Protect / reference
Bank statement privacy and the 24-hour content lifetime
Statement sources, extracted rows, review events, and exports share one 24-hour deadline and stay behind authorized access.

At a glance
One deadline for the financial content
Illustrative schedule
- 09:00Upload begins
- 17:00Review the draft
- 18:00Approve and export
- 09:00 next dayContent access ends
Approval and export do not restart the clock. Source PDFs, extracted rows, review events and exports share the upload-based deadline.
Step by step.
Upload to private storage
Source files and downloads stay behind authorized proxy access instead of public object URLs.
Process through named routes
Rendered pages go only to routes allowed by the active evaluated provider policy.
Review within the same deadline
Rows, evidence, review events, and exports inherit the source content expiry.
Fence expired content
Access closes at expiry even when a failed storage deletion needs another attempt.
Private source and export access
Fulla uses private encrypted object storage. Source and export requests are authorized and proxied, so the service does not expose public object URLs for financial content.
Account and workspace records needed to operate the service can outlive the financial-content window. The Privacy notice lists those records separately.
Named extraction boundaries
Application-rendered page images go through OpenRouter only to the model and provider endpoint pinned by the active evaluated policy. The route in use is Mistral through Mistral ZDR, requested with formal OpenRouter zero data retention and data collection denied.
Expiry and support consent
Uploaded and derived financial content expires 24 hours after presign. A failed deletion remains fenced from access and is retried rather than silently extending access.
Support can inspect one currently owned document only after explicit versioned consent on a ticket and before expiry. Operator access is audited, and revocation clears the document link.
Questions about this guide
Does a failed delete extend access?
No. The content remains fenced from access while deletion is retried.
Are statement objects publicly addressable?
No. Source and export access is authorized and proxied rather than exposed through public object URLs.
Can support browse all workspace documents?
No. Consent applies to one selected, currently owned document on a ticket and ends at expiry or revocation.