Privacy policy.
Effective August 14, 2026. This policy explains what StatementMint collects, why we use it, when we share it, and the choices available to you.
Information we collect
We collect information you provide, including your email address and account profile, uploaded PDF statements and filenames, extracted transaction data, plan selections, conversion ratings, issue reports, and support messages. If you choose to include a statement with a negative feedback report, we also retain that review copy temporarily.
We create records needed to run the service, such as conversion status, processed page numbers, usage, subscription status, timestamps, and error categories. Our hosting, security, analytics, and abuse-prevention systems also receive limited technical information such as IP address, browser or device details, cookie or session identifiers, and request timestamps. Payment providers collect payment and billing details; StatementMint stores subscription and transaction identifiers but not complete payment-card numbers.
How we use information
We use information to provide accounts and previews, process entitled statement pages, create CSV and Excel files, maintain conversion history, manage plans and billing, enforce limits, prevent abuse, provide support, investigate reported problems, understand product usage, measure advertising performance, diagnose errors, comply with law, and protect StatementMint and its users.
Document processing
Source PDFs are stored in private cloud storage. StatementMint submits only the pages covered by the applicable preview or plan allowance to a contracted document-processing service; locked pages are not submitted. Larger inputs may use a temporary provider file, which StatementMint requests to delete after processing. The provider may retain limited operational or legal records under its own terms. CSV and Excel files are generated on demand after an ownership check and returned with no-store response controls.
StatementMint does not use statement contents for advertising or generative-model training. Optional parser improvement is off by default and can be enabled under Plan & usage. When enabled, an eligible conversion may create a data-minimized structural layout record that excludes the PDF, filename, transaction text, dates, amounts, balances, account number, and user identity. Turning participation off deletes linked layout records.
Conversion feedback
You can rate a conversion and describe a problem. Including the source statement is a separate checkbox that is off by default. If selected, the statement is copied to a private review area available only to authorized StatementMint personnel for investigating the report. It is not used for advertising or model training and is deleted within 30 days, or sooner if you delete the conversion or account.
Service providers and disclosures
We share information only as needed with providers that support cloud hosting, authentication, private file storage, document processing, scheduled cleanup, payments and tax handling, transactional email, product analytics, advertising measurement, customer support, and error monitoring. Google supports optional account sign-in and advertising measurement; Stripe and Link support checkout and billing; PostHog supports limited product analytics; and Sentry supports minimized error and performance monitoring. Providers may process data in other countries under their contractual and legal transfer mechanisms.
We may also disclose information when required by law, to protect rights or safety, investigate abuse, complete a business transaction, or act on your direction. We do not sell or rent personal information and do not use uploaded financial information for advertising audiences, remarketing, Customer Match, or personalized advertising.
Product analytics and advertising measurement
StatementMint sends a limited set of product events, such as page category, sign-in method, upload completion, checkout start, conversion feedback, and export format. We do not send analytics providers statement contents, extracted transactions, filenames, email addresses, typed form contents, conversion identifiers, or full conversion URLs. Session replay, click and form autocapture, heatmaps, and browser exception capture are disabled.
For visitors arriving through a validated United States Google Ads click, StatementMint may use an advertising cookie and send one paid-subscription conversion containing a random receipt identifier, the amount paid, and currency. We do not send Google the statement, extracted data, email address, internal user ID, filename, or plan name. Advertising personalization and remarketing are disabled.
You can disable advertising measurement through “Advertising privacy choices” in the footer. StatementMint also honors Global Privacy Control. Disabling measurement prevents future StatementMint purchase events and future advertising-cookie storage, but cannot recall a conversion already sent. Depending on applicable law, this limited ad attribution may be considered “sharing” for cross-context behavioral advertising.
Retention and deletion
Conversions, source PDFs, extracted data, review history, optional feedback attachments, and opted-in parser-improvement records expire within 30 days. Cleanup runs on a schedule, so removal may occur after the expiration time rather than at the exact second. Unclaimed direct uploads expire after 15 minutes. You can delete an individual conversion sooner.
Account, authentication, billing, support, security, fraud-prevention, and legal records may be kept longer when reasonably necessary for those purposes. Limited copies may remain temporarily in provider backups, caches, or legally required records. Self-service account deletion removes active account files and linked product data after open billing and processing obligations are resolved.
Cookies and browser storage
StatementMint uses essential cookies for authentication and anonymous previews. Browser storage may remember interface state, a privacy-safe analytics session identifier, and your advertising-measurement choice. After a validated ad click, Google may use first-party advertising cookies unless you disable measurement or send Global Privacy Control. Stripe or Link may use their own storage on hosted checkout pages.
Security
We use HTTPS, encryption at rest from our infrastructure providers, private storage, row-level access controls, ownership checks, short-lived signed links, server-only credentials, schema validation, rate limiting, and privacy-limited logging. No internet service can guarantee absolute security. If you suspect unauthorized access, contact us and provide a conversion ID rather than attaching the statement.
Your choices and rights
You can delete conversions, manage parser-improvement participation, disable advertising measurement, manage or cancel a subscription, and request account deletion from Plan & usage. Depending on where you live, you may also request access, correction, deletion, restriction, portability, or objection; withdraw consent where it applies; or appeal a denied request. We may verify your identity and retain information when an exception is permitted or required by law.
Children
StatementMint is intended for adults and is not directed to children under 18.
Changes and contact
We may update this policy as the service or law changes. We will post a revised effective date and provide additional notice when required. To exercise a privacy right or ask a question, use the contact form.