Privacy Policy
Last updated: 30 August 2026
Who we are
Statement Compass (“we”, “us”, the “Service”) is a personal finance application operated by an independent developer. It turns bank and card statements you already have into categorized transactions, budgets, and forecasts. For anything in this policy, you can reach us through the contact page.
The short version
- Your original PDF statements are never uploaded. They are read entirely inside your browser.
- Only the text and page images you approve — after you draw redaction boxes — are sent to our servers and to our AI provider for categorization.
- Anything you do not redact is stored and processed as-is. Redaction is in your hands, and we tell you this in the app before every upload.
- We do not sell your data, show ads, or use tracking cookies. We use a privacy-conscious analytics tool (PostHog, hosted in the EU) that we configure to never see your statement content — details below.
- You can erase your imported data yourself at any time from Settings.
What stays on your device
When you upload a statement, the PDF file is opened and parsed by code running in your browser. The raw document — including any pages you deselect and any regions you redact — never leaves your device and is never transmitted to us or to anyone else. There is no copy of your original statement anywhere on our systems, which also means we cannot recover it for you.
What we collect and store
When you use the Service, we store:
- Account data — your email address and a hashed password, used to sign you in.
- Statement content you approve — the extracted text and rendered images of the statement pages you selected, with your redaction boxes burned in as permanently black regions. Redacted content is removed before anything is sent and cannot be recovered from what we store.
- Financial records you create — transactions, accounts, categories, budgets, recurring rules, goals, and settings such as currency and locale.
- Usage records — a count of your uploads each month (used to enforce plan limits and control our costs) and in-app notifications about your statements.
- Product analytics events — which pages and features you use (for example, that you completed an upload or hit a plan limit), collected through PostHog as described under “Analytics” below. These events never include statement content, transaction details, or amounts.
We do not collect device fingerprints, advertising identifiers, precise location, or browsing history.
Redaction is under your control — and your responsibility
Before a statement is processed, the app asks you to draw boxes over anything you want removed: account numbers, names, addresses, or anything else. Redacted regions are excluded from the extracted text and blacked out in the page images at the pixel level.
There is no automatic redaction. Anything you leave unredacted — including personal information — will reach our servers and our AI provider exactly as it appears on the page. If you proceed without drawing any redaction boxes, the app asks you to confirm that choice first.
How we use your data
- To provide the Service: storing your transactions, computing budgets, forecasts, and dashboards.
- To categorize your statements: the approved text and page images are sent to Anthropic’s Claude API, which reads them and proposes transactions and categories for your review. Nothing is committed to your records until you approve it.
- To notify you: transactional emails (such as “your statement is ready to review” and email confirmation at signup) and in-app notifications. We send no marketing email.
- To enforce plan limits and prevent abuse of the Service.
We never sell your data or share it with anyone for advertising.
Analytics
We use PostHog, hosted in the European Union, to understand how the Service is used — for example, how many people finish the upload flow, or where they abandon it. We have deliberately configured it to collect as little as possible:
- No statement content, ever. Automatic capture of page text and form input is disabled. We send only named events we chose by hand (such as “upload completed”), and they never carry transaction descriptions, amounts, or anything extracted from a statement.
- No session recording. We do not record or replay your screen.
- No analytics cookies. Analytics runs without storing identifiers in your browser, which means we cannot follow you across visits with an analytics cookie.
- Events from signed-in use are associated with your internal account ID, never your email address.
Service providers
Four providers process data on our behalf, each only to provide the Service:
- Supabase — hosts our database, authentication, and file storage. Your data is protected by per-user access rules; page images live in a private bucket accessible only to your account.
- Anthropic — provides the AI model that reads your approved statement content. Under Anthropic’s API terms, data sent to the API is not used to train their models.
- Resend — delivers transactional email and contact-form messages.
- PostHog — provides product analytics, hosted in the EU and limited as described under “Analytics” above.
These providers may process data in countries other than yours. Wherever it is processed, it remains covered by this policy and by our agreements with them.
Cookies
We use only the cookies required to keep you signed in (authentication session cookies). Our analytics runs without cookies or stored identifiers (see “Analytics” above), so there are no advertising, analytics, or third-party tracking cookies — which is why the Service shows no cookie banner.
Retention and deletion
- Your data is kept for as long as your account exists, so the Service can show your history.
- You can erase your imported data yourself: Settings → Danger zone → Clear my data removes your transactions, statements, stored page images, custom categories, and notifications, and resets account balances.
- Monthly upload counts are retained even after you clear your data, because they enforce plan limits for the current month.
- To delete your account entirely, contact us and we will remove it along with all associated data.
Security
All traffic is encrypted in transit (HTTPS). Data access is enforced row-by-row at the database level, so one user’s session can never read another’s records. Stored page images sit in a private bucket behind the same per-user rules, and short-lived signed links are used to display them. No system is perfectly secure, but if we learn of a breach affecting your data we will notify you without undue delay.
Your rights
Wherever you live, we honor the core data-protection rights found in laws like the GDPR: you may ask us for a copy of your data, ask us to correct it, or ask us to delete it. Much of this you can do directly in the app; for the rest, contact us and we will respond within 30 days. If your local law grants you additional rights, we will honor those too.
Children
The Service is not directed at children and requires you to be old enough to hold a bank account and enter into these terms — at least 18, or the age of majority where you live. We do not knowingly collect data from children.
Changes to this policy
If we change this policy, we will update this page and the date at the top. For material changes — anything that expands what we collect or how we use it — we will notify you in the app before the change takes effect.