How we protect your data
Plain-language answers to the security and privacy questions we hear most.
This page is maintained by SortFi to describe how we handle your data. It is not an independent certification or audit. For the formal privacy notice, see the Privacy Policy.
What happens to your statement, step by step
- You upload a CSV, Excel, PDF, or a photo of a statement.
- SortFi reads the file to pull out the individual transactions. CSV and Excel files are parsed directly in your browser and never leave your device as a file. PDFs and photos are sent to a private processing area just long enough to extract the transactions.
- AI suggests an expense category for each transaction. You can review, edit, or override every suggestion.
- Only the extracted transactions are saved to your account. The original statement file is not stored — PDFs and photos are deleted immediately after extraction.
Encryption
Your data is encrypted in transit using TLS (HTTPS) between your device and SortFi. Transactions, receipts, and account data are encrypted at rest in our managed database and storage.
Your data is isolated to your account
Every transaction, receipt, and setting is scoped to your account. Our database enforces this with row-level security policies, so one signed-in user cannot query another user's data. Storage buckets holding receipts are private — there are no public file URLs. When you view a receipt, SortFi generates a short-lived, signed link that only works while you're signed in.
You stay in control
SortFi never asks for your bank login or password, and we don't connect to your bank. You choose exactly which statements to upload. You can delete an import (and all of its extracted transactions) at any time from the Imports page, and you can delete individual receipts and transactions from within the app.
Where processing happens
Categorization is performed by a third-party AI provider, reached through the Lovable AI Gateway. Only the extracted transaction text — description, amount, and date — is sent for categorization. The original statement file is never sent to the AI provider. We do not currently guarantee that all processing stays within Canada; if you need specifics for a compliance review, contact us.
Canadian privacy (PIPEDA)
SortFi is built with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) in mind. That shapes how we approach consent, collecting only what we need, keeping your data safe, and honouring your right to access or delete your personal information. Our Privacy Policy is the formal notice of what we collect and how we use it, and you can reach us any time with a privacy request.
What we don't claim
SortFi is in beta. We do not currently hold SOC 2, ISO 27001, PCI DSS, or "bank-level security" certifications, and we don't describe ourselves that way. If that changes, we will update this page.
Reporting a security concern
If you believe you've found a security issue, please email hello@sortfi.app with the details and we'll get back to you.