Security & privacy
Last updated: July 9, 2026
You’re uploading bank statements, so you deserve to know exactly what happens to them. Every statement below reflects how the system actually works — not marketing.
Encrypted in transit and at rest
Everything you upload travels to our servers over TLS 1.2+ encryption, and the whole site is served over HTTPS. Your statements and reports are stored encrypted at rest (AES-256), and we apply an additional layer of application-level encryption so that a raw copy of our database or file storage is ciphertext on its own.
Stored privately — and only for you
When you underwrite a business, we save that deal — the statements and the resulting report — to your account, so you can reopen it, unlock it later, and keep a history. Access is locked to your account by row-level security; there is no admin browser for customer statements in the product, and you can delete any deal (and its stored files) permanently at any time.
To be precise about what “private” means here: to read a statement, our server necessarily processes it in plaintext, and our AI provider transcribes it (below). So this is “encrypted and private to your account,” not “mathematically impossible for us to access.” We don’t view, sell, or share your statements or reports; access is limited to operating the service for you.
How the reading is done (and what our AI provider can see)
To transcribe the numbers, your statement is sent to Google’s Gemini API on our paid, billing-enabled plan. Under Google’s paid API terms, your data is not used to train or improve Google’s models. For security and abuse monitoring, Google may retain a request for a short period (up to 55 days by default) and then deletes it; that logged data is not used for model training. We do not opt into any data-sharing program.
Only you see your reads
Your deals, reports, and history are visible only to your account, enforced by per-user access controls (row-level security in our database) and served only to you.
The AI reads; verified code decides
The model only transcribes the numbers off the page. All arithmetic, classification, and the high / needs-review verdict are computed by deterministic code that reconciles every figure against the bank’s own printed running balance (or printed summary totals). If a number can’t be reconciled it’s flagged for review — never served as a confident wrong answer.
We don’t sell your data
We do not sell or rent your personal information or the data in your statements, and we don’t use it for advertising. See our Privacy Policy.
Service providers (subprocessors)
We use a small set of trusted providers, each bound to use data only to provide their service to us:
| Provider | Purpose | Data |
|---|---|---|
| Google (Gemini API) | Reads (transcribes) uploaded statements | The uploaded document, transiently; not used to train models |
| Supabase | Database, authentication & file storage | Your account, your stored statements & reports (encrypted at rest) |
| Stripe | Payments & billing | Billing details (we never see your full card number) |
| Vercel | Application hosting | Standard request/traffic data |
Questions
Security or privacy questions? Email support@mcaunderwriting.com. This tool is an assist-only pre-read — see our disclaimer.