Privacy Policy

Last updated: April 2026

What we collect and why (APP 5 Collection Notice)

We only collect what we need to generate your report. Here is every data point we collect and its purpose:

DataPurposeRequired?
Full nameLabel your report, personalise emailsYes
Email addressDeliver your report and support emailsYes
Trade / industryImprove categorisation accuracy (e.g. Bunnings for a builder = business)Yes
Financial yearFilter and group transactions to the correct periodYes
Business structureAdjust categorisation rules (sole trader vs Pty Ltd)Yes
Bank statement data (transaction dates, descriptions, amounts)Parse and categorise your transactionsYes
Accountant emailCC your accountant on the report (if provided)No
Subcontractor namesIdentify subcontractor payments for TPAR totalsNo
NotesProvide additional context for categorisationNo
Receipt imagesExtract purchase details for expense matchingNo

What we don't collect

We never have access to your bank login, account numbers, BSB numbers, passwords, or credit card numbers. Bank CSV exports simply don't contain this information. For PDF statements, we strip headers and footers and only extract transaction rows — no account numbers, BSBs, or PINs are sent to any third party.

How we use your data

Your transaction data is used for one purpose only: to categorise your transactions and generate your report. Specifically:

Overseas processing (APP 8 Cross-border Disclosure)

Your transaction data is processed by Anthropic (United States) via their Claude API for categorisation. Anthropic does not use API data for model training. The following data is sent:

The following is never sent to Anthropic:

Data is processed and returned within seconds. See Anthropic's privacy terms at privacy.anthropic.com.

Support copies

When we send you your report, a copy is BCC'd to our support inbox (hello@sortmystatement.com.au) for customer support purposes. These copies are retained for up to 90 days and then deleted. If you'd prefer we don't keep a support copy, email us before uploading.

Data storage and deletion

Your uploaded files and generated reports are stored on Vercel's infrastructure (powered by AWS). All data is transmitted over SSL encryption.

Your uploaded bank statements are deleted from our servers after your report is generated. Your report is stored for 30 days then permanently deleted. No exceptions.

No accounts, no tracking

SortMyStatement does not require you to create an account, set a password, or log in. We do not use advertising cookies or tracking pixels. We do not run Google Analytics or Facebook Pixel.

Third parties

Your rights

Under the Australian Privacy Principles, you have the right to access and correct any personal information we hold about you. Since we delete your data within 30 days and don't maintain accounts, there is typically nothing to access. If you need anything deleted sooner, email us.

Contact

If you have questions about your data or want it deleted immediately, email us at hello@sortmystatement.com.au.