Security
What happens to a bank statement after you upload it: where it is stored, who processes it, and when it is deleted.
This page summarises how the service is built. The Privacy Policy is the document that governs, and it is more detailed. Last updated 15 August 2026.
Storage and encryption
- Where your files are stored
- Our primary infrastructure runs on AWS in the EU (Ireland), with the website delivered through CloudFront's edge network. Uploaded documents and generated output files are stored in object storage in that region.
- Encryption
- All traffic to and from the service uses TLS. Stored files are encrypted at rest with AES-256 server-side encryption.
- Access to the storage
- The storage buckets holding uploads and outputs block public access and are reachable only through identity-restricted access from our own services. Download links handed to your browser are time-limited and signed for a single file.
- Accounts
- Authentication runs on AWS Cognito. Passwords are hashed, and Google Sign-In is available if you would rather not have a password with us at all.
- What we never ask for
- We do not connect to your bank. There is no place in the product to enter online banking credentials, and no integration that would use them. You give us a file.
Retention and deletion
- Uploaded documents
- Deleted automatically seven days after upload. This is enforced by a storage lifecycle rule rather than by a scheduled job, so it happens whether or not anything else is working.
- Converted output files
- The same seven days from generation. That window is what makes the conversion history re-downloadable; after it, the files are gone.
- Deleting sooner
- Deleting a conversion from your history removes the output file, the metadata beside it and the original document you uploaded, without waiting for the seven days.
- Files you attach to feedback
- Kept for up to 30 days, then deleted.
- Your account
- You can delete it from the dashboard. Deletion removes your remaining files and your per-account records within 30 days; the Privacy Policy sets out exactly what is kept and why.
AI processing
- What is sent
- Converting a PDF means sending the document to an AI provider for extraction. That is the core of how the product works, and it is worth understanding before you upload anything sensitive.
- Training
- The providers we use are contracted so that inputs and outputs are not used to train or fine-tune their models, and are not retained beyond returning the result to us. Providers may keep their own request metadata, such as volumes and timestamps, for security and abuse monitoring.
- Where it happens
- Depending on the provider, processing may take place in the EU or in the United States. For transfers outside the EU we rely on the safeguards set out in the Privacy Policy.
- Current AI providers
- Anthropic (extraction, United States with global routing), Fireworks AI (document processing, United States), Datalab (OCR, United States) and Mistral AI (document processing, EU). The Privacy Policy carries the full sub-processor list, including payment, email and analytics providers, and is updated when it changes.
What this page does not claim
Worth stating plainly, because security pages tend to imply more than they say.
- We hold no third-party security certification. There is no SOC 2 report, no ISO 27001 certificate and no published penetration test.
- We do not claim that no person could ever access an uploaded document. Access is restricted to our own services, and we do not read customer statements as a matter of course, but we do not publish a formal access-control policy you could hold us to.
- No system is perfectly secure. If a personal data breach affecting you occurs, we will notify you and the relevant supervisory authority as the law requires.
Reporting something
If you think you have found a security problem, email info@ledgertome.com with enough detail to reproduce it. We would rather hear about it early and awkwardly than late.