Privacy

Privacy Policy.

Revised [last updated: DRAFT]

StatementKeep signs in to your financial accounts for you, downloads your monthly statements, and turns them into spreadsheets you can hand to your accountant. That means we hold some genuinely sensitive things — your logins and your statements. This page explains, in plain language, exactly what we keep, why we keep it, how it is protected, and the choices you have.

Draft

This policy is a working draft, pending final review. The wording may change before it becomes final.

01What we collect, and why

We try to collect only what the service actually needs. In practice that is four things:

  • Account and contact info — your name and email, and your password (stored only as a secure hash). We use this to run your account, sign you in, and email you about your statements and your account.
  • The logins you choose to connect — the username and password (and any similar credentials) for each bank, credit card, e-commerce, or buy-now-pay-later account you ask us to fetch from. More on how these are handled below.
  • The statements we fetch — the PDF statements we download for you, and the CSV files we create from them for QuickBooks. This is the whole point of the product.
  • Basic app and usage data — things like which pages you visit, your browser and device type, and error logs, so we can keep the service working and secure. We do not use this to build advertising profiles.

StatementKeep is not for anyone under 18, and we do not knowingly collect information from children.

02Your account credentials

To download your statements, we have to log in to your accounts the same way you would. That means we store the credentials you give us — but carefully:

  • They are encrypted the moment you enter them and kept in a dedicated secrets vault, never in plain text.
  • They are reversible by design — we have to be able to decrypt them at fetch time to type them into your bank's login page. There is no way around that; a login has to be usable.
  • They are used only to fetch your statements, and for nothing else.
  • We never sell them, share them, or hand them to anyone outside the service.

You can remove a connected login at any time, which deletes its stored credentials.

03Your statements and the CSVs we make

The statements we download and the CSVs we generate from them are yours. We store them so you can come back and get them, and we process them only to do the job you asked for — downloading, converting to CSV, and filing them in your account. We do not sell them, share them, or mine them for anything else.

04Phone helper (optional)

Some financial institutions will only let you in from an ordinary home internet connection, not from a data center. Phone helper is an optional feature that lets your own phone route your own statement-fetch traffic through your home internet so those institutions work. Here is exactly how it behaves:

  • Only your own traffic. Your phone only ever carries the traffic for your own connected accounts — never anyone else's, ever.
  • Your phone cannot read it. The connection to your bank is encrypted end to end. Your phone simply forwards that encrypted traffic along; it never unlocks it, never sees your login or statements, and cannot act as a middleman. It is a relay, not a reader. The data stays encrypted in transit and at rest.
  • Used only for your statements. We never use the phone connection for anything other than fetching your own statements, and never on behalf of anyone else.
  • Off unless you turn it on. It is opt-in and off by default. The app shows you a specific agreement the first time you enable it, and you can turn it off again whenever you like.
  • Minimal operational data. To run this feature we keep a little bookkeeping: whether your phone is currently online and when it was last seen (so we know where to route), and a rough count of how much data has passed through (so we can show it to you). We keep this to the minimum needed to make the feature work.

05How we keep it safe

Security is the core of this product, so this is not boilerplate:

  • Encrypted in transit. Everything travels over TLS — your browser to us, and us to your bank.
  • Encrypted at rest. Your statements and CSVs are encrypted where they are stored, with keys scoped to your account, so one customer's files are cryptographically separate from another's.
  • Credentials in a vault. Your logins live in a dedicated encrypted secrets vault, separate from the rest of your data.

No system is perfectly unbreakable, but this is real, specific protection rather than a padlock icon. You can read more on our Security page.

06Who we share it with

We do not sell your information — any of it, ever. We do not trade or rent it for marketing, and we do not share your credentials or statements with outside parties for their own use.

The only companies that touch your data are the service providers we use to run StatementKeep — for example, cloud hosting, storage, and email delivery. They act on our instructions, only to help operate the service, and nothing more. We may also disclose information if the law genuinely requires it, or to protect against fraud or a threat to someone's safety.

07Text messages (SMS)

If you give us your mobile number and tick the SMS-consent box in your account settings, we send you transactional text messages only: sign-in codes, statement-retrieval status, and action-needed alerts. Consent is optional and never a condition of service; message frequency varies, and message and data rates may apply. Reply STOP to any message to unsubscribe, or HELP for help.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Your phone number and SMS consent are used solely to deliver the messages described above, via our SMS delivery provider acting on our instructions.

08How long we keep it

We keep your account, your connected logins, and your statements for as long as you keep your account, so they are there when you need them. If you close your account, we delete your stored credentials right away and your statements and CSVs shortly after, except for the few records the law may require us to keep for a while.

09Your choices

It's your data, and you're in control:

  • See it. You can access your statements and account information from within the app.
  • Remove a login. Disconnect any account at any time to delete its stored credentials.
  • Delete it all. Close your account and we delete your data as described above.
  • Turn off Phone helper. Enable or disable it whenever you want.
  • Stop the texts. Untick the SMS box in your account settings, or reply STOP to any message.

Depending on where you live, you may have additional rights — such as requesting a copy of what we hold or asking us to delete it. Just reach out and we'll help, wherever you are.

10Contact us

StatementKeep is operated by [StatementKeep legal entity]. If you have any questions about this policy or your data, or you want to exercise any of the choices above, email us at support@statementkeep.com or call 1-628-888-6331. We'll be glad to help.

If we make a meaningful change to this policy, we'll let you know and update the date at the top of this page.