What we process, what we keep, and who else is involved. Effective September 3, 2026.
Your statements are parsed in memory and never written to disk. They are never stored, never sold, never shared, and never used to train anything. No third-party AI or LLM service is in the processing path. What we do keep is a small account record if you sign in, and one anonymous line of metadata per conversion. That is the whole list.
When you upload a statement PDF, it travels over TLS to our server, is parsed in memory by our own software, and the result is sent back to your browser. When the request ends the file is gone. The web server is configured so that request bodies are not spooled to disk even temporarily. The result page is not stored either. There is no workspace and no library of client files on this server; if you need the spreadsheet again, convert the PDF again.
If a page of the PDF has no text layer, it is rendered to an image in memory and read by OCR software (Tesseract) running on the same server. The image is passed to that program over a pipe and is never written to a file. No outside OCR or AI service is involved.
If the PDF has a password, you enter it in the browser and it is used once, in memory, to open the file. It is not kept.
When you download an export, the file is built from the grid your browser sends and streamed back to you. The export is not kept.
If your statement comes from a bank whose layout we cannot read yet, we keep only the layout shape so we can add support: the column headings, their positions, and the date and money formats. The shape never contains amounts, names, dates, or account numbers. The result page tells you when this has happened and shows the words that were retained (typically a handful, such as the bank's name, "Date", "Description", "Amount", "Balance"). If you would rather we kept nothing, email us and we delete that layout.
We set a session cookie after you sign in, so the site knows it is you, and a gate cookie while the site is in private testing. There are no advertising trackers and no third-party analytics scripts. Our analytics are server-side counts that do not use cookies and do not identify you.
Nobody else. Statements are not sent to any third party, including AI, OCR or document-processing services. The OCR we use runs on our own server.
Statements: not retained. Exports: not retained. Account records: for as long as your account exists, then deleted on request or when we close the account. Metadata lines: kept as anonymous counts. Support email: for as long as needed to handle your request.
Wherever you are, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email ville@pennyclose.com from the address on your account and we answer within one business day. If you are covered by the GDPR, the UK GDPR, the CCPA or a similar law, you also have the rights those laws give you, including the right to complain to your local supervisory authority. We do not sell personal information and never have.
Connections use TLS (1.2 or 1.3). Processing happens in memory on a dedicated, isolated US server used for nothing else. Administrative access is by cryptographic key only, limited to one person, and the parsing service runs as an unprivileged account with no write access to the system. Card data never reaches us. If you find a security problem, email ville@pennyclose.com and we will respond within one business day.
The service is for adults handling business records. It is not directed at anyone under 18 and we do not knowingly collect information from them.
If this policy changes in a way that matters, we update the effective date at the top and email account holders before the change takes effect. If a fact on this page stops being true, we change the page the same day.
Email ville@pennyclose.com. PennyClose is run by its founder; this address reaches them directly.