Practical guide

Choose how generated PDFs are stored, accessed and handed over

Last materially reviewed 2026-10-02

Quick answerMap where the input and output go, who can retrieve them and how long each copy remains. A successful generation or regional endpoint does not establish an approved data-handling workflow.

Draw the whole path, including copies

For a fictional report, list source system, connector, generator, temporary output, review location and final recipient. Add request history and downloaded copies to that map. Omitting a box from the diagram does not mean the corresponding copy does not exist.

Questions for the responsible owner
PartDecision to establish
InputWhich approved fields may leave the source?
ProcessingWhich service and region handle this request?
Temporary outputWho can retrieve the link, and when does it expire?
Review copyWhere is the file held before release?
LogsDo request or error records contain report content?
DistributionWho authorizes the recipient and records the result?

Use synthetic records while resolving the design. Do not upload a real client report to discover whether your organization permits the service. This worksheet identifies decisions; it does not make them on your behalf.

Distinguish the documented output routes

CraftMyPDF’s access documentation describes temporary presigned download URLs, direct binary responses and an own-storage route. A holder of a presigned URL can access its file. Direct binary output avoids that output’s CDN storage, while request logging remains a separate consideration. The documentation describes incoming logs lasting up to 14 days by default.

Treat a live download URL as access-bearing information, not a harmless report ID. Keep it out of public pages, ordinary analytics events and broadly shared logs. A private review record can refer to a controlled artifact without embedding a reusable access token.

Own storage still needs correctly scoped access, retention and recipient handling. It is not automatically safer merely because the bucket belongs to your organization. Have the responsible administrator establish the actual configuration; do not make an object public to solve a delivery problem.

Resolve limits for the exact route

The regional endpoint page lists different timeout and payload limits by route. Its binary-size note and the secure-output page do not present one unambiguous universal limit. Record the chosen endpoint and export mode, and resolve the applicable limit before relying on a large report.

The merchant also describes regional processing and links a sample DPA in its storage documentation. Those are merchant statements, not an independent audit or proof that your particular use is legally compliant. A region label does not answer what your connector, logs or final delivery system retain.

Make an expired or missing link a controlled event

If a reviewer cannot open an output, first identify the existing generation and its intended storage route. Check whether the link expired or whether a controlled copy was already retained. Do not regenerate and redistribute the entire batch simply because one temporary URL no longer works.

If the file cannot be recovered, record that outcome and obtain the applicable decision about a new generation. Keep the original attempt and its charges visible. A replacement file must pass the same source and page checks before release; it is not automatically equivalent because it uses the same filename.

Close the loop after the handoff

Record which reviewed output was sent through which authorized channel, without unnecessarily copying its private contents into the record. Follow the organization’s actual retention rules for working files, logs and local downloads. Do not invent a universal deletion period from a product plan.

Keep unresolved processing, recipient or access requirements as holds in the brief. If the generator cannot meet a mandatory condition, retain an appropriate existing workflow or evaluate another route. A polished report is not worth an uncontrolled disclosure.

Sources and evidence limits

Documentation checked 2 October 2026. Original examples are fictional; no merchant account or API was tested.

  1. CraftMyPDF output access choices — checked 2026-10-02
  2. CraftMyPDF data storage documentation — checked 2026-10-02
  3. CraftMyPDF regional endpoint limits — checked 2026-10-02