The short version
- Your bank statements are converted inside your browser. They are never uploaded to our servers and never stored by us.
- We keep only what an account needs: your email, your plan, your credit balance, and usage counts (page numbers — never page contents).
- You can verify this yourself: load the page, disconnect from the internet, and the converter still works.
1. Who we are
Fahad Mehmood, a sole proprietor trading as BayanSheet (“BayanSheet”, “we”, “us”), is the controller of your data and provides a tool that converts bank statement PDFs into Excel and CSV files, built first for accountants in the UAE and the wider Arab world. You can reach us at support@bayansheet.com.
2. Your statements never reach us
When you convert a statement, the file is read and processed by code running in your own browser, on your own device. The PDF is not sent over the internet to BayanSheet. The extracted transactions exist only in your browser’s temporary memory, and the Excel/CSV output is generated in the browser and saved directly to your device. When you close or refresh the tab, nothing remains.
Because the file never reaches us, we cannot store it, leak it, log it, or be forced to hand it over.
Don’t take our word for it. Let the page load, then disconnect from the internet — the conversion still works, which would be impossible if your file were being uploaded. You can also open your browser’s developer tools (F12 → Network tab) and watch: no request carries your file anywhere.
3. What we do store
If you create an account, we store the minimum needed to run it and bill for it:
- Account: your email address, an optional display name, and a password stored only as an irreversible hash.
- Plan and billing state: your subscription tier and status, billing interval, and identifiers that link your account to our payment provider.
- Usage numbers: your page allowance, pages used this period, and your never-expiring credit balance — counts only.
- Conversion metadata: when a conversion ran, which bank template was used, how many pages, whether it succeeded, and the output format (xlsx/csv). Never the contents.
- Support messages you choose to send us.
4. What we never store
- The bank statement PDF itself, or any part of it.
- Any transaction data — amounts, dates, descriptions, balances.
- Account numbers, IBANs, or card numbers from statements.
- Names, addresses, or any personal data found inside a statement.
- The Excel/CSV output file.
- The file names of your statements (these can contain client names).
5. Service providers we use
A small number of companies process limited data on our behalf:
- Vercel — our hosting provider. Every page of this site is served from Vercel, so it necessarily sees the ordinary details of a web request: which page was asked for, your IP address, and your browser type. It also provides the page-view counting described in section 6. It never receives a statement file — the file is never sent anywhere.
- Supabase — our authentication and database provider. It stores the account and usage records described in section 3, including your login email and hashed password.
- Paddle — our payment provider and merchant of record. When you pay, your card details go directly to Paddle and never touch our servers. Paddle appears as the seller on your card statement and invoice, and calculates and remits VAT/sales tax.
- Plausible Analytics — our page-view analytics provider. It is cookieless and does not track you across websites. What it receives is listed in section 6: the addresses of the pages visited, and three product counters. It never receives a statement, a file name, a transaction, or your email address.
None of these providers ever receives your statement files or their contents — the files never leave your browser. If this list changes, we will update this page. You can request the current list at any time via support@bayansheet.com.
6. Cookies, local storage, and analytics
We use only what the service needs to function:
- Session: if you log in, your browser holds a session token so you stay signed in.
- Free-page counter: if you try the tool without an account, your browser’s local storage keeps a small counter of the free pages you have used. It stays on your device.
No statement data is ever written to cookies, local storage, or any other browser storage. We do not use advertising cookies or cross-site trackers, and we do not sell or share anything with advertisers.
We do count page views — we would rather name it here than have you find it in your browser’s Network tab. Two cookieless services do this:
- Vercel Web Analytics — provided by our hosting company and served from our own domain. It counts page views. It sets no cookie and builds no profile that follows you to other websites.
- Plausible Analytics — a privacy-focused, cookieless service. It receives the address of the page you are on, and three product counters: a conversion succeeded (with the number of pages), a conversion failed (with a short reason code such as “scanned” or “not-pdf”), and a counter for when our own page-metering service is unreachable.
Neither one receives any part of a statement — not the file, not its name, not a transaction, not an amount. That is not a matter of our carefulness: the only values our code is able to send are a page count and one of a fixed, short list of reason codes, and that restriction is enforced in the code itself. Neither service is used for advertising, and we do not sell or share what they collect. If we ever add another analytics service, or start collecting anything beyond this, we will update this page.
7. A possible future feature: assisted OCR (not active)
Some scanned or unusual statements are hard to read in the browser alone. We may one day offer an optional, consent-based mode that sends a difficult page to a server for OCR help. To be clear: this mode does not exist today — no statement data leaves your browser in any current path. If we ever build it, it will be strictly opt-in (off by default), we will name the provider, require a zero-data-retention arrangement, and update this policy before it goes live.
8. Your rights
We honour data-protection rights under the UAE Personal Data Protection Law (PDPL) and, for users in the EU/UK, the GDPR: you may access, correct, export, or delete your data. Because we store so little, an export is small — your account details, billing state, and conversion metadata.
Deleting your account removes your account, subscription, credit, and conversion-metadata records, including your record with our authentication provider. Invoices may be retained in anonymised form where tax and accounting law requires it. To request deletion, email support@bayansheet.com from the address on your account and we will action it within 30 days.
9. How long we keep data
The period for each kind of record we hold:
- Statement contents: no period — we never store them, so there is no copy anywhere to expire.
- Account data (email, display name, hashed password): kept while your account exists. Email us to delete it and we action the request within 30 days.
- Billing and credit records (plan and status, credit purchases and spends, payment-provider identifiers): kept while your account exists and deleted with it. The invoice itself belongs to Paddle, our merchant of record, which keeps its own payment and tax records for as long as the accounting and tax rules that apply to a sale require — those are not ours to delete. A payment we cannot match to an account stays on a reconciliation list until we resolve it; that entry holds billing identifiers and amounts only, never your email.
- Conversion metadata (date, page count, bank template, whether it succeeded, output format): kept while your account exists and deleted with it. You can ask us to purge it sooner. Conversions run without an account are counted with no identifier attached at all.
- Statement layout reports (the bank name and short note you send us when a statement converts badly): kept for up to 24 months while we fix that bank’s layout, and cleared at our annual January review. Deleting your account removes the link to you, leaving only the bank name and the note.
- Admin audit log (a record of every change we make to a plan or a credit balance): kept for as long as we operate — it is the proof that nothing was changed without a trace. Deleting your account unlinks these entries from your account record. One exception, which we would rather state than have you discover: where the entry is the record of us changing your email address or deleting your account, your email address is kept inside that entry on purpose — an audit log that cannot say whose account was deleted is not an audit log, and it is what lets us show, years later, that a deletion we were asked for actually happened. Nothing else about you is in it, and it is never used to contact you or to rebuild your account.
- Server and hosting logs: kept for the short default period our hosting provider applies; we do not extend it. They record requests and errors — never a request body, never statement data.
Nothing on this list contains any part of a bank statement.
10. Legal bases
We process account and billing data to perform our contract with you (providing the service you signed up for), and limited operational data under our legitimate interest in keeping the service secure and preventing abuse. Anything optional will be based on your consent.
11. Changes to this policy
If we change how the product handles data, we will update this page and the “last updated” date, and for significant changes we will notify account holders by email.
12. Contact
Questions, requests, or concerns: support@bayansheet.com. See also our Terms.