Email import
Send a bank statement to your own secret address and the transactions wait for your approval. What the email must contain, how the account is suggested, security, limits and what is kept where.
Last updated: September 30, 2026
Email import ends in the same import as uploading a file; only the route is different. Instead of signing in to Assetli, you send your bank statement as an email attachment to your own address. Its transactions appear in the app, and nothing is written until you approve the import.
The feature is part of the paid Premium and Max plans. On the Free plan the page shows the plans instead of an address.
Where to find it and how to turn it on
The page is in the Bank accounts section, on the “Email import” tab. Settings → Bank import links to it as well.
Email import is off by default. Once you turn it on, you get your own secret address of the form i-<32 characters>@inbound.assetli.app. Do not share it. The “Generate a new one” button creates a different address and invalidates the old one immediately. Use it if you suspect the address has leaked.
Steps
- Download the statement from your online banking as CSV or XML (
camt.053). An OFX file also works. - Send it by email. Pick the account next to the Subject field. The “Write email” button opens your mail app with the address and subject filled in. If you write from another app, use “Copy subject”.
- Approve the import. The statement appears under “Waiting for approval” with a suggested account. Check the account and click “Import”, or “Discard” the statement.
What the email must contain
| Field | What goes in it |
|---|---|
| To | Your secret address |
| From | An allowed sender. The email of your Assetli account is allowed automatically; you can add more addresses under “Allowed senders”. |
| Subject | ”Statement – account name”. The account is suggested from the subject. |
| Attachment | CSV or XML. One email can carry up to 20 statements, and each is filed separately. Each attachment can be at most 10 MB. |
| Message body | Not read. Only when the message has no attachment at all do we try to find a statement pasted into the body. |
The Windows-1250 encoding used by some Central European banks for CSV is recognised automatically.
What we cannot do yet
- PDF. We cannot read PDF statements yet. Download CSV or XML from your bank.
- Automatic forwarding. Banks that email statements on their own mostly send them as PDF. Forwarding those statements is in preparation.
Which account is suggested
The account is only prefilled; you always confirm it. The suggestion is looked up in this order:
- an account number or IBAN in the file name,
- the account name in the file name,
- the account name in the subject (only when the message carries a single statement),
- the bank, recognised from the statement format, if you have only one account at that bank,
- the only account in your profile.
When two accounts have the same name, nothing is suggested and the page tells you so. We recommend renaming them; otherwise you choose the account when approving.
Approval and what happens on import
Nothing is imported on its own. Every statement waits in the approval queue, and batches that are not approved are deleted after 14 days.
A statement we could not understand shows up in red with the reason and can be discarded. In that case upload the file manually on the Bank accounts page, where you can assign the columns yourself (see Importing data).
An approved import takes the same path as an uploaded file: duplicate detection, pairing of transfers between your accounts and a balance recalculation. The same plan limits apply. An account synced with Wallet by BudgetBakers does not accept email import, for the same reason it does not accept CSV import: it would create duplicates.
Categorization after import
Your categorization rules always run after approval, free of charge. AI categorization of the rest runs only when the “Categorization after import” switch is on. It is the same setting as Settings → Bank import, and it uses your AI credit (see Plans and credits).
Security
An inbound address is a route into your data, so four layers protect it, one after another:
- Secret address. Until you turn import on, the address accepts nothing. You can replace it with a new one at any time.
- Allowed senders only. Mail from other addresses is not processed.
- Quarantine. A message from an unknown sender appears under “Waiting for your decision” with the buttons “It is mine” and “Not mine”. The quarantine holds at most 5 addresses.
- Approval. Nothing is imported until you click “Import”.
A forged email therefore never changes your data without your click.
Limits
- The address processes 10 messages a day from allowed senders.
- After 20 rejected messages in a day from unknown senders, the address turns itself off and the page tells you it has probably leaked. The “Generate a new address and turn on” button creates a new address and turns import back on.
- When the whole service receives an unusual amount of unsolicited mail, receiving pauses until the end of the day (UTC) and the page shows “Receiving is paused for today”. Send your statements the next day.
Privacy and retention
- The attachment is not stored anywhere. It is read in memory, and only the parsed transactions stay in the queue. They are removed from the queue right after import, and unapproved ones after 14 days.
- Mail is received by the provider Resend. It keeps a copy of the message, attachments included, for 30 days and does not allow earlier deletion. See Who processes your data and How long data is kept.
When nothing arrives
The step-by-step checklist is in Import: what to do when it fails.