How your data is protected
You are trusting us with your bank statements. Here is what we do with them, and how we tested it, in plain words. Where we have not tested something yet, we say so.
What we keep, and what we never keep
We don't save the file you upload, unless you ask us to keep one so we can fix how we read it. We read the rows out of it and throw the file away. We only offer to keep a file if we could not read it, or most of it, or you tell us something looks wrong.
We never pull out your name, your address or your full account number. We keep the last four digits of an account, so we can tell your accounts apart.
What we do keep is locked twice. Every description, amount, balance, account digit and file name is encrypted by us, on top of the encryption our database provider already applies.
How long we keep it is on our privacy page, and you can delete everything at any time.
What our AI sees
Our AI provider sorts your transactions into categories. Before a line is sent, we hide what could identify someone: a person's name after a transfer, an email address, a long number (like an account or a phone number) and a street address.
Some PDFs are built in a way our software cannot read. For those, we send the statement itself to our provider, as your bank wrote it, to turn the page into a list of transactions. That is the one case where the details printed on the page travel with it, and it is used for that one step only.
Our provider does not train on your data, under the agreement we have with them. Details are on our privacy page.
How we tested it
We planted fake personal details and went looking for them. We made statements carrying a made up name, street, email, phone number and account number, uploaded them like a real person would, then searched every place data can end up: our database, our analytics, our server logs. They were nowhere.
We scanned every version of our code, since the first one, for passwords and keys. None were found, and the scan now runs every time we change anything.
We attacked our own site from the outside. An automated scan, with no account, tried every part of the app that accepts a request. Nothing answered with anyone's data, the connection is encrypted with current standards only, and the files that must never be public are not. A separate review then read the code that decides whose report a request may open, on every route that opens one.
We tried to trick the AI. We hid instructions inside statement lines, the way a stranger could in a transfer message, telling it to count a purchase as income or hide spending. Seven of eight were ignored outright. The eighth, a deposit whose own text claimed to be regular pay, was filed as regular income, the way a real pay stub line would be. A stranger can only put a deposit on your statement by sending you money, so we accept that one.
We tried to hijack a sign in. A sign in link cannot be redirected to an outside website, and signing out ends your session on our side straight away.
What we have not done yet
An outside security firm has not tested us yet. That happens before we open to everyone. Until then, this page is our own testing, checked by a separate review that did not do the work.
Two protections are still on our list: a stricter rule for which scripts a page may run, and a public page for reporting a security problem to us. Neither changes what we keep.
Questions: privacy@myfinally.com.