Statements to Ledger

Security & data handling

A plain-language overview of what is uploaded, where processing happens, how long ledger data is retained, and the controls available to you.

What you upload and where it is processed

You upload bank statement PDF files and provide a batch name. PDFDrill stores statement files and extracted ledger data in private backend storage for processing and to make the reviewed ledger available to you. Uploaded source files are not placed at public URLs.

To extract statement information, document text and, for scanned statements, page images are sent to OpenAI's Chat Completions API. OpenAI does not use API data to train its models and may retain it for up to 30 days for abuse monitoring unless longer retention is required by law.

Files and ledger data are stored privately and deleted automatically according to the retention periods below. Storage may use the local filesystem or private object storage; encryption at rest has not been independently verified.

Retention periods

  • Source statement PDFs: automatically deleted 7 days after batch creation.
  • Extracted ledger data: retained for 30 days after batch creation.
  • Source page access: provided through authenticated, short-lived links that expire after 300 seconds.

Your deletion controls

From your account, delete an individual batch before its automatic expiration. Deleting a batch removes its source files and associated ledger rows. Ledger data is also included in the account deletion flow.

Automatic retention is not a substitute for deleting a batch when you no longer need it.

Access and file links

Source PDFs are stored privately, not exposed through public file URLs. Source pages are available only through authenticated, short-lived links. Keep account credentials and API keys confidential.

For API integration details, see the developer API documentation.

Questions about handling your statements? Contact PDFDrill.