Privacy policy
Effective: September 2026
The short version
Your file is processed in temporary storage and permanently deleted within 10 minutes. We never read, store, or share the transaction data in your file.
What we do with uploaded files
When you convert a bank statement, the file is written to ephemeral temporary storage, converted, and the input and output are permanently deleted within a hard 10-minute window — whether or not you download the result. A parsed copy is held in server memory for up to 5 minutes only so you can switch export formats without re-uploading. Nothing is ever written to a database or retained longer.
We cannot recover a file after that window, and we cannot see transaction data from completed conversions. This is a deliberate design decision, not a promise we hope to keep.
What we do collect
- Usage metadata — that a conversion happened, which formats and template were used, file size, whether it succeeded. This powers rate limits, billing and service monitoring. It never includes file contents.
- A hashed IP address for anonymous free-tier rate limiting. The IP itself is never stored raw — only a one-way hash — and entries are pruned automatically.
- Account data (email, plan, saved preferences) if you create an account. We use a transactional email provider for account and billing mail only.
We do not use advertising trackers, and we do not sell data. We measure site visits with Google Analytics (anonymized IPs), and Google Analytics only loads if you accept the analytics notice shown on your first visit — declining loads nothing and sends nothing. You can clear that choice any time by deleting site data. Analytics never includes file contents or transaction data.
Reporting problems
When you report a problem through the converter or the contact form, we receive the description you type plus technical metadata about the conversion (formats, counts, which checks failed) — never your file's contents. If you choose to attach the file so we can reproduce the issue, that attachment is stored securely, is only accessible to the operator, and is permanently deleted as soon as the report is resolved — and at the latest after 30 days. Ordinary conversions are never retained in any form; this opt-in attachment is separate and explicit.
Legal footing
MT2CAMT is operated by the sole developer of MT2CAMT, processing personal data under the EU General Data Protection Regulation (GDPR). Because file contents are transient by design, our data-processing footprint is deliberately small. If you are an accounting firm and need a data processing agreement (DPA) for processing client data through the service, email hello@mt2camt.com and we will provide one.
You can request access to or deletion of any account data at any time by emailing hello@mt2camt.com.