myfulus.

Privacy Policy

Effective August 7, 2026

What we collect

Your account basics (email, name, profile photo) from the sign-in provider you choose. The bank and card statements you upload, and the transactions, categories, and recurring charges our software derives from them. Your display currency and timezone. Your chat messages with the accountant. The address a sign-in request or an unsubscribe link came from, briefly, so neither can be hammered — it is stored as a counter, not a history, and swept away nightly. And if you arrived from one of our adverts, the click identifier and campaign tags that were in the link you followed, kept on your account so we can tell the advertising network that its click led to a sign-up — nothing about your money goes with it, and it is deleted with everything else. That’s the list.

How your statements are processed

Statements are parsed by an AI model via OpenRouter. We instruct the routing to use only providers that do not retain prompts or train on your data. Your files are stored on a private volume that is not reachable from the public internet, and your ledger lives in a Postgres database on the same infrastructure (Railway, hosted in the United States). Statement content is never used to train any AI model, by us or by our processors under our instructions.

If a statement PDF is password-protected, the password you enter is used once, on our server, to open the file. It is not stored, not written to any log, and not sent to the AI provider — only the statement’s text is.

What we never do

  • We never ask for, receive, or store your bank login.
  • Nobody at MyFulus reads your statements. Access happens only if you report a fault and ask us to look, and we tell you when we do.
  • We never sell your data — the subscription is the business model.
  • We never share your financial data with advertisers or data brokers. The only thing an advertising network ever hears from us is that one of its clicks became a sign-up.

Deletion — the real kind

The “Delete account & data” button (in your account area) permanently removes your account, every transaction, every uploaded statement file, briefings, and chats — immediately, with no retention window. Two things survive, and only these: a minimal log entry that a deletion happened, and — if you ever paid us — the invoice and payment records Stripe holds on our behalf, which tax and payment-dispute law requires us to keep. Those contain your billing details, never your statements or your transactions.

Cookies

Only cookies the sign-in itself needs — the one that keeps you signed in (7 days), plus two Auth.js sets to protect the sign-in form and remember where to return you. No advertising or analytics cookies.

Processors we rely on

Railway (hosting, database, and file storage), OpenRouter (AI processing under a no-retention instruction), Google (sign-in, if you choose it), Resend (transactional email, when enabled), and Stripe (payments — your card details go to Stripe directly and never touch our servers).

Your rights

Access, correction, export, and erasure — for everyone, not just where CCPA, Saudi PDPL, or UAE PDPL require it. Most of it is self-serve in the product; for anything else, email us and we will resolve it within 30 days.

Contact

Privacy questions: nascreative@gmail.com

12900 Brookfield Rd., Nokesville, VA, USA

MyFulus is financial-management software — not a licensed accountant, tax preparer, or financial advisor. See our Terms of Service.

HomeTermsالعربية