The short version
- Your PDF file never leaves your browser. It is opened on your device.
- The text of each page is sent to our API (for scanned pages without text, a JPEG image of the page is sent instead) and read either by our own table reader or by AI models running on Cloudflare Workers AI.
- We don't store or log statement text, images or results. They exist in memory only for the seconds it takes to process them.
- We don't have accounts, emails or passwords. We keep page counters for quotas, keyed by hashed identifiers.
Step by step
1. In your browser
When you drop a PDF, it is read by pdf.js, an open-source PDF library that runs inside the page. If the PDF has a password, you type it into Footed and pdf.js uses it locally to decrypt the file; the password is not sent anywhere. Footed extracts each page's text with its positions and rebuilds the lines of the statement. The file itself is never uploaded.
Pages without a text layer (scans) can't be read as text, so Footed draws that page onto a canvas in your browser and converts it to a JPEG image (at most 1600 pixels wide). That image is what gets sent for those pages.
2. Sent to our API
The page text (or page image) is sent over HTTPS to our API at footed-api.hrishikesh.workers.dev, a Cloudflare Worker. Along with it go: the page numbers, the number of pages in the file, a few hints about the statement (period, currency, number format) taken from earlier pages, a random browser ID generated on your device, and your license key if you've entered one.
3. Read by our table reader or by Cloudflare Workers AI
First, the Worker runs Footed's own deterministic table reader on the text. If the statement's printed balances prove that reading correct, that result is used and no AI model sees the text at all. Otherwise the Worker sends the text to language models hosted by Cloudflare Workers AI (OpenAI's open-weight gpt-oss-120b, with Meta's Llama 3.3 70B as a fallback; scanned page images are transcribed by Mistral Small 3.1). The models run on Cloudflare's network; the text is not sent to OpenAI, Meta or Mistral. The structured result (statement details and transactions) is returned to your browser.
Cloudflare's Workers AI data usage page says, in its own words, that inputs and outputs are "Customer Content", and that:
"Cloudflare does not make your Customer Content available to any other Cloudflare customer."
"Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services, and would not do so unless we received your explicit consent."
"Your Customer Content for Workers AI may be stored by Cloudflare if you specifically use a storage service (e.g., R2, KV, DO, Vectorize, etc.) in conjunction with Workers AI."
Footed does not use any storage service with your statement content, and does not route requests through Cloudflare AI Gateway (which can log prompts).
4. What we keep
| What | Where | Why | How long |
|---|---|---|---|
| Statement PDF | Nowhere — never leaves your device | — | — |
| Page text, page images, extracted transactions | Worker memory during the request; your browser tab | To convert the statement | Discarded when the request ends; in your tab until you close it |
| Pages used per day/month | Our database (Cloudflare D1) | Quotas | Kept as counters |
| Your IP address | Only as a salted SHA-256 hash in the usage counter | Free-tier limits and abuse rate limiting | Daily counters; raw IPs are never stored by us |
| Browser ID | Random ID in your browser's localStorage; a hash of it in the usage counter | Free-tier limits | Until you clear site data |
| License key | Your browser's localStorage; a SHA-256 hash in our database | To unlock your plan and count usage | Hash and validation result cached up to 6 hours, counters kept |
Our Worker never writes statement text, images or results to logs. We have turned off Cloudflare's automatic per-request "invocation logs" for the API, so request headers (which include your IP address and license key) aren't recorded there either; the only log lines are our own, recording an endpoint name, a status code and an error code when something fails.
Other services involved
- Cloudflare hosts this website (Pages), the API (Workers), the AI models (Workers AI) and the usage database (D1). Like any network provider it processes connection data such as IP addresses to deliver requests. See Cloudflare's privacy policy.
- jsDelivr serves the pdf.js library and cdn.sheetjs.com serves the Excel export library to your browser. They see a normal request for a JavaScript file (your IP address and browser), never your statement.
- Gumroad processes payments and issues license keys. When you enter a key, our API asks Gumroad whether it is valid. Gumroad's handling of your purchase is described in Gumroad's privacy policy.
- Analytics: none at the moment. If we add privacy-friendly page-view analytics later, this page will say which.
Your choices
- Clearing this site's data in your browser removes the browser ID and the saved license key.
- Closing the tab discards your results — export first.
- If you'd rather nothing leave your device at all, don't use Footed for that statement. We would rather you know that than assume.