Security & Data Handling
Bank statements are sensitive. This page explains, in plain terms, what happens to a file after you upload it, how long we keep it, and who can access it.
Last updated:
At a glance
| What | How we handle it |
|---|---|
| Uploads in transit | Sent over HTTPS (TLS) between your browser, our servers, and our processing service. |
| Guest uploads | Deleted automatically 24 hours after upload, including extracted transactions. |
| Signed-in documents | Kept in your private vault until you delete them or delete your account. |
| PDF passwords | Used only to open the file for processing. Never saved to our database. |
| Card details | Handled entirely by our payment provider. We never see or store card numbers. |
| Account deletion | One click from your dashboard permanently removes your profile, documents, and order history. |
Data retention
Guests. When you convert without signing in, the extracted data is stored only so you can preview and download it. It carries an expiry time and is removed automatically 24 hours after upload. Download your files before then.
Signed-in users. Converted statements are saved to your vault so you can re-download them in any format. They stay there until you delete a document from the vault or delete your account from the dashboard.
Access control
- Sign-in uses Google OAuth. We never see or store your Google password.
- Sessions use a signed, HTTP-only cookie that page scripts cannot read.
- Every request for a saved document, export, invoice, or order is checked against the signed-in account that owns it.
- Administrative tools are restricted to an explicit allow-list of staff accounts.
- Guest results are reachable only through the private link created for that upload, and only until they expire.
Payments
Purchases are processed by Razorpay. Card and bank details are entered with and stored by Razorpay, not Finlyzers. We keep only the order record (plan, amount, status, and the payment reference) so we can credit your pages and issue invoices. Payment confirmations are verified with a cryptographic signature before credits are added.
How documents are processed
Uploaded files are sent to our document processing service, which reads text with OCR and an AI vision model to identify dates, descriptions, amounts, and balances. The result is returned to Finlyzers and stored as described above.
We do not sell your documents or use them for advertising. See the Privacy Policy for the full list of service providers, and the Methodology page for how extraction and verification work.
Your controls
- Delete any single document from the Document Vault.
- Delete your whole account and all associated data from the dashboard.
- Use Finlyzers without an account for statements up to 30 pages, so nothing is kept beyond the guest window.
Reporting a security issue
If you believe you have found a vulnerability, please report it to us privately before disclosing it publicly. Do not access or modify other users' data while testing.