Home / Security
Security
Bank statements are sensitive. Here's plainly how we handle yours.
We don't keep your statements
Your uploaded PDF is encrypted, used only to extract your transactions, and deleted as soon as processing finishes. The extracted results are removed on the same 24-hour clock — nothing about the substance of your statement (descriptions, amounts, balances) is retained on our systems beyond 24 hours of your conversion. We hold only your account record, a monthly page-usage count, and statistics about statement layouts (per-bank conversion counts and the column layout of the statement formats uploaded — never transactions, amounts, transaction dates, names or account details). If a statement needs AI-assisted extraction (see below), Anthropic deletes its copy within 30 days (up to 2 years only if flagged by its automated safety systems) — see our Privacy Policy.
Never used to train AI
The contents of your statements are never used to train AI models — ours or anyone else's. Extraction runs on deterministic parsing built for each bank's statement layout. If that can't produce a result that reconciles to the cent (for example, a scanned statement or a layout we don't recognise yet), the statement may be processed by Anthropic's Claude API to extract the transactions. Under Anthropic's commercial terms it does not train its models on this data, and we only use the result if it reconciles to the cent. Either way, we use your data for one thing only: producing your export.
Every conversion is verified
Bank statements are self-checking: the opening balance plus credits minus debits must equal the closing balance (for credit cards, the opening balance plus purchases minus payments). We run that reconciliation on every conversion, to the cent. If the numbers don't add up — a page failed to read, a row went missing — we flag the discrepancy instead of handing you a file that silently looks complete.
Where processing happens
Statement extraction runs on our service hosted in Sydney, Australia. If a statement needs AI-assisted extraction, it is processed by Anthropic outside Australia (primarily in the United States). Like most modern web applications, we also use trusted global providers for hosting, storage, authentication and payments (Vercel, Cloudflare, Supabase, Stripe) — with all data encrypted in transit and at rest.
Encryption
All data is transmitted over TLS 1.2+ (HTTPS). Data held by our infrastructure providers is encrypted at rest using their platform defaults.
Payments
Payments are processed by Stripe, a PCI-DSS Level 1 provider. Your card details go directly to Stripe — Ledger Pilot never sees or stores your full card number.
Authentication & access control
Accounts are secured by Supabase Auth. Database access is protected by row-level security so that each account can only read its own data. The extraction service only accepts requests from our own backend.
Data minimisation
We collect the minimum needed to run the service: your email, your subscription status, and how many pages you've converted this month — plus the layout statistics described above, which carry no statement contents. Nothing about the substance of your statements is retained on our systems beyond 24 hours of your conversion.
Responsible disclosure
Found a vulnerability? Please email support@ledgerpilot.com.au and give us a reasonable chance to fix it before public disclosure. We appreciate your help.