Current processing and retention details

How StatementExport processes and retains bank statements

Understand where extraction runs, which providers may process data, when files are scheduled for cleanup, and how to delete a conversion you no longer need.

Cloud processing · local extraction and OCR · scheduled retention · conversion deletion controls

Local extraction and OCR

Digital PDF text and scanned pages are processed within StatementExport application infrastructure; scanned pages use local Tesseract OCR.

Scheduled file cleanup

Guest statement files and extracted content follow the 24-hour session schedule. Signed-in and organization originals and exports follow a 7-day schedule.

Conversion deletion control

Signed-in and organization normalized transactions remain with conversion history until the owner explicitly deletes that conversion.

A cloud service with defined data boundaries

StatementExport is a cloud service: an uploaded PDF leaves your device and is stored and processed in configured application infrastructure. Digital text extraction and Tesseract OCR run locally within that infrastructure. In the current implementation, statement documents are not sent to an external OCR, AI, or language-model provider for extraction.

Local extraction does not mean that no provider processes data. Configured hosting, object storage, database, email, monitoring, analytics, authentication, and payment providers process the data needed for their roles, as described in the Privacy Policy. Statement files are not provided to payment, email, or Telegram providers for extraction. Production provider identities and locations are not yet final.

Access to conversions, source pages, exports, and organization data is checked against the guest session, user account, or organization role. Downloads use backend permission checks or short-lived links. These controls reduce exposure but do not make any cloud system risk-free.

Retention separates replaceable files from useful conversion history. Originals and generated exports use short scheduled windows. Normalized transactions for signed-in users and organizations remain available for review and repeat export until the conversion is explicitly deleted.

Synthetic retention example

Different data follows different schedules

This illustrative status table explains the current defaults. It does not show a real conversion or promise deletion at an exact minute.

Illustrative events
Guest session expires · 18 Jul 2026, 10:00 UTC
Account conversion created · 17 Jul 2026, 10:00 UTC
Owner selects · Delete conversion
Current default handling
Current default handling
DataDefault scheduleAvailable control
Guest statement content 24-hour sessionHourly cleanup
Account/org original 7 daysDelete conversion
Account/org export 7 daysDelete conversion
Normalized rows While history remainsDelete conversion
Minimal operational record Retained after purgeNo statement content

Schedules are processed by cleanup jobs, so deletion may occur after the stated expiry rather than at that exact instant.

Data lifecycle

What the current controls mean in practice

Guest data is temporary

Guest originals, exports, extracted statement data, and normalized rows are scheduled for purge after the 24-hour guest session expires; cleanup runs hourly. A minimal deleted-status operational record remains without statement content.

Account files have a separate window

Original PDFs and generated exports for signed-in users and organizations are scheduled for deletion after 7 days.

History stays until you remove it

Normalized transactions for signed-in and organization conversions remain in conversion history until the conversion is explicitly deleted.

Processing lifecycle

From upload to scheduled cleanup or deletion

  1. 1. Validate the upload

    The service accepts PDF files up to 25 MB and 50 pages. It validates file properties and rejects password-protected PDFs.

  2. 2. Extract inside app infrastructure

    The worker tries digital text first and uses local Tesseract OCR for scanned pages. Raw statement content is excluded from application logs by policy.

  3. 3. Review through authorized access

    Session, account, and organization-role checks protect conversion, source, and export access. Downloads use checked responses or short-lived links.

  4. 4. Follow retention or delete the conversion

    Cleanup jobs process scheduled file expiry. The conversion deletion control removes normalized transactions, extracted statement data, and files still stored, while retaining a minimal deleted-status operational record.

Scope and limitations

What this page does not claim

These are current product behaviors, not a certification, compliance conclusion, or promise that processing is risk-free.

  • Guest use is not described as anonymous: guest sessions and operational network data are still processed.
  • Scheduled deletion is not immediate deletion at an exact timestamp; cleanup jobs process expired data.
  • Signed-in and organization normalized transactions are not removed by the 7-day file schedule; they remain until explicit conversion deletion.
  • Cleanup and explicit deletion retain a minimal operational record with status, ownership or session association, file and page counts, processing metadata, and timestamps; statement content and filenames are purged.
  • StatementExport does not claim bank-grade security, GDPR compliance, encryption at rest, malware scanning, or external security certifications on this page.
  • The Terms and Privacy Policy remain pre-launch drafts because the final operator, production processors, hosting regions, contacts, and jurisdiction still require completion and legal review.
Processing questions

Security, retention, and deletion FAQ

Does my statement stay on my device?
No. StatementExport is a cloud service. The PDF is uploaded to application infrastructure, where text extraction and local Tesseract OCR run. Operational providers still process data as disclosed.
When is guest statement content purged?
The original, exports, extracted statement data, and normalized rows are scheduled for purge after the 24-hour guest session expires. Cleanup runs hourly, so deletion is not promised at the exact expiry minute. A minimal operational record remains.
What is scheduled after 7 days?
Original PDFs and generated exports for signed-in users and organizations. Their normalized transactions remain in conversion history until the conversion is explicitly deleted.
What does Delete conversion remove?
The deletion workflow removes normalized transactions, extracted statement data, and any original or export files still stored. It retains a minimal deleted-status operational record without statement content.
Who can access a conversion or download?
Access is checked against the guest session, signed-in account, or organization role. Downloads use backend permission checks or short-lived links.

How StatementExport processes and retains bank statements

Cloud processing · local extraction and OCR · scheduled retention · conversion deletion controls

Convert one PDF free