A client sends over six months of statements, you find a site that converts them at no cost, and you pause with the file selected. The hesitation is correct, and the usual advice is not: being told that a service takes security seriously is not information. What you need is a set of checks you can actually run, and an answer you could give the client if they asked where their statement went.
Free is not the same as unsafe. Plenty of free tools handle documents responsibly, and plenty of paid ones do not. The price does tell you one useful thing, which is that some other arrangement is paying for the servers. Working out what that arrangement is happens to be the fastest route to the answer. The checks below apply to every service you might use, including this one, and the last section answers them for us so you can hold the comparison side by side.
Work out what is paying for it
Running conversion at scale costs money. If you are not paying, these are the arrangements you will meet most often.
- Advertising and tracking. The page carries ads and analytics. Ordinary, and the relevant question narrows to what those third party scripts can see while a statement is on screen.
- A paid tier this one advertises. The free conversion is a sample of a commercial product. A commercial parent gives the service a business reason to handle files carefully and gives you a company to address a complaint to, which is worth something. It is not evidence of good handling on its own, so run the same five checks anyway.
- The data itself. Uploaded documents used to improve, train or evaluate a product. Sometimes disclosed in the terms as a broad licence to use uploaded content. This is the model that should stop you when the document is a client's bank statement.
- Nobody is paying for it. A side project, a volunteer maintained tool, or something grant funded. These vary enormously. Some are well maintained open source with a public issue tracker and a named maintainer; some were abandoned three years ago and still serve traffic. What they share is that there is no commercial party who is accountable to you, so you have to look at the evidence yourself: recent releases, a reachable maintainer, a stated policy.
There is a fifth arrangement worth knowing about, because it changes the question rather than answering it. Some free converters run entirely in your browser and never send the file anywhere. If that is genuinely what is happening, most of the checks below stop applying, because there is no upload and no retention. Verify the claim rather than accepting it: an offline test is the simplest one, since a tool that works with the network disconnected is not transmitting your statement.
If you cannot tell which arrangement you are looking at, that is itself the finding. A service that will not explain how it sustains itself has not given you enough to make a decision with a client's financial history.
The five answers, in writing
The five checks
Run these against the privacy policy and terms of service, not the marketing page. The marketing page is not a commitment; the terms are. Run them against every service you are considering, at every price, including the one you already pay for and including ours. The reason they are worth running on a no cost site is not that free is worse, it is that unanswered checks are more common where nobody has had to write a contract.
Retention window
Look for a specific period stated in hours or days, and for what it applies to: the uploaded statement, the converted output, or both. Phrases like deleted regularly, or deleted when no longer needed, are not retention policies. If no number appears anywhere, you do not know how long the file is kept and you have no commitment to hold anyone to. That is not proof it is kept forever; it is a reason not to send someone else's financial history until you have asked. A worked example of how one service states its retention, deletion and processing region shows what a checkable commitment looks like, and most services either make one or reveal that they have not thought about it.
Whether uploads are used for training
Search the terms for the licence you grant on upload. Broad wording covering the right to use, reproduce and modify submitted content to improve services can include model training. This is the check most people skip and the one with the longest tail, because a document absorbed into a training set cannot be recalled later by deleting your account.
Sub processors
A converter is rarely one company. There is usually cloud hosting, often a third party recognition service, sometimes an external model provider, and usually analytics of some kind. Each one is another party that touches the statement, or in the case of analytics, another party present on the page while it is on screen. A service handling professional data should name them; if the policy mentions unspecified third party service providers and stops there, you cannot tell a client who has seen their account number.
Processing region
Find where files are processed and stored, not where the company is registered. For client data under GDPR or an equivalent regime this is a compliance question rather than a preference, and the answer determines what you need on paper. Who counts as controller and who counts as processor depends on the jurisdiction and on the arrangement you have with whoever the statement belongs to, so it is worth establishing rather than assuming. The criteria worth applying to any converter you hand client data to turn on exactly this point and on whether a data processing agreement is on offer at all.
Deletion on request
Check that a route exists and that someone is on the other end of it. A named contact address, a stated response time, and ideally a self service delete control. On an abandoned project this check fails quietly: the address exists and nobody reads it. The cheapest way to find out is to send the request and see whether anything comes back.
