(Security) Last updated October 2026
Statements stay
on your device.
DepositDesk reads bank statements inside your browser. The PDFs, the deposits and the income figure are never sent to us, because there is no server on our side that receives them.
(01) Processing
Everything happens in your browser.
When you drop a statement in, your browser opens the PDF with pdf.js, reads the text, finds the deposit lines and does the math. All of it runs on your computer. The statement file is never transmitted anywhere.
The code that reads statements, pdf.js and our parser, is served from trydepositdesk.com itself, not from a third-party script host.
(02) Uploads
Nothing is uploaded. Nothing is stored on a server.
- No borrower file, deposit, name or income figure is sent to DepositDesk or anyone else.
- We have no database of your files and no account system that holds borrower data.
- We don't run ad trackers, tracking pixels or session recording on the tool. Cloudflare Web Analytics counts page views and load times without cookies; it never sees statement contents.
(03) Scans
Scanned statements: OCR, still on your device.
If a PDF has no text layer (a scan or a phone photo), DepositDesk loads the open-source Tesseract OCR engine into your browser and reads the page there. Your browser downloads the engine and its English language file from public CDNs; the statement image itself never leaves your device.
(04) On your device
What is kept on this device, and why.
- The open worksheet, in this tab's session storage, so a reload doesn't lose your work. It is erased when you close the tab or press New file.
- Saved files (Founding Broker), in your browser's IndexedDB, only when you press Save file: borrower or file name, months, deposits, exclusions and settings.
- Your "Prepared by" name, if you type one, so it is filled in next time.
- Plan status: a flag saying whether this browser has used its free file or has Founding Broker access. It contains no personal information.
Anything stored this way lives in your browser profile only. We can't see it, back it up or restore it, and it doesn't sync between devices.
(05) Clearing
How to clear it.
- New file clears the open worksheet.
- Clear all local data, here or under Saved files in the tool, deletes every saved file, the open worksheet and your preparer name. Plan status stays so you keep access.
- To remove everything, including plan status, clear site data for trydepositdesk.com in your browser settings.
(06) Third parties
What else your browser talks to.
- Cloudflare hosts the site and runs its cookieless Web Analytics. Like any web host it sees standard request data (such as IP address and pages requested), never statement contents.
- Google Fonts serves the typefaces.
- jsDelivr and the Tesseract project's language files, only when a scanned page needs OCR.
- Stripe handles checkout when you subscribe. Payment details go to Stripe, not to us.
(07) Compliance
GLBA-friendly by design.
Under the GLBA Safeguards Rule your firm is responsible for protecting borrowers' nonpublic personal information. DepositDesk is built so it never receives that information: statements are processed on the device you control, under your own device, browser and access policies.
To be plain about it: DepositDesk holds no SOC 2, ISO 27001 or other certification, and we don't claim any. Your own information security program still applies to the devices you use DepositDesk on. If your compliance team has questions, email [email protected].
(08) The figure
An estimate, not an underwriting decision.
DepositDesk produces an estimate for pre-qualification. The lender's underwriter determines final qualifying income, under that lender's guidelines, expense factors and exclusions.