Your source remains private; extraction has named boundaries.
Fulla documents where statement content is stored, which provider routes can process rendered pages, and when financial content expires.
Storage and deletion
PDFs use private encrypted object storage. Uploaded and derived financial content expires 24 hours after presign. Source and export access is authorized and proxied; Fulla Ledger does not expose public object URLs.
Vision providers
Application-rendered page images are sent through OpenRouter only to a model and provider endpoint pinned by the active evaluated policy. Eligible routes are GLM through DeepInfra ZDR, Mistral through Mistral ZDR, and Gemini Flash through Google Vertex. The selected Gemini route uses a current no-retention policy and data collection denial, but it is not formal OpenRouter ZDR. PDF text can be supplemental evidence.
Identifiers
Account, card, routing, ABA, and IBAN-like values are reduced or masked before scoring, persistence, review events, exports, support diagnostics, and telemetry. Unsafe output is rejected in process memory.
Accounts, credits, and billing
Identity, workspace membership, consent, page ledger, subscription projection, credit products, credit purchases, credit grants, lot balances, lot expiration, discount references, API-key hash and prefix, and deletion state persist as needed to operate and account for the service. A credit lot expires no later than 365 days after issue, while its purchase, grant, redemption, and expiration records may remain in the billing and audit history. API key secrets are shown once and stored only by hash.
Support consent
Support may access only one currently owned document selected on a ticket, after explicit versioned consent and before the document expires. Operator access is audited. Revocation or cleanup clears the link.
Administration and audit
Authorized operators can view account, workspace, billing, credit, discount, support, export, conversion-cost, and deletion records in a separate private dashboard. Operator grants, credit changes, discount changes, subscription controls, workspace access changes, and consent-bound source access are audited.
Content can be forwarded to the named extraction providers above. Fulla does not claim otherwise.