Last updated 4 August 2026.
Firelog reads your bank statements inside your own browser. In normal use nothing you import is sent anywhere, because there is nowhere for it to go. The exceptions are two things you can choose to send us, and this page explains exactly what they are, how they are protected, and how long they last.
The short version.
Your statements stay on your device. There are no accounts, no cookies and no analytics. If Firelog cannot read a statement it will offer to send us that one file so we can add support for the format — that is a deliberate choice you make, file by file, and it is the only time statement data leaves your browser. Anything you do send is encrypted before it is stored, to a key our hosting provider does not have, and it is normally deleted from that provider within about five minutes.
Firelog is operated from Singapore by an individual, not yet an incorporated company. Under the Personal Data Protection Act 2012 (PDPA) that still makes it an organisation with obligations, and it must name a Data Protection Officer.
Statement PDFs you import are parsed in your browser by code that runs locally. The resulting transactions are written to your browser's private storage for this site (the Origin Private File System). We cannot read that storage, and it is not synchronised anywhere. Clearing your browser data for this site erases it.
Firelog also uses your browser's local storage for one narrow purpose: remembering how you arranged the diagram in the Flow view. That is layout preference, it stays on your device, and it contains no transaction data.
There are no cookies, no analytics, no advertising or tracking pixels, and no accounts. After the application has loaded, it makes no further network requests unless you explicitly ask it to share something.
Two features send data, and neither runs on its own. Each requires you to select the specific items and confirm a warning first.
When a PDF fails to parse, Firelog offers to send that file so the format can be supported. If you accept, we receive:
We ask for this because we cannot support a bank's format without seeing a real example of it. It is entirely optional, and Firelog works the same whether you send anything or not.
You can contribute the description text of transactions — the merchant lines — so that categorisation rules improve for everyone. No amounts, no dates, no balances and no account numbers are included, and digit sequences that look like account or card numbers are stripped both in your browser and again when we receive them.
Being straight about a limitation: that stripping removes numbers. A description such as “TRANSFER TO JOHN TAN” still contains a name, and we do not attempt to detect names. This is why these contributions are kept for a bounded period and reviewed, rather than retained indefinitely.
We rely on your consent, given by ticking the confirmation shown next to each share. You can withdraw consent at any time by emailing the DPO, and we will delete what we hold. Withdrawing consent does not affect anything already used to build a parser before you asked.
This is the part most privacy policies leave vague, so here it is precisely. Two different places are involved: our hosting provider, and the machine where the data is actually worked on.
| What | Where | How long |
|---|---|---|
| Anything you share | Cloudflare R2 (hosting provider) | About five minutes. An automated job collects it every five minutes and deletes it from the provider. It is encrypted the entire time it is there. |
| A shared statement PDF | Our working machine in Singapore | Until the format is supported or judged unsupportable, and in no case longer than 90 days from receipt. |
| Your email address | Our working machine in Singapore | Deleted when we have told you the format works, or with the statement, whichever comes first. It is never added to a mailing list. |
| Transaction descriptions | Our working machine in Singapore | The same 90 days, then deleted. |
When we build a parser from a statement you sent, we keep only an invented test file that imitates the layout — made-up names, made-up account numbers, made-up transactions. Your actual statement is deleted. This matters because it is what lets us keep testing the parser forever without keeping your document forever.
Deletion is performed by a scheduled job rather than by someone remembering to do it, and each deletion is logged.
Everything you share is encrypted before it is written down, using a one-off key per upload (P-256 ECDH with AES-256-GCM). The private key that can decrypt it exists only on our working machine and has never been uploaded to our hosting provider.
The practical consequence: if our website, our hosting account or the storage bucket were compromised, what an attacker would obtain is unreadable ciphertext and a list of timestamps. The stored file names contain nothing about you — not your name, not the document's name, not a checksum.
What this does not do, stated plainly: it does not protect the file while it is in transit beyond ordinary HTTPS, and it does not protect against someone compromising our working machine, which holds the key.
Cloudflare, Inc. hosts this site, the application and the temporary storage used when you share something. They act on our instructions as a data intermediary. The storage bucket is located in the Asia-Pacific region. Because what they hold is encrypted to a key they do not have, the protection travels with the data.
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it to build profiles of you.
Under the PDPA you may ask us to:
Email dpo@firelog.sg. We will respond within 30 days, and tell you in advance if we cannot. If you shared a statement without giving an email address, say roughly when you sent it and which bank it was from, so we can find it.
If a data breach occurs that is likely to cause you significant harm, we will notify the Personal Data Protection Commission and affected individuals as the PDPA requires. If you gave us an email address, that is how we will reach you.
If you are unhappy with how we have handled your data, please contact the DPO first — and if that does not resolve it, you may complain to the Personal Data Protection Commission.
If this notice changes materially we will update the date at the top and, where the change affects data already shared with us, contact anyone who gave us an email address. Firelog is in beta and its features are still moving; this page is updated when behaviour changes, not on a schedule.