1. Current service scope
The service accepts PDF files only, up to 25 MB and 50 physical pages per file. Password-protected PDFs are rejected; save an unlocked copy before uploading. Scanned pages are processed with local Tesseract OCR and must be reviewed.
CSV and XLSX exports are available. QBO and OFX exports are experimental and require complete metadata for exactly one account and one statement. The service does not provide direct QuickBooks, Xero, or other accounting-platform synchronization.
3. Accounts and access links
Account access supports passwords, Google sign-in when configured, and email magic links that expire after 30 minutes. Password-reset links also expire and can be used only once.
Registration collects an email address and an optional display name. For password accounts, only an Argon2id password hash is stored, never the raw password. If Google sign-in is enabled and used, the service stores the Google subject identifier, verified email address, and profile display name, if available; Google sign-in remains optional and configuration-dependent.
Magic-link and password-reset tokens are stored only as keyed HMAC-SHA256 hashes, not as plaintext tokens. A necessary HttpOnly session cookie maintains access after sign-in. Password and Google registration record the accepted Terms and Privacy versions and the acceptance timestamp.
An authorized security administrator can suspend account access. A suspended account cannot sign in or use an existing session until it is reactivated.
Keep magic links, organization invitations, and client upload links confidential. Depending on their role permissions, organization owners and admins can manage roles and links; documents submitted through a client link belong to that organization and use its shared page credits.
4. Accuracy and review
Text extraction and local OCR can omit, split, merge, or misread transactions and metadata. Scans, image quality, and unusual layouts can reduce accuracy.
The service is a conversion tool, not accounting, tax, legal, audit, lending, or financial advice. Review and correct the rows and statement metadata before relying on an export.
5. Credits, subscriptions, and payments
Each 24-hour guest session can receive one free full conversion for its first eligible PDF of 1 to 5 physical pages. It includes a full preview and full CSV/XLSX exports without sign-up, a card, or page credits. PDFs over 5 pages and conversions uploaded while another PDF owns the free slot receive a preview and CSV/XLSX sample of up to 25 transactions. Failed extraction or extraction with no usable transactions releases the free slot; a retry or later upload can claim it if the slot is still available. Experimental QBO and OFX exports are unavailable to guests and require signed-in processing. For uploads by signed-in users or organizations, one page credit per physical PDF page is reserved at upload. The reserved page credits are deducted after successful extraction produces usable rows and returned to the available balance after failed or empty extraction. Creating an export does not use another page credit.
WayForPay provides hosted card checkout and monthly card subscriptions. Monthly subscriptions renew automatically until canceled; a signed-in user can cancel a personal subscription in the dashboard, and confirmed cancellation stops future renewals. NOWPayments is used only for one-time crypto page-credit packs, not subscriptions. Crypto checkout uses the configured supported asset and network shown by the provider and may be unavailable when the product price does not exceed the provider’s current minimum with the required safety buffer.
Cancellation does not automatically refund a completed subscription period or remove page credits already granted for that period, unless a provider-confirmed reversal or an adjustment required by the provider or applicable law applies.
There is no automatic refund after page credits have been used. Duplicate or incorrect charges, failure to provide the paid service, provider-confirmed reversals, and rights required by applicable law will be reviewed. Before paid launch, the operator must define the request channel, required evidence, request deadline, target response time, refund destination, and payment timing.
Page credits are granted only after verification of a server-to-server provider callback. Browser return pages, pending payments, partial crypto payments, and wrong-network transfers do not grant page credits.
After a verified successful payment, StatementExport emails a service payment confirmation to the checkout email. It is not represented as a fiscal receipt or tax invoice; any legally required fiscal document remains subject to the provider setup and the operator’s RRO or pRRO obligations.
6. Retention and deletion
Guest sessions expire after 24 hours; hourly cleanup then purges their original PDFs, generated exports, extracted statement data, and normalized rows. It retains a minimal deleted-status operational record with the session association, file and page counts, processing metadata, and timestamps, but no statement content, customer filename, or checksum. Signed-in and organization originals and generated exports are scheduled for deletion after 7 days.
Signed-in and organization normalized rows remain until the conversion is deleted. Deleting a conversion purges its normalized rows, extracted statement data, and any files still stored, while retaining the same kind of minimal deleted-status operational record. The current product does not offer configurable or longer organization retention.
Payment accounting entries and monthly payment-register CSV archives are stored separately from customer statements for business and statutory recordkeeping. They do not contain statement files or transaction rows and are not deleted when a conversion is deleted. The final retention period must be approved before paid public launch.
7. Organizations
Organizations currently support batch uploads, client upload links, shared page credits, and owner, admin, member, and viewer roles. Access to these features is not currently restricted by plan, and no team-member limit is enforced.
Creating an invitation generates a link that should be copied and shared securely. Even when invitation creation succeeds, email delivery is not guaranteed.
8. Acceptable use
- Do not upload malware, exploits, unlawful data, or documents you are not authorized to process.
- Do not bypass limits, overload the service, interfere with other users, or attempt unauthorized access.
- Do not use unreviewed output as the sole basis for regulated, accounting, tax, audit, lending, or compliance decisions.
9. Documents and processing permission
You retain your rights in uploaded documents and resulting data. You permit the service to store, extract, display, correct, export, and delete that data only as needed to provide the requested conversion and organization features.
10. No accuracy guarantee
The service does not guarantee uninterrupted availability, perfect extraction, accounting correctness, or fitness for a particular professional purpose. Any final warranty, liability, refund, and dispute terms require counsel review after the governing law has been selected.
11. Details required before launch
The final operator, registered address, support contact, privacy contact, governing law, venue, refund request procedure, and named production processors have not been inserted. Do not treat this draft as final public legal notice.