Private host storage
Original documents and extracted results are stored in the application host’s private .data directory. They are not published as static assets or exposed through public document URLs.
YOUR DOCUMENTS DESERVE CLEAR ANSWERS
Bank statements are sensitive. Here is how this version of TallyClip handles them, from upload to deletion.
Original documents and extracted results are stored in the application host’s private .data directory. They are not published as static assets or exposed through public document URLs.
Document access and export requests are checked on the server against your workspace. A statement belongs to its workspace, and another workspace cannot retrieve it by guessing its ID.
PDF text extraction and OCR run on the application host. External AI is off by default. If the operator explicitly configures an AI provider, locally extracted statement text is sent to that provider for structured extraction. Original files are not sent to that provider.
Guest documents expire after 24 hours. Registered-account documents and their extracted results default to a 30-day retention window. The workspace shows each statement’s expiry.
You can delete a statement and its stored document data from the workspace. Expired documents are removed by the application cleanup process.
Stripe handles checkout and payment-method information when billing is configured. TallyClip uses the confirmed subscription status and does not store full card details.
THE IMPLEMENTATION BOUNDARY
This implementation runs on a single application host. Private storage and workspace access checks are part of the application; operational protections also depend on the host, filesystem permissions, deployment configuration, and the services the operator enables.
TallyClip has not completed an independent security audit or SOC 2 certification. This page describes the implemented handling rules. It does not claim certifications or infrastructure guarantees.
The upload panel identifies external AI processing when it is enabled. That provider receives statement text, and its own retention and processing terms apply. Local deletion does not control records retained by a configured provider.
When configured, Supabase handles account authentication and Stripe handles billing. Neither needs the content of your bank statements to perform those functions.
Read the privacy policyMAKE ROOM FOR THE REAL WORK
Your next statement is a good place to start.