ZeroParse
HomeHelp

Privacy Policy

Effective September 25, 2026

1. The short version

ZeroParse Statements is built around not having your financial data to lose. CSV and Excel files are parsed entirely in your browser and never uploaded anywhere. PDF files are uploaded for text extraction, processed in memory, and destroyed immediately after — never written to disk, never retained. We store the minimum needed to run your account: your email, credit balance, and plan.

2. What we collect

  • Account data: your email address and password (password is hashed by our authentication provider, Supabase Auth — we never see or store it in plain text).
  • Billing data: your subscription tier, credit balance, and Stripe customer/subscription IDs. Card numbers are handled entirely by Stripe — we never receive or store them.
  • Processing metadata: for each PDF you process, we log the file type, page count, and timestamp — never the file's contents.
  • Operational telemetry: server logs and (for administrators) an operations console record response times, error codes, and an account identifier — either our internal account ID or a non-reversible identifier derived by one-way hashing your email address — never the email itself, and never statement contents. When something fails, a technical error report goes to our error-monitoring provider, Sentry (Section 6). This exists to debug incidents and detect abuse, not to profile you.
  • Failed sign-in attempts: to protect your account from password-guessing, we record the email address used in a failed sign-in and the time it happened. No password data is ever recorded. These records are deleted automatically after 24 hours.
  • Feedback you send us: the message text, and — only if you're signed in and explicitly check the box to include one — a file you choose to attach to a support request. This is the one deliberate exception to everything below; see Section 3a.

3. What we never collect, and the technical reason why

  • Transaction descriptions, amounts, dates, or any other statement contents.
  • Bank account numbers, routing numbers, or balances.
  • The contents of any CSV, Excel, or PDF file you process — with one narrow, opt-in exception described in Section 3a.
  • Your payment card details.

CSV and Excel files never leave your browser — they are parsed by JavaScript running on your own device, so there is nothing for us to collect even if we wanted to. PDF files are different in kind but not in outcome: the file is held in server RAM strictly for the duration of the OCR/extraction run needed to answer your request, is never written to disk at any point, and every reference to it (and to the text extracted from it) is dropped from memory before the response is returned — whether extraction succeeds or fails. What survives that request is exclusively non-content operational telemetry: which account made the request, how many pages, how long it took, and whether it succeeded — never what the statement said.

3a. Feedback attachments — the one exception, and only if you choose it

If you report a problem while signed in, you can optionally attach the file the problem is actually about (PDF, CSV, or Excel, up to 3MB) so we can diagnose it. This is off by default and requires an explicit, separate checkbox — it never happens as a side effect of using the Service or sending ordinary feedback.

  • It is stored, not processed-and-discarded. The file is emailed, as an attachment, to our support inbox via Resend (the same provider used for other account emails). Unlike every other file this product touches, it is not held in memory and dropped — it sits in that inbox.
  • Retention is manual, not automatic. We aim to review and delete it within about a week, but that is an operational commitment, not a system control — no software here enforces an expiry. If that matters for your situation, don't check the box.
  • Who can see it: whoever on the ZeroParse Statements team investigates the report, via that inbox — the same access any of our support email already has.
  • Only signed-in accounts can attach a file, so there's a traceable owner for every attachment we hold.

4. How we use your data

We use the data described above to:

  • Authenticate you and maintain your session.
  • Track and enforce your credit balance.
  • Process payments and manage your subscription.
  • Respond to support requests you send us.
  • Detect abuse and debug incidents, using the operational telemetry described above.

We do not sell your data, use it for advertising, or send it to third-party AI models for training.

5. Legal basis & international transfers (GDPR)

For users in the EU/EEA and UK, we process personal data under the following legal bases (GDPR Article 6):

  • Contractual necessity — account data, billing data, and processing metadata, because we can't run your account, deduct credits, or bill your subscription without them.
  • Legitimate interests — operational telemetry and failed sign-in records, for security, fraud prevention, and keeping the Service running, balanced against your privacy by keeping this data non-content, short-lived (failed sign-ins), or already non-reversible (the hashed account identifier).

