Your source remains private; extraction has named boundaries.
Effective September 20, 2026 ยท Version 2026-09-20-v3. Fulla documents where statement content is stored, which provider routes can process rendered pages, and when financial content expires.
Storage and deletion
PDFs use private encrypted object storage. Uploaded and derived financial content expires 24 hours after presign. Source and export access is authorized and proxied through the application, so Fulla Ledger does not issue public object URLs and object locations are not exposed to the browser. Static site assets and images are delivered through a content delivery network.
Subprocessors
Fulla Ledger uses a small, named set of processors:
- Amazon Web Services โ private S3 object storage for uploaded and derived files, SES for transactional email, and CloudFront for static asset delivery.
- Stripe โ payment processing, subscriptions, invoices, promotion codes, and refunds. Card data is entered with Stripe; Fulla Ledger stores only customer, subscription, invoice, and purchase references.
- OpenRouter and its routed model endpoints โ vision extraction of application-rendered page images, pinned to the evaluated policy described below. Page images leave Fulla Ledger only for these routes.
Each processor handles only the categories above and is named here rather than described in general terms.
Vision providers
Application-rendered page images are sent through OpenRouter only to a model and provider endpoint pinned by the active evaluated policy. Eligible routes are GLM through DeepInfra ZDR, Mistral through Mistral ZDR, and Gemini Flash through Google Vertex. The selected Gemini route uses a current no-retention policy and data collection denial, but it is not formal OpenRouter ZDR. PDF text can be supplemental evidence.
Identifiers
Account, card, routing, ABA, and IBAN-like values are reduced or masked before scoring, persistence, review events, exports, support diagnostics, and telemetry. Unsafe output is rejected in process memory.
Accounts, credits, and billing
Identity, workspace membership, consent, page ledger, subscription projection, credit products, credit purchases, credit grants, lot balances, lot expiration, discount references and redemption records, API-key hash and prefix, and deletion state persist as needed to operate and account for the service. A credit lot expires no later than 365 days after issue, while its purchase, grant, redemption, and expiration records may remain in the billing and audit history. API key secrets are shown once and stored only by hash.
Transactional email
Fulla Ledger sends account email to your account address only: address verification, password reset, workspace invitations, conversion-ready notices, allowance or quota notices, billing failures, credit purchase receipts, and support acknowledgements. These messages are transactional rather than marketing, do not include statement content, and are delivered through Amazon SES. The service records a recipient hash and delivery status so messages are neither lost nor duplicated.
Support consent
Support may access only one currently owned document selected on a ticket, after explicit versioned consent and before the document expires. Operator access is audited. Revocation or cleanup clears the link.
Administration and audit
Authorized operators can view account, workspace, billing, credit, discount, support, export, conversion-cost, and deletion records in a separate private dashboard. Operator grants, credit changes, discount changes, subscription controls, workspace access changes, and consent-bound source access are audited.
Content can be forwarded to the named extraction providers above. Fulla does not claim otherwise.