The Short Version
Account, licensing, payment, security and optional usage-event requests also use network services. This policy describes those requests and the information they carry.
Information We Process
| Data | When | Details |
|---|---|---|
| PDF files and images | Local tools | Read in browser memory for operations such as merge, split, convert, OCR, compression, signing, encryption and redaction. The original file is not uploaded by these tools. |
| Extracted document text | Only after an AI confirmation | The app sends the selected text, feature, request ID and, for translation, target language to our Worker with an account authorization token. The Worker forwards task input to Cloudflare Workers AI; it does not forward the account token to the model. The original PDF binary is not included. Our Worker does not persist the request text or generated response after processing. For up to 90 days, it retains an account-associated usage record that includes a request-derived hash, feature, credit charge, input length, model/prompt version and processing time. Cloudflare processes content under its own service policies; provider-side handling or retention may differ. |
| OCR history | Only when enabled in Settings | Up to 10 recent results are stored in this browser profile. Each entry can include its filename and up to 5,000 characters of extracted text. History is off by default and is not synced to our servers. |
| Saved signatures | When you choose to save one | Up to six PNG signature images can be kept in local browser storage. They remain on this device profile until removed or browser data is cleared. |
| Usage events | Only after opt-in in Settings | Events may include a feature or tool name, language, file count/type, page count, timing, or an operation result. We filter filenames and document text from these event requests. Event records are retained for up to 90 days. We do not use ad pixels or session replay. |
| Account and licensing | When signing in, buying, restoring, or using cloud AI | Firebase supplies an account identifier and, if linked, an email address. Our license service processes account ID, entitlement, credit balance, usage and purchase/refund records. A signed entitlement token may be cached locally for offline verification. During an upgrade, an existing local paid-access record is kept while the license service verifies the purchase. |
| Payment information | When you make a purchase | Lemon Squeezy processes checkout and payment details. Our service receives order and product identifiers, status, receipt details and the checkout email needed for restore; it does not receive your full card number. |
| Technical request data | When network services are used | Hosting, identity and payment providers may receive standard request data such as IP address, browser information and timestamps for delivery, security and abuse prevention. |
Local Processing and Cloud AI
For local tools, your browser reads the selected file and runs the operation on your device. The result is downloaded through the browser. OCR language models and app assets may need to be downloaded before their first offline use.
Cloud AI is a separate, optional service. Before each cloud request, the app shows a confirmation describing the feature and the amount or coverage of text to be sent. If you cancel, the request is not sent. When you confirm, the app sends extracted textโnot the original PDFโplus the feature name, a unique request ID and any requested target language to our Worker using an account authorization token. The Worker forwards task input to Workers AI without forwarding that token.
Do not send text that you are not comfortable having processed by a cloud service. Cloud AI requires an internet connection and may use AI credits. Our Worker does not persist the extracted text or generated response after processing. For up to 90 days, it retains an account-associated usage record that includes a request-derived hash, feature, credit charge, input length and processing metadata. Cloudflare separately processes requests under its own service policies, so provider-side handling and retention may differ. Local processing can continue offline after required app assets and language models have been downloaded; cloud AI, purchases, account restore and license refresh need a connection.
Local Storage, History and Deletion
The app uses browser storage for preferences, local usage state, cached app assets, OCR history when opted in, and saved signatures when you choose to save them. It does not intentionally store the original PDF files in browser storage.
- OCR history is off by default. Turning it off stops new history entries; use Settings โ Privacy & Local Data โ Clear local document data to remove existing OCR history and saved signatures.
- Saved signatures are stored only in this browser profile. You can remove them in Settings or from the signature tool.
- Signed offline entitlement data contains an account identifier and its issue/expiry times. It is cryptographically verified and expires; connect to the license service to refresh or restore access.
- Browser settings can also clear this app's local storage, cached assets and service-worker data. Clearing browser data can remove offline resources and local preferences.
Disabling optional usage events stops future event submissions. To ask about deletion of account, purchase or server-side event records, contact us using the address below. Transaction and security records may need to be retained for legal, accounting or abuse-prevention purposes.
Service Providers
We use service providers to operate specific parts of PDF Tools Pro. Depending on the feature, requests may go to:
- Cloudflare for the app's Worker API, account/license data and optional Workers AI processing. Cloudflare's Workers AI data-use information and privacy policy describe provider-side processing.
- Firebase for anonymous or linked account authentication.
- Lemon Squeezy for purchase checkout and payment processing.
- Google Fonts for fonts loaded by the app; a font request can expose standard network information such as your IP address to Google.
- Microsoft Store or browser hosting services when the app is installed or loaded from those services.
These providers process information under their own terms and privacy notices. The app's locally bundled PDF libraries run in your browser; they do not receive your file as a separate hosted processing service.
Retention
OCR history and saved signatures stay in local browser storage until you clear them or clear browser data. App and language-model assets remain cached until the browser evicts them, you clear them, or an app update replaces them.
Account, credit, entitlement, purchase and refund records are retained as needed to provide and restore access, prevent abuse, reconcile transactions, and meet legal or accounting requirements. Hosting and security logs may be retained under the relevant provider's operational policies. Contact us to ask about a specific record or deletion request.
Children's Privacy
PDF Tools Pro is not designed for children. If you believe a child has provided personal information through an account or purchase flow, contact us so we can review the request.
Changes to This Policy
We may update this policy as the app changes. We will update the date above and provide an in-app notice for material changes to data handling where appropriate.
Contact
For privacy questions, data requests or concerns, email privacy@pdftools.pro. For billing and purchase support, email support@pdftools.pro.