Privacy Notice
This notice explains how FullWorth handles account information, connected financial data, bill statements, and operational information while providing the service.
1. Scope
This notice applies to FullWorth websites, applications, APIs, and beta services that link to it. Third-party services such as financial institutions, Plaid, email providers, hosting providers, and other disclosed processors have their own privacy practices.
2. Information FullWorth collects
Depending on the features you use, FullWorth may collect:
- account information such as your email address, account identifiers, authentication state, security settings, and account timestamps;
- connected institution and financial-account metadata that you authorize through a data provider;
- transaction information used to identify recurring bills and changes;
- bill streams, bill history, alerts, evidence, and subscription or beta-access state;
- statements and images you upload, along with extracted text and validated bill facts;
- technical and security information needed to operate, protect, diagnose, and rate-limit the service, such as request timing, security events, and limited network metadata.
3. Connected financial information
FullWorth may use Plaid or another disclosed financial-data provider to connect to institutions you choose. The provider's connection interface collects the credentials or authentication information needed to connect to your institution. FullWorth is designed to receive provider access credentials or tokens rather than your institution password.
Provider access tokens are treated as sensitive secrets, kept server-side, and protected at rest. Browser clients are not intended to receive Plaid access tokens.
FullWorth uses authorized financial information to discover recurring bills, synchronize transaction history, monitor connection health, identify likely bill payments, calculate bill changes, and support related product features.
4. Statements, images, OCR, and extracted evidence
When you upload a supported bill document, FullWorth stores the source file in user-isolated statement storage and may extract text from PDFs or run OCR on images and scanned documents. FullWorth then validates candidate fields before using them as bill evidence.
Stored statement paths are internal implementation details and are not intended to be exposed to clients. Download and status requests are scoped to the authenticated owner.
Do not upload unrelated documents or documents you are not authorized to provide.
5. How FullWorth uses information
FullWorth uses collected information to provide and secure the service, including to:
- create and authenticate your account;
- connect and synchronize financial institutions you authorize;
- detect recurring bills and meaningful changes;
- process statements and generate evidence-backed explanations or alerts;
- maintain subscriptions, beta access, and account preferences;
- prevent abuse, enforce ownership boundaries, investigate failures, and protect service integrity;
- send transactional messages such as email verification, password recovery, security notices, and service notices;
- evaluate and improve product accuracy and reliability using controlled, privacy-aware testing.
6. Automated and AI-assisted processing
FullWorth uses deterministic software for security decisions, ownership enforcement, financial arithmetic, comparisons, and final persistence decisions. Where separately enabled, AI-assisted processing may interpret limited statement evidence or produce candidate facts for evaluation.
FullWorth's current architecture does not treat AI output as evidence by itself. Candidate facts must pass deterministic validation before they can influence persisted bill evidence. Controlled shadow evaluation is designed not to expose raw statement text in normal telemetry.
7. Service providers and disclosures
FullWorth may disclose information to service providers only as needed to operate the service, such as financial-data connectivity, hosting, email delivery, payment processing, backup infrastructure, security operations, and explicitly enabled document or AI processing.
FullWorth may also disclose information when reasonably necessary to comply with law, respond to lawful process, protect users or the service, investigate fraud or abuse, or complete a corporate transaction subject to appropriate protections.
FullWorth does not sell connected financial transaction data for advertising. If the business model changes materially, this notice and applicable consent flows must be updated before relying on that change.
8. Retention, backups, and deletion
FullWorth keeps active account and financial records for as long as needed to provide the service and maintain the bill history you use. When you delete your account through supported controls, FullWorth is designed to remove user-owned database records and stored statement files after required bank-connection revocation steps complete safely.
Encrypted operational backups can retain previously deleted information for a limited recovery lifecycle until the applicable backup snapshots expire under FullWorth's retention policy. Backups are intended for disaster recovery rather than routine access to deleted records.
FullWorth may retain limited records longer when necessary for security, fraud prevention, legal obligations, dispute resolution, or enforcement of agreements.
9. Security practices
FullWorth uses technical safeguards intended to reduce unauthorized access, including HTTPS, authentication and authorization controls, owner-scoped queries, antiforgery protections for browser mutations, rate limits, protected server-side credentials, security headers, encrypted or protected secrets, isolated statement storage, release-integrity checks, encrypted backups, and recovery verification.
No internet service can guarantee absolute security. You should use a unique password, enable available two-factor authentication, protect recovery codes, and promptly act on account-security notices.
10. Your choices and controls
Depending on the current FullWorth release, you may be able to update account preferences, change account security settings, disconnect linked financial institutions, download supported records, and permanently delete your account.
You can stop future financial synchronization by disconnecting a bank connection. Disconnecting does not automatically erase historical records already needed for your FullWorth bill history; account deletion is the broader deletion control.
Privacy rights can differ by location. FullWorth should evaluate and support legally required access, correction, deletion, portability, restriction, or appeal rights before expanding availability into jurisdictions where those rights apply.
11. Children
FullWorth is not designed for children under 13. The service should not knowingly collect personal information from a child under 13. Additional age or consent requirements may apply in some jurisdictions and should be reviewed before broad public availability.
12. Changes to this notice
FullWorth may update this Privacy Notice as the product, providers, law, or data practices change. The version and effective date above identify the current notice. Material changes should be communicated through a reasonable notice or consent flow before FullWorth relies on them when required.
13. Contact
Privacy questions or requests may be submitted through the contact or support method published by FullWorth in the service. A dedicated privacy contact and mailing address should be added before a broad commercial launch if required by applicable law.