Who we are
StatementProof is operated by To be confirmed, registered at To be confirmed, GSTIN To be confirmed. For the purposes of India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the account data described below, and a Data Processor acting on your instructions for the client statements you upload.
Questions about this policy go to hello@statementproof.in. Our grievance officer is To be confirmed, reachable at the same address.
What we collect, and why
We collect three separate categories of data, kept for different reasons and different lengths of time.
| Category | What it includes | Why we hold it |
|---|---|---|
| Early-access enquiries | Name, work email, firm name, role, monthly page volume, preferred output format, the page you arrived on, referring URL and UTM parameters | To contact you about the pilot and to understand which channels reach accounting firms |
| Account data | Name, email address, hashed password, workspace membership and role, session records | To operate your account, authenticate you and enforce role permissions |
| Client statement data | Uploaded statement files, extracted transactions, corrections, exports, and an audit record of who did what | To perform the conversion and reconciliation you asked for, and to give you a defensible trail |
We do not ask for, and cannot accept, bank login credentials. There is no account linking and no ongoing access to any bank account. The service works only from statement files you already hold.
We do not sell personal data, and we do not use client statement contents to train models or to build any profile of you or your clients.
The lawful basis for each use
- Early-access enquiries are collected on the consent you give by submitting the form. You can withdraw it at any time, and we will delete the record.
- Account data is processed because it is necessary to provide the service you have signed up for.
- Client statement data is processed on your instruction, as your processor. You remain responsible for having the right to share your clients' statements with us.
How long we keep it
| Data | Retention | How it ends |
|---|---|---|
| Uploaded statement files | 24 hours by default; configurable per workspace from 0 to 365 days | A scheduled hourly sweep deletes the encrypted bytes and the stored file password |
| Extracted transactions and exports | Same policy as the file they came from | Removed with the parent document |
| Audit events | Retained after the document is purged | Deliberately outlives the data, so the record of who accessed what survives deletion. Carries no statement contents |
| Account and workspace records | For as long as the account is open | Deleted on request, subject to statutory retention of billing records |
| Early-access enquiries | Until you ask us to remove them | Deleted on request |
On-demand deletion is immediate. Policy-based expiry runs as a scheduled sweep, so a file may persist for up to an hour past its stated expiry before the sweep reaches it.
How it is protected
- Statement files are encrypted at rest with a per-workspace key and tamper-checked on read, so an altered file fails to open rather than returning altered data.
- Passwords are stored as scrypt hashes. Password reset and email tokens are stored only as HMAC hashes, never in recoverable form.
- API keys are read-only and stored as hashes. Outbound webhooks are signed so your systems can verify they came from us.
- Access, corrections and exports are attributable to the individual member who performed them.
Who else processes it
We use the following sub-processors. Each is bound to process data only on our instructions.
| Sub-processor | Purpose | Data reaching them |
|---|---|---|
| Neon | Managed Postgres database | Account records, workspace settings, extracted transaction data, audit events |
| Vercel | Application hosting and compute | Encrypted statement files, request logs |
| Resend | Transactional email delivery | Name and email address, for password resets, invitations and confirmations |
| Kelviq | Payment processing for page credits | Billing contact and payment details, handled by Kelviq — card numbers never reach our servers |
Transfers outside India
Our infrastructure providers operate globally. Data for this service rests in To be confirmed. Where that is outside India, the transfer is made on the basis that the destination is not a territory restricted by the Central Government under the DPDP Act, and our providers are contractually bound to equivalent protections.
Your rights
Under the DPDP Act you may exercise the following rights over personal data we hold about you. Write to us and we will respond within 30 days.
- Access — a summary of the personal data we hold about you and how it is being processed.
- Correction — to have inaccurate or incomplete data corrected or completed.
- Erasure — to have your data deleted where we no longer need it or where you withdraw consent.
- Withdrawal of consent — as easily as it was given, for anything processed on that basis.
- Grievance redressal — to raise a complaint with our grievance officer before approaching the Data Protection Board of India.
- Nomination — to nominate another individual to exercise these rights should you die or become incapacitated.
If your client asks you to exercise their rights over a statement you uploaded, you can act on that directly: deletion is available to you in-product and takes effect immediately.
Changes to this policy
If we change how data is handled in a way that affects you, we will update the date at the top of this page and, for material changes, notify account holders by email before the change takes effect.