Privacy Policy

Last updated: May 2026

1. About This Policy

StatementFlow ("we", "us", "our") is committed to protecting the privacy of individuals who use our service. This Privacy Policy explains how we collect, use, disclose and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using StatementFlow you agree to the collection and use of information in accordance with this policy.

2. What Information We Collect

Account information: When you create an account we collect your name and email address.

Uploaded documents: When you upload a PDF bank statement for conversion, the file is processed entirely in memory. It is never written to a permanent database and is permanently deleted within 60 seconds of conversion completing.

Usage data: We collect anonymised usage data such as the number of conversions performed and general feature usage. This data cannot be used to identify you.

Payment information: Payments are processed by Stripe. We do not store your card details. Stripe's privacy policy applies to payment data.

3. How We Use Your Information

We use your information solely to:

  • Provide and improve the StatementFlow service
  • Process your bank statement conversions
  • Send transactional emails (conversion confirmations, account notices)
  • Respond to support requests
  • Comply with legal obligations

We do not sell, rent or share your personal information with third parties for marketing purposes.

4. Data Retention

Uploaded PDF files are permanently deleted within 60 seconds of conversion. Converted output files (Excel, CSV) are stored temporarily and are accessible only via a unique download link. They are deleted after 24 hours.

Account information is retained for as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us at [email protected].

5. Security

All data transfers are protected by TLS 1.3 encryption. Bank statement processing occurs entirely in memory and is never written to disk. We implement industry-standard security measures to protect your personal information from unauthorised access, disclosure, alteration or destruction.

6. Third-Party Services

StatementFlow uses the following third-party services:

  • Anthropic Claude API — AI processing of bank statement text. No personally identifiable information is sent to Anthropic. Only extracted transaction text is processed.
  • Stripe — Payment processing. Stripe's privacy policy applies.

7. Your Rights

Under the Australian Privacy Act you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Complain about a breach of the Australian Privacy Principles

To exercise any of these rights, contact us at [email protected].

8. Contact Us

For privacy-related enquiries contact us at [email protected]. We will respond within 5 business days.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. Continued use of StatementFlow after changes constitutes acceptance of the updated policy.