Cross-border transfers. We are based in Singapore and our infrastructure providers — Vercel, Render, and Supabase — operate cloud infrastructure across multiple regions, which may include regions outside your own. Error reports sent to Sentry are stored in its United States region. Where that involves transferring personal data out of the EU/EEA, UK, or Singapore, we rely on the standard contractual clauses or equivalent transfer safeguards those providers make available under their own terms, rather than maintaining separate transfer agreements of our own. If you need copies of the specific mechanisms in place for your account, email admin@getzeroparse.com.

If you're in Singapore, we handle personal data consistent with the Personal Data Protection Act (PDPA); if you're in California, see the CCPA note in Section 8 below.

6. Who we share data with

We use a small number of infrastructure providers to run the Service, each of whom only sees what they need to do their job:

  • Supabase — authentication and database hosting (email, credit balance, plan).
  • Stripe — payment processing (billing details, never your card number).
  • Vercel — hosts the web application, and provides aggregated, cookieless traffic analytics (see Cookies & Analytics below).
  • Render — hosts the PDF extraction backend; sees PDF contents only transiently, in memory, during processing.
  • Resend — delivers account and administrative emails. If you choose to attach a file to a support request (Section 3a), Resend is where it's actually stored, as an email attachment, until we delete it.
  • Sentry — error monitoring for the web application and the PDF extraction backend. When something fails, it receives a technical report: the error and where in our code it happened, the page or endpoint involved (without any query string), and log messages from just before it, which identify an account only by our internal account ID or the one-way hash described in Section 2. It never receives statement contents, passwords, payment details, request bodies, or session cookies. Reports are stored in Sentry's United States region.

We don't share your data with anyone else, except where required by law. If you're an accounting firm or other organization processing client data through ZeroParse Statements, our Data Processing Addendum sets out these same providers as pre-approved subprocessors, with a process for notifying you before we add or change one.

7. Cookies & analytics

We use strictly-necessary cookies to keep you signed in — nothing else on ZeroParse Statements sets a cookie.

We use Vercel Web Analytics and Speed Insights to understand site traffic and performance. Both are cookieless: they don't track you individually or across other sites, and we never see your IP address or any personally identifying information through them — only aggregated counts (page views, referrers, approximate country, device/browser type, and page load performance). We do not collect personal demographic data (age, gender, income, etc.) — that would require far more invasive tracking than we're willing to add, and it isn't something Vercel Analytics provides. Because this analytics is cookieless and doesn't process personal data, no cookie-consent banner is required for it; if we ever add anything more invasive, we'll add a consent banner and update this section first.

8. Your rights

From your Account page, you can:

  • Export your data — download everything we hold about your account as a JSON file.
  • Delete your account — permanently removes your profile, credit balance, and processing history. This cannot be undone.

If you're in the EU/EEA or UK, GDPR also gives you the right to access, rectify, restrict, or object to our processing of your data, and to lodge a complaint with your local data protection authority. If you're a California resident, the CCPA gives you the right to know what personal information we collect and to request its deletion — both of which the Account page above already gives you directly, since our collection is deliberately narrow enough that there's nothing extra to disclose. We do not sell personal information, so there is no opt-out to exercise. For any of the above, or any other jurisdiction's data rights, email us at admin@getzeroparse.com and we'll assist directly.

9. Data retention

We keep your account data for as long as your account exists. PDF file contents are never retained at all — there is nothing to expire. Processing metadata (file type, page count, timestamp) and your credit history are kept until you delete your account, at which point they are permanently deleted along with everything else tied to your account. Failed sign-in records are deleted automatically after 24 hours, whether or not you have an account with us.

10. Security

All traffic is encrypted in transit (TLS). Database access is protected by row-level security so your account data is only ever readable by you. Administrative operations (billing, account deletion) use a separate, tightly-scoped service credential that is never exposed to the browser.

11. Enterprise & business use

If you're a CPA, bookkeeping firm, or other organization using ZeroParse Statements to process statements on behalf of clients or third parties, our Data Processing Addendum sets out the roles, security commitments, and subprocessor list relevant to that use. You can also request it directly by emailing admin@getzeroparse.com.

12. Children's privacy

ZeroParse Statements is not directed at children under 16, and we don't knowingly collect data from them.

13. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above.

14. Contact

Wedgr Technologies (UEN 53532707B), which operates ZeroParse Statements, is responsible for the personal data described in this policy. Questions about this policy: admin@getzeroparse.com