Back to Home
Privacy First Architecture

Privacy Policy

Last updated: October 2026 • Effective Date: January 1, 2026

Local Processing

Many PDF tools process documents locally in your browser using WebAssembly and JavaScript. Excel-to-PDF and PowerPoint-to-PDF upload files to our server. Website-to-PDF renders public webpages on our server. AI PDF Summarizer sends extracted PDF text through our server to OpenAI.

Storage Depends on the Tool

Standard local PDF operations do not upload file contents to our server. Server conversions use temporary files; Website-to-PDF stores results in Google Cloud Storage and job metadata in PostgreSQL. Cleanup attempts and access expiry are not guarantees of immediate or complete deletion.

Document Content and Service Data

Our conversion API logs do not include document contents. Accounts, billing, usage records and analytics handle service data separately. AI summaries require sharing extracted text with OpenAI; this policy does not promise how OpenAI retains that text or uses it for training.

1. Introduction

At Private PDF Editor (https://private-pdf-editor.com/), many tools let you work on documents without uploading their contents. Other tools require server processing or an external service. This Privacy Policy explains those differences, the storage and cleanup mechanisms used by the app, and the account, billing, usage and analytics data handled when you use the website.

2. How Documents Are Processed

Standard PDF editing and manipulation tools run in the browser. This does not apply to every tool: Excel-to-PDF and PowerPoint-to-PDF upload complete files, Website-to-PDF sends a URL for server rendering, and AI PDF Summarizer sends extracted document text to our server and OpenAI.

  • Client-Side Engine: Local PDF tools use Google PDFium WebAssembly and client-side JavaScript engines for PDF reading, rendering, editing and file generation. These tools do not upload your PDF contents for processing. The website can still make requests for authentication, usage accounting, software assets and analytics.
  • Browser Memory: Local tools hold loaded files and generated outputs in browser memory, buffers and blobs. Resetting a tool clears its working state, but does not guarantee immediate erasure of every copy in memory. Download links may keep generated PDF blobs available for the lifetime of the tab. Closing or refreshing the tab ends that page session; it is not a guarantee of secure erasure from your device.
  • Website-to-PDF: The URL you submit is sent to our server and opened in a temporary isolated Chromium browser. The renderer retrieves the webpage and its resources, contacting the destination website and resource providers. Only public HTTP and HTTPS pages are supported; local, private-network and intranet addresses are blocked. The submitted URL and job metadata are stored in PostgreSQL, and generated PDFs are temporarily stored in Google Cloud Storage. Metadata includes job status, timestamps, a generated filename, a hashed access token and a hashed IP-based rate-limit identifier. The submitted URL is cleared when the job is marked ready, failed or cancelled. A completed result has a five-minute access window starting when it is marked ready, and may become unavailable earlier after receipt or cancellation. Cleanup mechanisms attempt to remove the stored PDF after the browser receives and validates it, on cancellation, or after expiry, and remove expired job metadata. Access expiry does not guarantee physical deletion at exactly five minutes: cleanup depends on successful requests or cleanup runs, service availability and storage operations. Removal of the temporary browser profile is attempted before a result is made available; a detected rendering-profile cleanup failure prevents a successful result.
  • Local and Server Storage: Standard browser-only PDF operations do not upload or store your document contents in our server databases or storage buckets. The server-side exceptions above and in Sections 3–5 handle content outside your device. Saved browser settings and account-related records are separate from document processing, as described in Sections 6 and 7.

3. PowerPoint-to-PDF Conversion

PowerPoint-to-PDF uploads your complete .ppt or .pptx presentation to this app's server, where LibreOffice converts it to PDF. The uploaded presentation, generated PDF and LibreOffice profile are handled in a per-conversion temporary workspace. The server attempts to remove that workspace when conversion finishes or fails. If removal fails, the error is logged, but a successfully generated PDF may still be returned and temporary files may remain. A process interruption can also prevent cleanup. This feature does not use a third-party conversion provider. The conversion logs record format, byte counts, duration and error information, not presentation contents or the uploaded filename.

4. Excel-to-PDF Conversion

Excel-to-PDF uploads your complete .xls or .xlsx workbook to this app's server, where LibreOffice converts it to PDF. The uploaded workbook, generated PDF and LibreOffice profile are handled in a per-conversion temporary workspace. The server attempts to remove that workspace, with retries, before returning a successful PDF. If cleanup fails, no successful PDF is returned, but this does not mean that the remaining files have been deleted. A process interruption can also prevent cleanup. This feature does not use a third-party conversion provider. The conversion logs record format, byte counts, duration and error information, not workbook contents or the uploaded filename.

