Privacy proof

See where every kind of data goes

Your financial files never leave your browser. The Financial file data sent: 0 B indicator is scoped to uploaded financial-file bytes and parsed transaction content—not to ordinary page, account, or payment requests.

1

Your browser

File bytes → parser → canonical rows → target generator → independent reader → comparison → download

Financial content remains here
2

Rows to Books API

Email identity, hashed session tokens, Paddle IDs, access period, export reservation status

No file endpoint exists
3

Paddle

Paddle receives payment information, billing email, tax location, and purchased product.

It does not receive your statement

Collected fields and purpose

DataWherePurposeRetention
Financial file and outputBrowser memoryConvert and verifyUntil refresh or tab close
Saved structural mappingBrowser local storageReuse Pro column rolesUntil you clear it
Email and local user IDRows to Books APIPasswordless identityWhile the account is needed; deletion by support request
Hashed magic/session tokenRows to Books APIAuthenticate without passwordsExpiry or revocation
Paddle transaction/subscription ID and periodRows to Books APIGrant, renew, refund, or revoke accessAccounting and dispute obligations
Target format and random reservation IDRows to Books APICount successful exportsEntitlement and audit period

How the boundary is enforced

Threat boundary

Rows to Books can guarantee its own application behavior and server boundary. It cannot protect a compromised device, malware, a hostile browser extension, screen-capture software, or a modified browser. A local-first design reduces server exposure; it does not make an unsafe device safe.