Skip to main content
Convert·Into
Trust & transparency

Data Handling

A step-by-step account of exactly what happens to a statement from the moment you upload it to the moment it is gone: the practical companion to our Privacy Policy.

Effective 1 July 2026 · Last updated 1 July 2026
The lifecycle of a file
  1. 01
    Upload
    Encrypted in your browser over TLS 1.3 before a single byte leaves your device.
  2. 02
    Isolate
    Placed in a single-tenant sandbox with no access to other customers or shared disks.
  3. 03
    Convert
    Read once, only to extract transactions and build your output, nothing else.
  4. 04
    Return
    Delivered directly to your encrypted workspace, ready to download.
  5. 05
    Delete
    Source and output are erased when you remove them, or on your retention schedule.

1. What this page covers

Our Privacy Policy sets out our legal commitments. This page is the practical companion to it: a plain, operational description of what actually happens to a statement you upload, at each stage, so you can satisfy yourself, and your own clients, that the data is handled responsibly.

Where this page and the Privacy Policy overlap, the Privacy Policy governs. This page is intended to inform, not to create additional contractual terms.

2. Upload & encryption

When you add a file, it is encrypted in your browser and transmitted to us over TLS 1.3. It is written to storage already encrypted with AES-256, using keys held in a hardware security module and never stored alongside the data they protect.

We do not accept files by email or other unencrypted channels, and we do not ask you to send statements outside the application.

3. Isolated processing

Each conversion runs in an isolated, single-tenant environment. The process that reads your file has no access to other customers’ data, to shared storage, or to the public internet beyond what the conversion requires.

Your file is read for one purpose only: to detect the statement’s layout, extract transactions, and produce the output format you asked for. It is not indexed, profiled, or copied into any secondary system.

4. Who can see your files

In normal operation, no member of staff reads your files. Access to production data is role-scoped, logged, and granted only when strictly necessary: for example, to investigate a fault you have reported.

When such access is needed:

  • It requires a specific, approved reason tied to a support case.
  • It is time-limited and automatically revoked afterwards.
  • Every access event is recorded in an audit log you can request.

5. No training, no profiling, no resale

We never use your files, or the data extracted from them, to train or fine-tune machine-learning models. We do not build profiles from your statements and we do not sell, rent, or share your data for advertising.

Any models involved in conversion are operated by us within our own environment; your data is not sent to third-party AI services.

6. Sub-processors

A short, deliberately minimal set of vetted providers helps us run the service: cloud hosting, payment processing, and transactional email. Each is bound by contract to protect your data and use it only on our instructions.

We keep the list short by design, review it regularly, and publish the current version on request. Statement contents are never shared with a payment or email provider.

7. Retention & deletion

You are in control of how long converted files live. Delete a file at any time and both the source and its output are removed. If you take no action, files are removed automatically on the default schedule for your plan.

Professional and Enterprise customers can configure custom retention windows, including immediate deletion after download. When data reaches the end of its retention window, it is deleted from live systems and rolled out of encrypted backups on the next cycle.

8. Getting your data out

Your converted files are yours. You can download them in the formats we support at any time while they are retained, and you can request a copy of the account data we hold about you.

If you close your account, you can export your data first; once the account is closed, remaining data is deleted in line with our retention schedule and any legal record-keeping obligations.

9. If something goes wrong

Our infrastructure is monitored continuously, and we maintain a tested incident-response plan. If a security incident affected your data, we would investigate, contain it, and notify affected customers and any relevant regulator within the timeframes the law requires.

You can report a suspected issue at any time to security@convertin.to; see our Security overview for how we protect the service day to day.

Questions about your data?

Our data team answers handling and deletion questions directly at privacy@convertin.to. For the legal detail see our Privacy Policy, and for infrastructure controls see our Security overview.