5. AI Summaries, Document Content and Retention

AI PDF Summarizer extracts text from your PDF in the browser and sends that text to the app's server, which sends it to OpenAI to generate a summary. The PDF file itself is not uploaded by this feature, but its extracted contents leave your device. Do not use this feature for text you do not want to share with an external AI provider. We have not verified OpenAI's account-level retention or training settings and do not promise a retention period, deletion schedule or exclusion from training for provider-side records.

The app keeps AI session data, intermediate digests and completed summaries in server process memory rather than storing summary contents in a database or file. Active sessions have a 30-minute expiry and completed summaries a five-minute expiry. Expired entries are removed during later session operations, not by a periodic deletion timer, so expiry does not promise immediate memory erasure.

App-side cleanup does not delete files you downloaded, copies you saved or shared, or records retained by an external provider. Exact cleanup timing after failures, infrastructure log retention, backups and recoverable storage copies have not been verified. We do not promise complete or irreversible erasure, zero data retention, or legal compliance or security certifications on the basis of these cleanup mechanisms.

For standard browser-only PDF operations, the app does not send the following to its server:

  • Text content, tables, metadata, or images contained inside your PDFs for local processing
  • Passwords used to protect or unlock your local PDF files
  • Biometric or electronic signature strokes created in the signature tool

6. Accounts, Billing, Usage, Analytics & Hosting

Account sign-in is handled by Clerk, which processes the information provided during authentication and session information. The app uses account identifiers to associate authenticated users with their subscriptions and usage records.

PayPal and Paddle handle their respective subscription checkout and payment flows. The app stores account-linked plan, provider subscription or transaction identifiers, subscription status, payment-period and verification timestamps, and payment-event identifiers and types in PostgreSQL. These records support subscription verification and access to paid features; they are not copies of your PDF contents. This policy does not establish retention periods or deletion guarantees for payment-provider records.

Usage accounting stores account identifiers, usage periods, successful-job counts, and reservation identifiers, statuses and timestamps in PostgreSQL. These records enforce plan limits without storing document contents. Account, billing and usage records are not automatically erased by resetting a PDF tool, closing the tab or allowing a document result to expire. No fixed deletion period for those records has been verified.

The website loads Google Tag Manager and supports Umami analytics when configured. The app's custom Umami events describe actions such as opening a tool, starting or completing processing, requesting a download and selecting a plan. Their additional fields are limited to approved tool and plan identifiers, not document contents, filenames or raw document URLs. Google Tag Manager can load tags configured outside this app; the contents of its live container and provider-side analytics retention have not been verified. Analytics and service requests can occur even when document processing is local.

Hosting and API infrastructure may log request metadata, such as IP address, browser user-agent, request path and response status, for security and diagnostics. The app's API request logger omits request bodies and strips query strings from logged request paths. The Excel and PowerPoint converters log format, byte counts and duration. Website-to-PDF logs job identifiers, the destination hostname, status and result size, but not the full submitted URL or rendered page contents in its application logs. This does not establish what hosting infrastructure, destination websites or external providers log, or how long they keep those records.

7. Cookies and Local Storage

Private PDF Editor uses browser localStorage to remember preferences, such as selected language (FR, EN, ES) and rendering quality. The Header & Footer tool can also save header/footer text and settings when you save a look. That saved look does not include the PDF or logo, but entered text may contain personal or company information. Saved data can remain after closing the tab or resetting a tool; avoid saving sensitive information if you do not want it persisted in your browser. You can remove local storage using your browser's controls for clearing this site's data, which also removes saved preferences. Authentication and external services can use cookies or other browser storage for their own functions.

If the app's Google AdSense integration is enabled, its Google Privacy & messaging consent manager loads before the app's ad-serving script. The app waits for consent data and regional privacy signals; where device-storage consent is required, it must have been granted. If the manager fails or reports an applicable opt-out, the app does not enable ad serving. Visitors can reopen available choices using “Privacy & cookie settings” in the footer. This describes the app's gating logic, not a certification of the live regional message configuration or legal compliance.

After AdSense is allowed to load, Google may receive request information and use cookies or similar technologies to serve and measure ads, according to the applicable consent signals and provider settings. The app's AdSense gating does not prevent other services, such as Google Tag Manager or authentication, from making requests. Provider-side storage and retention are separate from this app's document cleanup.

8. Contact Information

If you have questions regarding this Privacy Policy or wish to inquire about our privacy architecture, you may reach our privacy team via our Contact Page or by writing to:

Private PDF Editor Data Protection Team
Website: https://private-pdf-editor.com/
Email: privacy@private-pdf-editor.com