In transit: all traffic is served over HTTPS/TLS, so files are encrypted while moving between your browser and our servers.
  • At rest: in production, uploaded files and generated exports are stored with encryption at rest.

Minimal retention

We keep your files only as long as needed. By default, uploaded PDFs are deleted within 24 hours and generated exports are removed within 7 days. We don't need your statements long-term, so we don't keep them.

Private by design

  • Your files are never sold or shared with third parties for marketing.
  • We avoid logging the contents of your statements; operational logs capture only what's needed to run and debug the Service.
  • Download links are served through authenticated routes rather than exposing raw storage locations to the browser.

Infrastructure

The Service runs on established cloud infrastructure with managed networking, access controls, and database security. File storage is kept separate from our application database, which holds only metadata and references — not raw file blobs.

Responsible disclosure

If you believe you've found a security vulnerability, we want to hear from you. Please email security@statementtosheets.com with details, and allow us reasonable time to investigate and respond before any public disclosure.

Questions

For anything security-related, reach us at security@statementtosheets.com.