Privacy policy
Last updated: 8 September 2026
1. Overview
PivotBank (“we”, “us”, or “our”) operates this website and associated services. We are committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data. PivotBank is operated by Muhammad Gulraize Bilal Ltd, a company registered in England and Wales under company number 15584684, whose registered office is 8 Beechfield Street, Manchester, M8 0SG, United Kingdom. That company is the data controller for the purposes of this policy.
The core principle: Your PDF is opened and read on your device. The file itself is never uploaded. The transaction lines are sent to be read by an AI model, and your name, postal address, account number, IBAN and sort code are removed before that request leaves your device. Our own rules read every statement on your device first, and where their reading proves out against the statement’s own balances it is the one you get, but the lines are sent either way. Section 3 sets out exactly what is sent.
One exception, only when you ask for it: if you choose to unlock and save a statement (the optional one-time paid feature), the extracted transaction data, not the original PDF, is sent to and stored on our servers so you can re-download it later from your account. This only ever happens for statements you explicitly unlock while signed in, and you can permanently delete any saved statement at any time from your account.
2. Information We Collect
2.1 Account Information
If you create an account, we collect your name and email address. You may sign in via Google OAuth or with an email and password. We do not store plain-text passwords, credentials are hashed using industry-standard algorithms.
2.2 Usage Data
We record the number of pages converted, with a timestamp, to understand usage and to prevent abuse. We store only a page count and a timestamp, never the content of your statements.
2.3 Anonymous Session Identifiers
For unauthenticated users we generate a short-lived anonymous session ID stored in your browser’s local storage. This is used solely to attribute conversions to one browser and to prevent abuse, and is not linked to any personally identifiable information.
2.4 Cookies & Analytics
We use essential cookies for authentication and session management. With your consent, we also use Google Analytics (with IP anonymisation enabled) to understand how visitors use PivotBank. Analytics cookies are only loaded after you click “Accept All” on the cookie banner. If you choose “Essential Only”, no analytics data is collected. See our Cookie Policy for full details.
2.5 Saved Statements (optional)
When you unlock and save a statement, we store the extracted transaction data (dates, descriptions, amounts, balances and detected metadata such as bank name and statement period) associated with your account. We never store the original PDF file. This data is encrypted at rest and is used solely to let you re-download your statement. You can permanently delete any saved statement at any time, which removes it from our database.
3. Your Bank Statement Data
When you drop a PDF into PivotBank, the file is opened and read by your browser’s local JavaScript engine. Text extraction and spreadsheet generation happen on your device, and the PDF file itself is never uploaded to us or to anyone else. This includes scanned statements, where the page image is read by optical character recognition in your browser. Where our own rules can read the statement and prove the result against its own balances, that reading is the one used, even though the lines were also sent. Where they cannot, the model’s reading is used instead. That reading is checked against the statement’s own balances before it is used, and where the check fails the lines are sent again to a second, more careful model, so a statement may reach more than one provider.
What is sent is the transaction table only: dates, descriptions, amounts and balances. Your name, postal address, account number, IBAN, BIC and any card numbers are stripped out first, and everything above the transaction table on every page is removed with them. Every request that carries statement content goes out with an instruction about what may be kept of it, and which instruction depends on who reads it: to Cheaper Inference, which reads by default, we require zero retention routing, so the request goes only to a provider that states it keeps neither the prompt nor the response and trains on neither, and where no such provider serves the model the request fails rather than being handed to one that retains it; to OpenAI, which reads as a fallback, the request is marked not to be stored. The separate step that labels transactions with a category is held to the same rule. We do not keep it either: we hold no copy of your statement unless you choose to unlock and save one, which section 2.5 covers.
4. Third-Party Services
4.1 Stripe
Statement unlocks are one-time payments processed through Stripe, there is no subscription. When you pay to unlock a statement, your payment details are collected and stored by Stripe directly, we never see or store your card number. Stripe’s privacy policy is available at stripe.com/privacy.
4.2 Google OAuth
If you choose to sign in with Google, we receive your name and email address from Google’s OAuth service. We do not receive access to your Google Drive, Gmail, or any other Google service data.
4.3 The models that read statements
Statements that cannot be read on your device are read by an AI model. Only the transaction table is sent, with the identifying details listed in section 3 removed first, and every request carries an instruction about what may be kept of it. The reading is provided through Keak AI, Inc., trading as Cheaper Inference, which is a processor for this purpose and which routes the request to the operator of the model that performs it, currently DeepSeek, and may route it through a further provider in turn. We mark those requests for zero retention routing, which on Keak’s account sends them only to a provider that keeps neither the prompt nor the response and trains on neither, and where no such provider serves the model the request is refused rather than routed to one that retains it. Keak states that it keeps usage and billing records only and not the content of requests; its privacy policy is at cheaperinference.com. OpenAI remains available as a fallback reader and is also a processor for that purpose; requests to OpenAI are marked not to be stored, so they are not retained beyond the short window OpenAI keeps for abuse monitoring and are never used for training, and its privacy policy is at openai.com/policies/privacy-policy. Where no model will read a statement, the reading falls back to our own rules, which run on our server and send nothing further. The step that labels transactions with a category is held to the same rule as the reading itself. We cannot independently verify how long any provider keeps a request, which is why we send as little as we can rather than rely on it. The full list of processors, and the country each is in, is on our sub-processors page at /sub-processors.
5. Data Retention
Account data (name, email, unlock history) is retained for as long as your account is active. Conversion count records (page counts and timestamps, no content) are retained for 30 days for limit-enforcement purposes.
You may delete your account at any time from the Account Settings page. Upon deletion, all your personal data is permanently removed from our systems within 30 days.
6. Data Security
We use industry-standard security measures including HTTPS encryption for all data in transit and encrypted storage for data at rest. Access to production databases is restricted to authorised personnel only.
7. Your Rights
Depending on your jurisdiction you may have rights including: access to your personal data, correction of inaccurate data, deletion of your data, portability of your data, and the right to object to certain processing.
To exercise any of these rights, contact us at [email protected].
8. Children’s Privacy
PivotBank is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of PivotBank after changes constitutes acceptance of the updated policy.
10. Contact
If you have any questions about this Privacy Policy, please contact us:
- Email: [email protected]
- Contact form: /contact
