Privacy

What happens to your client's statements

  1. A person reads them. Right now that person is the founder, and nobody else. Decide whether that fits your own client-confidentiality obligations before you send anything.
  2. Where they sit. In private, access-controlled object storage with server-side encryption in the EU region, reachable only by the founder's account. Text-layer pages are parsed by software on our own infrastructure; scanned or photographed pages are sent to a vision model for a first read.
  3. Where the reading happens. The vision model that reads a scanned page is Anthropic's Claude API. That inference is global by default. We do not pin it to a country, and the storage region above does not bind it.
  4. Retention. Your statement PDFs are deleted 7 days after we deliver your export 7 and not 1, because that is the window in which a correction or a re-delivery is actually asked for, and we would rather keep the file than ask you to send it again. Your export files are deleted after 30 days, when the download link expires.
  5. Deletion on request. Email us and we delete everything the same day, including the export, and confirm in writing. This overrides every timescale above.
  6. What we never do. We never sell, share or publish your data; we never use it to train any model; we never contact your client; and we never keep bank credentials, because we never ask for any. The per-client memory table holds only merchant descriptions and account codes — no balances, no account numbers, no statement images — and you can ask for it as a CSV, or ask us to delete it, at any time.
  7. Who else touches it. Stripe takes the payment and never sees your files. The storage provider holds the files and reads nothing.

Ask anything about this by email: hello@halebook.com