Privacy

Your transaction file stays in this browser.

The core tools use the browser File API, in-memory parsers, and local Blob downloads. They do not need a server copy of your bank data.

Updated August 3, 2026 · Analytics requires an explicit choice.

Operator and data controller

BankFileKit is operated and maintained by 深圳织流科技有限公司, which is the data controller for the limited website analytics and support information described on this page.

What we process locally

File contents, filenames, transaction rows, dates, descriptions, amounts, mappings, account details entered for a beta export, and generated files remain in browser memory. Replacing the file, refreshing, or closing the page removes those in-memory values; BankFileKit does not create a server copy.

Optional analytics

Analytics is off until you accept it. If you accept, BankFileKit uses Google Analytics 4 and Vercel Web Analytics to understand page use and the local conversion funnel. You can reject analytics without losing any product feature and can change the choice through “Analytics settings” in the footer.

What analytics may receive

Google Analytics receives a canonical page path without query parameters, the static page title, and allow-listed product events. Product-event fields are limited to the event name, tool name, input and output format, coarse file-size bucket, coarse processing-time bucket, source-page category, result status, validation-reason category, and generic error category. Vercel receives its standard aggregate page data and the same allow-listed product events.

What analytics never receives

Analytics events do not include filenames, file contents, file hashes, bank names, account or card numbers, names, email or postal addresses, transaction dates, descriptions, merchants, notes, balances, or amounts. Raw parser errors and file-derived stack details are not sent.

Cookies, storage, and service details

Google Analytics may set first-party analytics cookies only after acceptance. BankFileKit stores the analytics choice in local browser storage; clearing site data removes that choice. Google Signals, ads personalization, user-provided data collection, User ID, and automatic Enhanced Measurement are not enabled. Vercel Web Analytics is cookie-free, its anonymous visitor hash resets daily, and the current Hobby reporting window is one month.

Retention and third parties

Google Analytics is provided by Google and Vercel Web Analytics is provided by Vercel. The GA4 property is currently configured to retain event-level and user-level data for 14 months for trend analysis; Google explains that most standard aggregate reports are not controlled by that setting. We do not send files to either provider. You can use the footer setting to reject future analytics and clear analytics cookies from this browser.

Error monitoring and AI services

No third-party error-monitoring or AI service is currently enabled for these tools. File contents are not sent to an AI provider, and parser failures are reduced to generic allow-listed categories before an analytics event can be sent.

When you contact us

If you email support, we receive the address and message you choose to send. Do not attach financial files or include transaction, account, balance, login, or identity data.

What not to enter

Do not enter a full bank account number. The beta QBO form only asks for an optional routing number and last four digits for the downloaded test file.

Important boundary

This is a file utility, not an accounting service. Check every output and follow your accounting software provider's backup and security guidance. See the conversion methodology for parser behavior.

Privacy contact

For privacy questions or data requests, email support@bankfilekit.com. Do not attach bank or transaction files.