llab08

Privacy notice

StatementSync (easystatement) privacy

Applies to the StatementSync web app (repository name easystatement): a web app hosted on Vercel that turns bank statement files you upload into a list of transactions in your account. The app’s /privacy and /terms pages link here.

This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The section below explains this product’s data handling and current availability.

Extraction is unavailable. You can create an account and upload statement files, which are stored as described below, but as of the date below no statement is read: an uploaded file stays unprocessed. The queue paragraph describes processing when extraction is enabled. AI extraction remains disabled pending provider and data-processing arrangements.

The statement files you upload

You choose and upload bank statement files. Each file is written to a private storage bucket on our own Supabase server under your user id; the bucket is not public and per-user access controls keep one account’s files out of another account’s reach. Deleting a statement in the app removes both the record and the raw file from that bucket.

How a statement is read

Uploads are not parsed inside the web request. A job is placed on a queue and a separate worker process picks it up, downloads the file from the private bucket and extracts the transactions, then marks the statement processed or failed.

AI extraction (off today)

Extraction can be handed to a third-party AI model provider, but only when that is switched on for the deployment. It is switched off today: no statement file or its contents is sent to an AI provider by the extraction service.

When it is switched on, the worker sends each uploaded statement image (PNG or JPEG) to llab08’s own AI gateway at sub2api.llab08.com. The whole image is sent, including anything printed on it, such as your name, address, account number and transactions. The gateway runs on our server, and connections to it pass through Cloudflare. It passes the image to a third-party AI model provider, which returns the transactions it reads. PDF files are not sent this way and cannot be extracted on this route. Your e-mail address and account identifier are not sent to the gateway or the provider.

The AI model provider used through our gateway is Anthropic, with its Claude models. Another provider may be used later only after this section is updated. Anthropic processes the image under its own terms; we make no promise on its behalf about how long it keeps it or whether it uses it to train models. The extracted transactions are stored with your account as described below.

Account and results

You sign in through authentication on our own server; the transactions, categories and statement records produced from your files are stored with your account so you can reopen and export them. Write to the address below to have the account and everything in it removed.

Purchases

Paid plans are not on sale yet. When they are, they will be processed by Stripe: card details will be entered on Stripe’s checkout page and never reach us, and we will keep the Stripe customer and subscription identifiers and the plan status so that your plan can be shown in the app.

No ads

The app shows no advertising and ships no advertising SDK. If that ever changes, this section is updated first.

Hosting and retention

The web app runs on Vercel; storage, the database, the worker and authentication run on our own server. Hosts may keep short access logs; we do not use them to identify anyone. Statement files, transactions and subscription records stay with your account until you delete them or ask us to delete the account.

Contact: hello@llab08.com · Updated 25 September 2026 · All privacy notices