Effective September 25, 2026
ZeroParse Statements is built around not having your financial data to lose. CSV and Excel files are parsed entirely in your browser and never uploaded anywhere. PDF files are uploaded for text extraction, processed in memory, and destroyed immediately after — never written to disk, never retained. We store the minimum needed to run your account: your email, credit balance, and plan.
CSV and Excel files never leave your browser — they are parsed by JavaScript running on your own device, so there is nothing for us to collect even if we wanted to. PDF files are different in kind but not in outcome: the file is held in server RAM strictly for the duration of the OCR/extraction run needed to answer your request, is never written to disk at any point, and every reference to it (and to the text extracted from it) is dropped from memory before the response is returned — whether extraction succeeds or fails. What survives that request is exclusively non-content operational telemetry: which account made the request, how many pages, how long it took, and whether it succeeded — never what the statement said.
If you report a problem while signed in, you can optionally attach the file the problem is actually about (PDF, CSV, or Excel, up to 3MB) so we can diagnose it. This is off by default and requires an explicit, separate checkbox — it never happens as a side effect of using the Service or sending ordinary feedback.
We use the data described above to:
We do not sell your data, use it for advertising, or send it to third-party AI models for training.
For users in the EU/EEA and UK, we process personal data under the following legal bases (GDPR Article 6):
Cross-border transfers. We are based in Singapore and our infrastructure providers — Vercel, Render, and Supabase — operate cloud infrastructure across multiple regions, which may include regions outside your own. Error reports sent to Sentry are stored in its United States region. Where that involves transferring personal data out of the EU/EEA, UK, or Singapore, we rely on the standard contractual clauses or equivalent transfer safeguards those providers make available under their own terms, rather than maintaining separate transfer agreements of our own. If you need copies of the specific mechanisms in place for your account, email admin@getzeroparse.com.
If you're in Singapore, we handle personal data consistent with the Personal Data Protection Act (PDPA); if you're in California, see the CCPA note in Section 8 below.
We use a small number of infrastructure providers to run the Service, each of whom only sees what they need to do their job:
We don't share your data with anyone else, except where required by law. If you're an accounting firm or other organization processing client data through ZeroParse Statements, our Data Processing Addendum sets out these same providers as pre-approved subprocessors, with a process for notifying you before we add or change one.
We use strictly-necessary cookies to keep you signed in — nothing else on ZeroParse Statements sets a cookie.
We use Vercel Web Analytics and Speed Insights to understand site traffic and performance. Both are cookieless: they don't track you individually or across other sites, and we never see your IP address or any personally identifying information through them — only aggregated counts (page views, referrers, approximate country, device/browser type, and page load performance). We do not collect personal demographic data (age, gender, income, etc.) — that would require far more invasive tracking than we're willing to add, and it isn't something Vercel Analytics provides. Because this analytics is cookieless and doesn't process personal data, no cookie-consent banner is required for it; if we ever add anything more invasive, we'll add a consent banner and update this section first.
From your Account page, you can:
If you're in the EU/EEA or UK, GDPR also gives you the right to access, rectify, restrict, or object to our processing of your data, and to lodge a complaint with your local data protection authority. If you're a California resident, the CCPA gives you the right to know what personal information we collect and to request its deletion — both of which the Account page above already gives you directly, since our collection is deliberately narrow enough that there's nothing extra to disclose. We do not sell personal information, so there is no opt-out to exercise. For any of the above, or any other jurisdiction's data rights, email us at admin@getzeroparse.com and we'll assist directly.
We keep your account data for as long as your account exists. PDF file contents are never retained at all — there is nothing to expire. Processing metadata (file type, page count, timestamp) and your credit history are kept until you delete your account, at which point they are permanently deleted along with everything else tied to your account. Failed sign-in records are deleted automatically after 24 hours, whether or not you have an account with us.
All traffic is encrypted in transit (TLS). Database access is protected by row-level security so your account data is only ever readable by you. Administrative operations (billing, account deletion) use a separate, tightly-scoped service credential that is never exposed to the browser.
If you're a CPA, bookkeeping firm, or other organization using ZeroParse Statements to process statements on behalf of clients or third parties, our Data Processing Addendum sets out the roles, security commitments, and subprocessor list relevant to that use. You can also request it directly by emailing admin@getzeroparse.com.
ZeroParse Statements is not directed at children under 16, and we don't knowingly collect data from them.
We may update this policy from time to time. Material changes will be reflected by updating the effective date above.
Wedgr Technologies (UEN 53532707B), which operates ZeroParse Statements, is responsible for the personal data described in this policy. Questions about this policy: admin@getzeroparse.com