Privacy
A converter that does not need your statement
Your financial files never leave your browser. That promise covers uploaded bytes, parsed transaction rows, mappings tied to row values, generated exports, and verification details.
What stays on your device
CSV, XLS, and XLSX content is read in a dedicated browser worker. Dates, amounts, descriptions, payees, references, worksheet content, normalized transactions, generated QBO/OFX/QIF/CSV bytes, and parse-back reports remain in memory on the current device. Refreshing or closing the page clears that in-memory state.
What our server receives
When you sign in or pay, our API receives an email address, opaque account and checkout identifiers, Paddle customer/order/subscription identifiers, entitlement periods, target format, and a random idempotency key. It does not receive a file name, file fingerprint, bank name inferred from a file, row count, transaction value, or generated output.
Payments
Paddle receives the information needed to run checkout, including your email, billing and payment details, tax location, and purchased product. Rows to Books does not receive your complete card number.
Browser-local Pro mappings
When you explicitly save a mapping, normalized header names and their roles are stored in this browser’s local storage. You can clear them from Account. No transaction values or file names are included.
Limits
We can control our application and server boundary. We cannot protect data on a device compromised by malware, a hostile browser extension, or a modified browser. Review your device and extensions before handling sensitive financial records.