Security
Effective 2 August 2026 · Version 2026-08-02
We never touch your bank
StatementClear works entirely from statements you already have. We never ask for your online banking credentials and never connect to your bank account. Feed lines reach Xero through Xero's official Bank Feeds API over an OAuth connection you authorise inside Xero - we never see or store your Xero password, and you can revoke the connection from Xero at any time.
Hosting and infrastructure
StatementClear runs on established cloud infrastructure providers that maintain their own physical and network security programmes. Our data and backend services are hosted with Supabase, and the web application is delivered through Vercel.
Encryption
Data is encrypted in transit using TLS. Stored data, including uploaded statements, is held by our infrastructure providers with encryption at rest.
Access control and tenant isolation
- Each customer's data is isolated per account and enforced at the database level with row-level security.
- Our team operates on least-privilege access.
- Connections to Xero use authorised OAuth tokens scoped to bank feeds; we request only the scopes the Service needs.
AI processing
Statement extraction uses an AI provider under business terms that do not permit your content to be used to train general-purpose models. Statements are sent for the purpose of extraction only.
Data retention and deletion
We retain data only as long as needed to provide the Service and meet legal obligations. You can ask us to delete uploaded statements at any time, and they are deleted within 30 days of the end of the relevant subscription. See the Privacy Policy for detail.
Availability
StatementClear is currently in beta and we do not yet offer a formal availability commitment. We monitor the Service and treat feed delivery issues as our highest-priority incidents.
Incident response
We monitor for issues and maintain a process to investigate and respond to security incidents. In the event of a personal data breach, we notify affected customers without undue delay and provide the information they need to meet their own obligations.
Reporting a vulnerability
If you believe you have found a security issue, please contact hello@statementclear.com. We welcome responsible disclosure and will work with you to confirm and resolve genuine issues.