Statement Analytics Logo

Privacy Notice

Effective date: 2026-01-15

1. Introduction

Statement Analytics, LLC ("Statement Analytics," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this Privacy Policy carefully. By using the Service, you consent to the collection and use of your information as described in this Privacy Policy.

2. Information We Collect

2.1. Account Information

When you create an account, we collect: name, email address, password (encrypted), and billing information for paid subscriptions.

2.2. Financial Data Collection via Plaid

When you choose to connect your financial accounts through the Service ("Linked Financial Account"), Statement Analytics uses Plaid Inc. ("Plaid") to facilitate secure access to your Linked Financial Account. Plaid collects and processes your data from your Linked Financial Account under the Plaid End User Privacy Policy.

Pursuant to your authorization, we receive data and information from Plaid, which may include: account balances, transaction history, account holdings, and fee information. Statement Analytics uses this information solely to provide the Service, including generating analytical reports.

Statement Analytics does not access, receive, or store your financial institution login credentials. Your credentials are entered directly into Plaid’s secure interface and are handled by Plaid.

2.3. Document Upload Data

When you upload financial statements, we collect and process the data contained in those documents, which may include: account numbers (partially masked in our systems), account balances, transaction history, holdings information, fee information, and performance data.

2.4. Payment Information via Stripe

Statement Analytics uses Stripe to process payments and manage subscriptions. When you provide payment information, it is transmitted directly to Stripe’s secure servers and processed under Stripe’s privacy and security practices.

We do not store your full credit card number. We may receive limited payment-related information from Stripe such as the last four digits of your card, card type, expiration date, and billing address to display payment information in your account and process refunds where applicable.

2.5. Automatically Collected Information

We automatically collect: IP address, browser type and version, device information, operating system, pages visited and time spent, referring URLs, and cookies and similar tracking technologies.

3. How We Use Your Information

We use the information we collect to:

(a) Provide and maintain the Service, including calculating your investment performance

(b) Process your transactions and manage your subscription

(c) Send you service-related communications (account confirmations, analysis results, technical notices)

(d) Send you renewal reminder emails at least 15 days before your subscription renews

(e) Respond to your comments, questions, and customer service requests

(f) Improve and optimize the Service

(g) Monitor and analyze usage patterns and trends

(h) Detect, prevent, and address technical issues and security threats

(i) Comply with legal obligations

4. Use of Data for Service Improvement

Statement Analytics uses artificial intelligence and automated processing technologies to analyze data and documents you upload to provide the Service. We may also use aggregated and de-identified data derived from such uploads and Service usage to improve, develop, and enhance our analytics, models, and data-extraction capabilities.

By uploading documents to the Service, you grant Statement Analytics a non-exclusive, worldwide, perpetual, irrevocable, royalty-free license to use your content in an anonymized and aggregated form to improve the Service, train machine learning models, and enhance data extraction algorithms. Anonymized and aggregated data does not identify you personally, is not used to re-identify individual users, and does not create additional privacy obligations.

5. Information We Do NOT Collect or Use

Consistent with our conflict-free commitment, we do NOT:

(a) Sell your personal information or investment data to third parties

(b) Share your data with financial advisors, brokers, or investment product providers

(c) Use your data to market financial products or services to you

(d) Provide your data to data brokers or advertising networks

(e) Use your investment data for any purpose other than providing you with performance analysis

(f) Access or store your financial institution login credentials

(g) Store your full credit card number

6. Disclosure of Your Information

We may share your information only in the following limited circumstances:

Service Providers: We share data with third-party service providers who perform services on our behalf, including: Plaid (account aggregation), Stripe (payment processing), cloud hosting providers (data storage), and analytics providers (aggregated, anonymized usage data only).

Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).

Business Transfers: If Statement Analytics is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

With Your Consent: We may share your information with third parties when you have given us explicit consent to do so.

7. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

(a) 256-bit encryption for data transmission (SSL/TLS)

(b) Encryption of sensitive data at rest

(c) OAuth authentication for account aggregation (no credential storage)

(d) Regular security assessments and monitoring

(e) Access controls limiting employee access to personal data

(f) SOC 2 Type 2 compliance (planned within 12 months of launch)

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you the Service. We will retain and use your information as necessary to:

(a) Comply with our legal obligations

(b) Resolve disputes

(c) Enforce our agreements

Uploaded statement files are processed and then deleted from our servers within 30 days. Calculated performance data and reports are retained for the duration of your subscription plus 90 days.

You may request deletion of your account and all associated data at any time by contacting us at privacy@statementanalytics.com.

9. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

(a) Access: Request a copy of the personal information we hold about you

(b) Correction: Request correction of inaccurate personal information

(c) Deletion: Request deletion of your personal information

(d) Portability: Request a copy of your data in a portable format

(e) Opt-Out: Opt out of certain data processing activities

To exercise these rights, please contact us at privacy@statementanalytics.com. We will respond to your request within 30 days.

10. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.

11. Cookie Policy

11.1. What Are Cookies

Cookies are small text files stored on your device when you visit a website. They help the website remember your preferences and understand how you use the site.

11.2. How We Use Cookies

Essential Cookies (Required): These cookies are necessary for the Service to function properly. They enable core functionality such as user authentication, account security, and session management. You cannot opt out of essential cookies.

Analytics Cookies (Optional): We use analytics cookies (such as Google Analytics) to understand how visitors interact with the Service. This helps us improve the Service. Analytics data is aggregated and does not identify individual users. You may opt out of analytics cookies.

Preference Cookies (Optional): These cookies remember your preferences and settings to enhance your experience (e.g., language preferences, display settings).

11.3. Cookies We Do NOT Use

Consistent with our conflict-free commitment, we do NOT use:

(a) Advertising or targeting cookies

(b) Third-party tracking cookies from advertising networks

(c) Cookies that share your data with financial product marketers

(d) Cross-site tracking cookies

11.4. Managing Cookies

Most web browsers allow you to control cookies through their settings. You can typically find these settings in your browser’s "Options" or "Preferences" menu. You can:

(a) Block all cookies

(b) Accept only first-party cookies

(c) Delete cookies when you close your browser

(d) Be notified when a cookie is set

Please note that blocking essential cookies may prevent you from using certain features of the Service.

12. California Consumer Privacy Rights (CCPA)

12.1. CCPA Disclosure

If you are a California resident, you have rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), including the right to:

(1) Know the categories and specific pieces of personal information we collect, and how we use and disclose it;

(2) Request deletion of your personal information, subject to exceptions under the law;

(3) Opt-out of the sale or sharing of your personal information, if applicable; and

(4) Not be discriminated against for exercising these rights.

12.2. Sale of Personal Information

Statement Analytics does not sell your personal information.

We have not sold personal information in the preceding 12 months and have no plans to sell personal information. Our business model is based entirely on subscription fees paid directly by users, not on monetizing user data.

12.3. Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information:

Identifiers: Name, email address, IP address, account credentials. Source: Directly from you. Purpose: Account creation, authentication, communications.

Financial Information: Account numbers, account balances, transaction history, holdings, fee information. Source: Uploaded statements and Plaid account aggregation. Purpose: Providing investment performance analysis.

Internet Activity: Browsing history on our Service, interactions with our Service. Source: Automatically collected. Purpose: Service improvement and security.

12.4. How to Exercise Your Rights

To exercise your California privacy rights, you may:

(a) Email us at privacy@statementanalytics.com

(b) Submit a request through our website at www.statementanalytics.com/privacy

(c) Use the "Do Not Sell or Share My Personal Information" link in our website footer

We will verify your identity before processing your request. We will respond to verifiable requests within 45 days.

12.5. Authorized Agents

You may designate an authorized agent to make requests on your behalf. Authorized agents must provide proof of authorization (such as a power of attorney or signed written permission).

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top. You are advised to review this Privacy Policy periodically for any changes.

14. Contact Information

Statement Analytics, LLC
Dallas, TX
Website: www.statementanalytics.com
Privacy and Data Requests: privacy@statementanalytics.com
General Inquiries: info@statementanalytics.com
Customer Support: support@statementanalytics.com

Response Times: General Privacy Requests: 30 days | CCPA Requests: 45 days