How to run the check in ten minutes
- 1
Open the terms and the privacy policy
Read the actual documents, not the summary on the landing page. Search them for the words retain, delete, train, improve, and processor. - 2
Identify the business model
Look for ads, a paid tier, a stated data use, or an open source project with recent activity behind it. If none of them is visible, you do not know who is keeping the service running, and you should not assume anyone is. - 3
Test with a statement that is not a client's
Convert one of your own statements first, or a redacted sample, and see whether the output is usable before you commit real client data to the decision. - 4
Record what you found
Note the service name, the retention statement and the date you checked. This is what you produce when a client asks who processed their statement. - 5
Redact what does not need to travel
Remove anything the conversion does not require. Trimming account numbers and personal identifiers before upload reduces exposure regardless of how the service behaves.
That last step deserves emphasis, because it does not depend on anybody else's conduct. Deciding what to redact before uploading a statement reduces the exposure whether or not the converter is trustworthy, and it takes less time than reading the terms did. It is not a substitute for the other checks: redaction can be incomplete, and a statement stripped of too much may not convert at all. The controls that stack with it are choosing a service that has committed to a retention window in writing, and not uploading the document at all where it does not need to travel.
Turn the same checks on us
Criteria you will not apply to your own supplier are not criteria, so here are our answers in the same order, offered as something to check rather than something to take on trust.
The business model is the simplest one: conversion is paid for, per statement, and the price is published. Nothing about the service depends on what is inside your documents. Uploaded statement documents and the converted output are used only to complete the conversion you requested, and are not retained afterwards. They are not used for training, for analytics, or for any purpose beyond that single job. Account numbers, names and balances read from a statement go into the file you download and nowhere else. The processing and deletion detail is written out in full on the security page, in the specific terms this article asks you to demand, so you can repeat it to a client without paraphrasing.
That is the shape a complete answer takes: specific, written down, and not requiring you to infer anything. It is still a stated commitment rather than an inspection, which is exactly what the same answers from anyone else amount to as well, so treat it the way you would treat theirs. Ask for it in writing, keep a copy of what you were told and when, and hold every service you use to the same standard, including the one you are already paying for. The comparison of free against paid statement converters comes down to stated commitments rather than price.
When the answer is not to upload at all
A narrow category of documents should not leave your control at all: statements under litigation hold, files covered by a client confidentiality clause that prohibits third party processing, and anything you have been explicitly instructed to keep offline. No privacy policy changes that, and the correct handling is that the document stays where it is. Where the volume is small, rekeying the figures by hand or using something that processes the file locally keeps the document off the network entirely, which is the only control that does not depend on someone else's conduct.
For everything else, which is almost everything, a monthly statement you need as rows in a spreadsheet, the question is not whether free means unsafe. It is whether the service will tell you, in specific terms, how long it keeps the file, who else touches it, where it sits, and what it is allowed to do with it. Answers to all five are a floor rather than a certificate: they tell you what a service has committed to, not that its engineering matches, and they are still the best evidence available to you without an audit. A service that gives them plainly has given you something you can repeat to the client who asked. One that gives none of them has already told you what you needed to know.
Frequently asked questions
Are free online statement converters safe to use?
Some are and some are not, and the price tells you little either way. What you can actually check is whether the service states a retention window, discloses its sub processors, and rules out using your uploaded content to train models. A free converter that answers all three plainly has given you more to work with than a paid one that answers none of them.
If a converter is free, how is it making money?
Commonly one of these: advertising and tracking on the page, a paid tier the free one advertises, data used to improve or train a product, or nobody funding it at all because it is a side project or a volunteer effort. Some free tools also run entirely in your browser, so there is no server cost to cover. The first two are ordinary, the third matters for client data, and the fourth means you should check whether anyone is still maintaining it.
What should I look for in a converter's privacy policy?
A specific retention period stated in hours or days, a named list of sub processors, the country where files are processed, and an explicit statement about whether uploaded content is used for training or product improvement. Vague phrasing such as files being deleted regularly is not a retention policy.
Can I upload a client's bank statement to a free converter?
Only if you can answer your client's questions about it afterwards. In a typical engagement you are handling the document on the client's behalf and the converter is processing it on yours, though the exact roles depend on your jurisdiction and your engagement terms. Practically, that means reading the terms, keeping a record of which service you used and when, and confirming a data processing agreement is available if your jurisdiction requires one.
Does paying for a converter make it safe?
No. Payment changes the business model question, not the handling question. A paid service can still retain files indefinitely, process them in an unexpected jurisdiction, or reserve the right to use uploads for product improvement. Apply the same five checks regardless of price, including to services you already pay for.