Trust

Security

Last updated: 13 July 2026

Cratebooks handles financial records, so the data flow should be understandable before you import anything. This page explains what reaches our systems and the controls currently in place.

The short version. Cratebooks does not require your bank login and cannot move money. Your original CSV or supported PDF statement is parsed in your browser and the file itself is never uploaded. The transaction rows it contains are sent to your account over HTTPS to be categorised, and you then decide which to keep, along with limited technical import diagnostics (parser version, page and row counts, error codes and a file fingerprint) so failed imports can be detected and fixed. Diagnostics never contain the file, its text, descriptions, dates, amounts or balances.

1. What happens when you import

  1. You choose a statement file on your device.
  2. The file is parsed in your browser. There is no statement-file upload endpoint.
  3. You preview supported PDF imports before confirming them.
  4. The transaction rows the file contains, including date, amount and statement description, are sent over HTTPS for categorisation and storage. This happens before you review them: categorisation is what produces the review queue. You then decide which rows count.
  5. Your reviewed records remain available in your account until you remove them or delete the account.

2. What Cratebooks stores

Bank statement descriptions can contain names or other personal information entered by a payer. Treat imported records as sensitive and protect access to your account.

3. Controls in place

4. Deletion and retention

You can delete your account from the app. Live account data, transactions and learned rules are removed through a cascading deletion. Residual copies in managed backups age out through the hosting provider's backup cycle. Limited billing or legal records may be retained where the law requires it.

5. Current limitations

6. Reporting a security issue

Please email security@cratebooks.com. We aim to acknowledge genuine reports within 48 hours. Do not access, alter or retain another person's data while testing.

7. More information

See the Privacy Policy for data-processing purposes, subprocessors and your rights. Security controls reduce risk but no online service can promise absolute security.