Your statements.
Your business.
Financial documents are personal. Here’s exactly what happens to yours when you use BankPDFExport, who is responsible for it, and the rights you have. Last updated 3 October 2026.
We do not sell your data. We do not retain your transaction contents in a database, send them to external AI services, or use them to train models.
Who is responsible for your data
The data controller is Abdellatif Iflillis, Latvia. For any privacy question or request, email support@bankpdfexport.com. Under the EU General Data Protection Regulation (GDPR), we are responsible for how your personal data is processed on this service.
Uploaded PDFs are temporary
Your PDF is uploaded to a private temporary directory on our server. It is deleted immediately after a successful conversion, when you clear it, or after an unsuccessful conversion attempt. Files left waiting for conversion expire automatically in 45 minutes, with cleanup running every 30 seconds while the service is running. The configured expiry is always below 60 minutes.
Previews are temporary, too
Extracted transactions live only in temporary server memory and your open browser tab. They are never written to our database or application logs. Downloads are generated in memory. Use “Clear & start again” to remove a preview immediately. Otherwise, it expires with the upload session. Close your tab when you are done on a shared computer. Any file you choose to download is yours to manage.
The account information we keep
We store your email address, sign-in sessions, subscription identifiers and status, monthly page usage, and conversion metadata: user ID, date, page count, parser identifier, and success or failure. We do not keep original filenames or transaction contents. To diagnose billing issues we also keep limited payment-event records: event type, resource ID, delivery digest, receipt time and processing status. Full billing payloads are not logged.
Why we process it (legal basis)
- To provide the service you asked for (performance of a contract, GDPR Art. 6(1)(b)): signing you in, converting your statements, enforcing your page allowance and managing your subscription.
- To keep the service secure and working (legitimate interests, Art. 6(1)(f)): rate limiting, preventing abuse, and short-lived payment-event records used to diagnose billing problems.
- To meet legal obligations (Art. 6(1)(c)): invoices and the records that tax law requires are kept by our payment provider, Lemon Squeezy.
How long we keep it
- Uploaded PDFs: deleted after conversion, and after at most 45 minutes if never converted.
- Transaction previews: memory only, until you clear them or the upload session expires.
- Sign-in links: 15 minutes, single use. Sessions: 7 days.
- Payment-event records: up to 90 days.
- Account, subscription, usage and conversion metadata: while your account exists. When you delete your account from your account page, these records are removed immediately.
Service providers we use
These companies process data on our behalf, only as needed to run the service. Your bank statements and extracted transactions are never sent to any of them.
- VibedHost: hosts the application and its database. Servers in Germany and the Netherlands (EU).
- Cloudflare: secure network and DNS in front of the website. Traffic passes through its global network, including the United States.
- Resend: delivers sign-in emails. Receives your email address and the sign-in link. Processed in the United States.
- Lemon Squeezy: checkout, payments, invoices and subscription management as merchant of record. Receives your email address and an account identifier when you open a checkout, and handles your payment details under its own privacy policy. Processed in the United States.
Transfers outside the EU
Where a provider processes data outside the European Economic Area, the transfer relies on the safeguards the GDPR allows, such as the EU–US Data Privacy Framework for certified companies or the European Commission’s Standard Contractual Clauses.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate.
- Delete your data. Delete your account yourself from your account page, or ask us by email.
- Data portability: receive your account data in a structured, machine-readable format.
- Restrict or object to processing based on legitimate interests.
- Complain to a data protection authority. In Latvia this is the Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv); you can also contact the authority in your own EU country.
To use any of these rights, email support@bankpdfexport.com from the address on your account. We reply within one month.
Cookies and security
We use one essential, HTTP-only session cookie for sign-in and request protection. No advertising or analytics cookies are added by this app. All traffic uses HTTPS. Uploads are limited to PDF files up to 20 MB, and sign-in and conversion requests are rate limited.
Review before relying on an export
Bank statement layouts vary. Automatic extraction can miss or misread rows, especially in scanned or unusually formatted documents. Compare the preview with the original statement before using the export in your bookkeeping.
Changes to this policy
If we change how we handle personal data, we will update this page and its date. Significant changes affecting account holders will be announced by email.