Privacy
Your bank statement never leaves your browser.
Tickvouch converts your file on your own device. The statement is not uploaded, not transmitted, not stored, and not seen by us. We could not read it if we wanted to.
Check it yourself. Two ways, both take a minute:
- Load this page, then turn off your wi-fi or unplug your network cable. Now convert a statement. It still works, because nothing needs to be sent.
- Open your browser's developer tools, choose the Network tab, and convert a statement. You will see no request carrying your file, because there is none.
What we do not collect. This site has no analytics and no trackers. There is no page-view counter, no session recorder, no advertising pixel, no cookie set by us, and no third-party script anywhere on this site. The build has a hard rule against third-party requests, so there is nothing to opt out of. If that ever changes, this page changes first, and it will name what was added and what it records.
One thing we will not claim: that nothing at all is recorded anywhere. Our host, Cloudflare, keeps standard server request logs, which include your IP address, in the ordinary course of serving you the page. That is true of every website. We do not read those logs for analytics and we keep no other record of your visit.
The waitlist. If you give us your email address for scanned-statement support, we store that address and the date you joined, and nothing else. No name, no IP address, nothing inferred about you. We use it only to tell you when that feature exists. We do not sell or share it. We have not sent a single message yet; when we do, every message will carry an unsubscribe link.
Where the waitlist lives, and how to leave it. Your address is stored in Cloudflare KV, on servers Cloudflare operates outside Singapore, under Cloudflare's own data-protection terms. We keep it until scanned-statement support ships or until you ask us to delete it, whichever comes first. To see what we hold about you, correct it, or have it deleted, write to [email protected] and we answer within two working days. Our basis for holding it is your consent, given when you submitted the form, and you can withdraw that consent at the same address. For any data-protection question, the contact is the owner of TICKVOUCH at [email protected].
Payment data. We never see your card. Payments are processed by Paddle.com as merchant of record, on Paddle's own pages — checkout is a link to paddle.com, and this site's pages still load nothing from any third party. Paddle collects the billing details it needs for payment and tax compliance under its own privacy policy.
When you buy credits, what we store is: the credit code itself, the pack you bought and its page total, the pages remaining, the issue date, the Paddle transaction id, and — if Paddle later refunds it — the refund status. We also store a keyed one-way fingerprint of the email you paid with, which lets the claim page find your code when you type that email; the fingerprint cannot be turned back into your address, and the address itself is never stored or logged by us. We do not store your email, name, address, or card. Paddle holds the purchase record. One honest consequence: we cannot email you your code, because we do not have your address — the claim page and your Paddle receipt are how you retrieve it.
What spending a credit sends. When a paid conversion completes with its reconciliation check, your browser sends us three things: your code, the page count, and a SHA-256 fingerprint of the file. The fingerprint is one-way — it cannot reconstruct the statement and does not tell us which bank it is from or what is in it. We store it against your code so the same file is never charged twice, on any device. The statement itself still never leaves your browser — paid or free. On your device, the code, your last known balance, and the fingerprints of files already charged sit in localStorage; "Forget this code on this device" removes them. The free converter still works with the network off — only credit spending needs a connection, and a conversion done offline is never charged, then or later.
Deleting a credit record. Write to [email protected] quoting the code or the Paddle transaction id, and we delete the code record and its fingerprint history within two working days. Said honestly: deleting the record also deletes any remaining balance on it.
No third-party requests on the converter page. The conversion page loads no external fonts, scripts, content delivery networks, or trackers. Everything it needs is served from this domain.
Questions: [email protected]