1. Scope and operator information
Bank File Flow is the site and product name used throughout this website. A registered business name, postal address and jurisdiction-specific privacy contact have not yet been published. Until those details are available, this policy should be read as a technical description of current data handling rather than a final jurisdiction-specific legal document.
2. Statement-file processing
The public conversion and editing tools use browser file APIs to read and process a selected statement on your device. In the supported workflows, statement contents and the transactions derived from them are not intentionally uploaded to the Bank File Flow application server. Downloads are assembled locally and triggered by the browser.
3. Password-protected PDFs
When a public tool accepts a password-protected PDF, the password is used in the browser to unlock that file. It is not intentionally transmitted or logged and is cleared from the page's working state after a successful unlock, cancellation, reset or error.
Browser and operating-system memory management remain outside the site's direct control. Use a trusted device and close the tab when you finish working with a sensitive document.
4. Conversion issue reports
Each bank and accounting converter offers an optional Report a problem form. The description and optional contact, bank, country and count fields that you choose to enter are transmitted to Bank File Flow and stored with limited structured diagnostics such as an allowlisted parser version and error code, browser and operating-system family, viewport category, detected structure, transaction count, reconciliation status and confidence category.
Reports are used to investigate converter compatibility and reliability. An optional email is used only to follow up about that report. Abuse prevention stores a secret-keyed one-way fingerprint of the Cloudflare-provided request address, not the raw address in the report record. Reports are restricted to authorized administrators and scheduled for permanent deletion once they are older than 180 days; rate-limit fingerprints are scheduled for deletion once older than two days. A daily retention job performs that cleanup, so deletion follows its next successful run. An administrator can delete a report sooner.
5. Accounts, mappings and billing
If you create an account, Supabase processes your email, password and authentication session. The browser stores the Supabase access and refresh session plus a cached profile so sign-in can persist. A signed-in user may also synchronize saved column-mapping preferences; those preferences describe column roles and do not contain statement rows.
If paid plans are enabled and you start checkout, Bank File Flow and Lemon Squeezy process the account, plan and billing identifiers needed for checkout, subscription status and customer-portal access. Payment-card handling is performed by the payment provider, not by the statement converters. Account and billing retention, deletion rights and operator-specific legal details must be finalized for the operator's jurisdiction before commercial launch.
6. Ordinary website hosting
The website is served through Cloudflare Pages. Like other hosting providers, it may process standard request information needed to deliver and protect the site, such as IP address, request time and browser user-agent data. This infrastructure activity is separate from statement conversion.
Bank File Flow does not make a specific claim about provider-controlled log retention beyond the provider's own current documentation.
7. Browser storage
The site stores non-financial preferences such as privacy choices and tool display settings. When you sign in, it also stores the authentication session and a cached account profile; saved mapping preferences may also be cached. This browser storage is not intended to contain statement rows, transaction descriptions or PDF passwords. Signing out clears the application session/profile, and browser settings can clear remaining site storage.
8. Analytics and advertising status
Analytics and advertising are not currently active because no identifiers are configured. If an optional service is enabled later, the public policy and consent behaviour will be updated before that service is used.
9. External destinations
Links can take you to other websites with their own privacy practices. Review the destination and its policy before submitting information. Bank File Flow does not control data handling on third-party sites.
10. Security and your choices
No website or device can be guaranteed completely secure. Keep the original statement, review every export, avoid shared or public computers for sensitive files, and close the working tab when finished.
- You can use the public conversion and editing tools without creating an account.
- You can clear local browser storage using your browser settings.
- You can decline optional services if a privacy-choice control is shown.
- You can leave optional issue-report fields blank and should describe problems without financial data.
- You should never send a real statement or financial identifier in a support enquiry.
11. Children and international visitors
The site is not directed at children and is not knowingly used to collect personal information from children. Ordinary hosting data may be processed in a country other than your own, depending on the hosting provider's infrastructure. A governing jurisdiction has not yet been published.
12. Changes and contact status
Material policy changes will be reflected in the “Last updated” date. A dedicated privacy contact address has not yet been published. When one becomes available, it will be added to the public contact information. Do not include real statement data in any privacy enquiry.