Skip to content
Tennanova

Security and privacy

Built around temporary processing and reviewable results

Bank statements are sensitive. Tennanova limits how long source files and extracted results exist, restricts result access to the verified account owner, and keeps financial data out of analytics and advertising events.

Core controls

These controls describe the current production design. No internet service can promise absolute security, so Tennanova also keeps the processing window narrow and asks you to review and download results promptly.

Immediate source deletion

The private source PDF is deleted immediately after OCR completes.

Two-hour result window

Successful extracted results automatically become inaccessible after two hours.

Encrypted temporary data

Sensitive job payloads use AES-256-GCM encryption while stored in Cloudflare D1.

Owner-checked access

Result and edit endpoints verify the signed-in Clerk account that created the job.

HTTPS in transit

Production traffic is protected in transit with HTTPS and TLS.

Financial data excluded

Statement and transaction data are excluded from product analytics and advertising events.

Data lifecycle

What happens to a statement

  1. 1. Private upload

    The PDF is streamed into private Cloudflare R2 storage after account and security checks.

  2. 2. OCR processing

    The document is sent to the OCR provider inline or through a short-lived signed URL for larger supported files.

  3. 3. Source deletion

    Tennanova deletes the R2 object immediately after OCR. Scheduled cleanup and storage lifecycle rules act as backstops.

  4. 4. Temporary result

    The normalized extraction is encrypted in D1 and can be accessed only by the account owner through authorized endpoints.

  5. 5. Automatic expiry

    The result becomes inaccessible two hours after successful processing and is then physically removed.

Service providers and data boundaries

Tennanova uses specialist providers for authentication, hosting, OCR, billing, product analytics, and advertising measurement. Each receives information relevant to its role. The privacy policy contains the complete processing and location disclosures.

PurposeProviderBoundary
AuthenticationClerkAccount identity and verified sign-in
Hosting and temporary storageCloudflareSite delivery, private PDF storage, encrypted temporary results
Document readingZhipu AI and Z.aiStatement content required to perform the conversion
BillingStripeCheckout and subscription management, not full card details to Tennanova
MeasurementPostHog and RedditAllow-listed product events and advertising events, excluding statement data

Read the full privacy policy for processing locations, retention details, analytics, advertising, and contact options.

Answers

Security questions

How long does Tennanova keep my PDF bank statement?

The source PDF is stored privately only while OCR is performed and is deleted immediately after that step. A 15-minute cleanup and a one-day storage lifecycle rule provide additional backstops.

How long is the extracted result available?

A successful result becomes inaccessible two hours after processing and is then physically removed. Download the CSV or Excel file before the temporary result expires.

Can someone access a result with only its job ID?

No. Result and edit requests verify the signed-in Clerk account owner. A random job identifier does not grant access by itself.

Does advertising tracking receive my financial data?

No. Statement contents, filenames, balances, account identifiers, transaction descriptions, and transaction values are excluded from product analytics and the Reddit Pixel. The pixel measures page visits and selected conversion events.