Your uploaded files are never stored

Zero-retention processing, encrypted transit, SOC 2 compliant infrastructure. We built this for people who care about where their bank data goes.

  • No bank login
  • Files never stored
  • EU-based operator

How we protect your data

Six security practices built into every request.

Zero-retention processing

Your uploaded file is processed entirely in memory. It is never written to disk, never saved to a database, and never stored in any form. The moment your results are generated, the original file is gone.

Encrypted in transit

All data is transmitted over TLS 1.3 (HTTPS). Your file travels encrypted from your browser to our servers. No unencrypted connections are accepted.

SOC 2 compliant infrastructure

We run on Vercel (SOC 2 Type II), use Google Cloud services (SOC 2, ISO 27001), and process payments via Polar. Our infrastructure providers undergo independent security audits annually.

No third-party data sharing

Your financial data is never sold, shared, or provided to advertisers, data brokers, or any third party. AI processing uses Google Gemini with data processing agreements in place.

Minimal data collection

We only store the extracted transaction data (dates, descriptions, amounts) needed to display your results. No raw files, no images, no full-text PDF content is retained.

Authentication & access control

Passwords are hashed with bcrypt. Sessions use secure HTTP-only cookies with 30-day expiry. IP-based rate limiting prevents brute force. OAuth via Google is available.

What happens to your file

The complete lifecycle of your uploaded bank statement.

  1. Step 1

    Upload (encrypted)

    Your file is sent over TLS 1.3. It arrives in server memory — never touches disk.

  2. Step 2

    Process (in memory)

    OCR reads the text (if scanned), AI extracts transactions and assigns categories. All in RAM.

  3. Step 3

    Extract results

    Only structured data is kept: dates, descriptions, amounts, categories. The original file is discarded.

  4. Step 4

    Deliver & delete

    Results are shown in your browser or downloaded as a file. The uploaded document no longer exists anywhere.

GDPR aligned

We follow GDPR principles by design — not as an afterthought.

  • Right to access

    View all data we hold about you from your dashboard settings.

  • Right to erasure

    Delete your account and all associated data at any time.

  • Right to portability

    Export your analysis history and transaction data.

  • Right to rectification

    Edit or correct your account information.

  • Data minimization

    We only process and store what is necessary to deliver the service.

  • Purpose limitation

    Your data is used solely for statement analysis — nothing else.

Infrastructure security

Every provider in our stack is independently audited.

  • Vercel
    SOC 2 Type II
    Application hosting & edge network
  • Google Cloud
    SOC 2, ISO 27001, SOC 3
    AI processing (Gemini) & OCR (Cloud Vision)
  • Turso (libSQL)
    Encrypted at rest
    Database storage
  • Polar
    PCI-compliant checkout
    Payment processing
  • Better Auth
    bcrypt + secure cookies
    Authentication

Third-party data processing

What data leaves our servers, where it goes, and how it's protected.

Google Gemini API

What is sent: Transaction descriptions and amounts are sent for AI categorization.

Protection: Google API Terms prohibit using API data to train models. Data is processed and discarded — not stored by Google. All requests over TLS.

Google Cloud Vision (OCR)

What is sent: Scanned/image PDFs are sent for text extraction.

Protection: Processed in memory by Google, not stored. Covered by Google Cloud data processing agreement.

Polar

What is sent: Payment card details (we never see or store these).

Protection: PCI-compliant checkout. Card data goes directly from your browser to Polar.

Public-site scripts

PostHog measures product usage with privacy controls.

The site uses PostHog for product analytics, attribution, conversion funnels, and privacy-protected session replay. Input values are masked, and replay is disabled on results, dashboard, settings, and claim pages. For the current provider list, see Subprocessors and Trust Center.

Who operates this service

Transparency about who handles your data.

Operator
DPmedia
Founded by
Dawid P.
Jurisdiction
Poland, European Union
GDPR status
EU-based operator — fully subject to GDPR
Contact
contact@mybankstatementanalysis.com
Operational docs
Trust Center, Subprocessors, Data Retention, Responsible AI

Try it on your own statement

Your first upload is free, with no account or card. If a paid report doesn't match your statement, you get your money back within 14 days.