Privacy

A converter that does not need your statement

Your financial files never leave your browser. That promise covers uploaded bytes, parsed transaction rows, mappings tied to row values, generated exports, and verification details.

What stays on your device

CSV, XLS, and XLSX content is read in a dedicated browser worker. Dates, amounts, descriptions, payees, references, worksheet content, normalized transactions, generated QBO/OFX/QIF/CSV bytes, and parse-back reports remain in memory on the current device. Refreshing or closing the page clears that in-memory state.

What our server receives

When you sign in or pay, our API receives an email address, opaque account and checkout identifiers, Paddle customer/order/subscription identifiers, entitlement periods, target format, and a random idempotency key. It does not receive a file name, file fingerprint, bank name inferred from a file, row count, transaction value, or generated output.

Payments

Paddle receives the information needed to run checkout, including your email, billing and payment details, tax location, and purchased product. Rows to Books does not receive your complete card number.

Browser-local Pro mappings

When you explicitly save a mapping, normalized header names and their roles are stored in this browser’s local storage. You can clear them from Account. No transaction values or file names are included.

Limits

We can control our application and server boundary. We cannot protect data on a device compromised by malware, a hostile browser extension, or a modified browser. Review your device and extensions before handling sensitive financial records.

Inspect the exact data flow and retention table