Last updated 8/2/2026
We use the following third-party services ("subprocessors") to provide StatementOrganizer. Each processes personal data only under a data-processing agreement, only on our instructions, and only for the purpose listed.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage, serverless functions | All account and statement data | US (us-east-2) |
| Cloudflare R2 | Encrypted off-site backups of the database | Encrypted database snapshots | US / global edge |
| GitHub Actions | Runs the scheduled backup job | Database snapshot in transit during the job | US |
| GoDaddy | Web hosting for the public site | No account data at rest | US |
Statement text is sent to an AI provider to extract transactions and produce insights. We only use providers whose API terms state that inputs are not used to train their models and are subject to limited or zero retention.
| Provider | Purpose | Data |
|---|---|---|
| Google Cloud (Vertex AI / Gemini) | Statement extraction, OCR, chat, insights and reports | Statement text with card numbers masked; document images where OCR is needed |
| Anthropic | Approved alternate provider for the same features | As above |
| OpenAI | Approved alternate provider for the same features | As above |
Card numbers are masked before any statement text is stored or sent. You can add your own masking rules under Settings → Privacy, use your own AI provider key, or run extraction entirely on your device in the mobile app — in which case no statement content is sent to any AI provider at all.
If you supply your own API key, your chosen provider is your own subprocessor and their terms apply, not ours.
| Provider | Purpose | Data |
|---|---|---|
| Resend | Transactional email (sign-in, receipts, alerts, data exports) | Email address and message content |
| Expo (push relay) | Delivers mobile push notifications | Device push token, notification title and body |
| Google Firebase Cloud Messaging | Android push transport behind Expo | Device push token, notification payload |
| Stripe | Card payments | Email, amount, order reference. Card details go directly to Stripe; we never see them |
| Razorpay | Payments (India) | As above |
| PayPal | Payments | As above |
| Provider | Purpose | Data |
|---|---|---|
| Google Analytics 4 | Aggregate usage statistics — only loaded if you accept analytics cookies | Page paths, approximate location, device type |
Our own visit counter is first-party, uses no cookies, and stores no IP address — see the Cookie Policy.
We will update this page before adding a new subprocessor that handles personal data. Questions or objections: privacy@statementorganizer.com.
We use necessary cookies to run the app. With your consent we also use analytics to improve it. See our Cookie Policy and Privacy Policy. You can change this any time in Settings → Privacy.