How statements are handled

Security and privacy

Bank statements are among the most sensitive documents a bookkeeper handles. Parseledger is built on a simple position: your statements are yours. We process them, prove the figures reconcile, hand you the export, and get out of the way.

01Residency

Processed in the EU, and only the EU

All application data is stored and processed in the European Union, on Supabase infrastructure hosted in EU regions. Nothing is replicated outside the EU.

That is a deliberate constraint, not a hosting accident. Statements belonging to UK and Irish clients are not routed wherever compute happens to be cheapest — uploads, extracted data, exports and audit trails all live in the same region, under the same rules.

02The data path

Where a statement goes, start to finish

A statement's life inside Parseledger is short and traceable. This is the whole of it:

  1. 01 · Upload

    The statement leaves your browser over TLS and lands on encrypted EU storage. It is readable to the job that processes it, and to nothing else.

  2. 02 · EU processing

    Extraction and both verification checks run on infrastructure in EU regions. The file is read, the figures are computed in integer minor units, and the results are written back — the source never leaves the region.

  3. 03 · 24-hour purge

    Once you have your export, the source file has done its work. It is deleted automatically within 24 hours of processing — and you can delete the whole job, file, data and audit trail, yourself at any time.

03Retention

Transient files, auto-purged

Uploaded PDFs and photos are held only as long as needed to extract and verify them. Uploads exist to be converted, not collected.

Source files are purged automatically after processing; you control how long the extracted data itself is retained, and you can delete a job — file, data and audit trail — at any time.

04Model training

No training on your data

Your statements are never used to train models — ours or anyone else's. Extraction runs under agreements that exclude customer content from model training.

A statement uploaded to be converted is used to convert that statement, and for nothing more. Your clients' transactions stay your clients' transactions.

05Encryption

Encrypted in transit and at rest

All traffic is encrypted in transit with TLS, and all stored data is encrypted at rest. The database sits behind the application — no public key can reach it directly.

Access to production systems is restricted to the people who operate them, and every access is logged.

06Correctness

Verification, not trust

Security extends to correctness. Every statement must satisfy opening + credits − debits = closing and pass line-by-line running-balance checks before it is marked Verified — so the file you hand to a client is provably consistent with the statement it came from.

The exports are careful too: transaction descriptions are sanitised against spreadsheet formula injection before they ever reach a cell. A small thing, until the day it isn't.

Parseledger is a data conversion and verification tool. It is not an accountant, does not provide accounting, tax or financial advice, and does not replace professional judgement. Review flagged rows before relying on any export.

Convert a statement

10 free pages a month. No card.