A browser session is transport, not a new memory.
One account, one stated question
The current build can inspect supported Fortum, Helen and Elisa account pages only when the person has already registered the matching credential reference. The result is a short account brief made from exact fields observed on that account page; an unsupported field or another host is left out rather than inferred.
If the site presents a login or human check, the same session is handed back through an owner-bound link. Another account cannot open it. Payment, password changes and broader account administration remain outside this path.
A document leaves no provider archive
A requested account PDF is copied into SAINT's private delivery store only after the transport copy has been deleted. If that deletion cannot be confirmed, no download link is shown and the local copy is removed.
The signed delivery link belongs to the person and expires with the document after 24 hours. Account deletion also releases parked sessions and retries any outstanding transport deletion before the record is cleared.
Submission still belongs to the person
For Fortum and Helen meter readings, SAINT first repeats the exact meter, value and site. Only an explicit confirmation can enqueue one submission, and the credential is checked again immediately before the browser opens.
The receipt distinguishes submitted, not submitted and unknown. A missing success marker never becomes a success claim. This is an in-development account-action path for supported utilities, not general permission to operate a person's accounts.
