Privacy Policy
pdfity is designed around a strict boundary: standard document processing happens in your browser. Your document content is not sent to pdfity servers for those operations.
Ultimo aggiornamento: July 24, 2026
The privacy boundary
We operate the account and plan. Your browser operates the document.
- No document bytes, file names, extracted text, thumbnails, signatures, or output files are stored on pdfity servers.
- We store the tool used, file count, aggregate input size, processing duration, outcome, and plan for dashboard, limits, and pdfity Wrapped.
- We store your sign-in provider identity and profile image, but not persistent OAuth access, refresh, or identity tokens.
- We use no advertising cookies, marketing cookies, Google Analytics, Meta tracking, profiling, data sales, or cross-site tracking.
- Polar handles checkout and payment as Merchant of Record. pdfity stores normalized billing state, not full card data or raw webhook payloads.
1. Scope and controller
This policy applies to pdfity.com, the pdfity web application, authenticated accounts, optional cloud provider actions, billing surfaces, and related support by email.
pdfity is the service operator and controller for the service data described in this policy. Privacy requests can be sent to contact@pdfity.com. Corporate registration, office address, and governing jurisdiction details will be added when the operating company is established.
2. Document processing
For standard pdfity tools, document input, processing, preview, and output remain inside the browser on your device. pdfity servers do not receive the document bytes.
The browser may use local memory, Web Workers, WebAssembly, browser storage, or temporary object URLs to complete an operation. These are device-side mechanisms. Closing the workspace or clearing browser data may remove local state, and pdfity cannot restore local documents or outputs.
- We do not receive or store document content or output files.
- We do not receive or store file names, extracted text, page images, thumbnails, signatures, annotations, passwords, or embedded document metadata.
- We do not create server-side document backups.
- We do not use document content to train models, target advertising, or build user profiles.
3. Account and sign-in data
pdfity uses supported identity providers such as Google, Microsoft, and Apple to create and authenticate accounts. The exact providers available may change.
We receive only the account details the provider shares for sign-in and account presentation. We retain the provider identity link needed to recognize the same account.
- Internal user ID
- Name, email address, email verification status, and profile image
- Identity provider name and provider account ID
- Account creation and update timestamps
- No persistent OAuth access token, refresh token, or identity token in the pdfity database
4. Usage, dashboard, limits, and pdfity Wrapped
When an authenticated user starts a document operation, pdfity creates a server-side operation receipt to enforce plan access and daily limits. The browser closes that receipt with a success, failure, or cancellation result.
File count and aggregate input size are reported by the browser. They support the dashboard and pdfity Wrapped. Because document bytes are not uploaded, pdfity does not claim that client-reported size is independently verified from the document content.
- Tool identifier
- Operation start and completion timestamps
- Success, failure, or cancellation outcome
- Number of input files and aggregate input bytes
- Browser-side processing duration
- Free or Pro plan at the time of the operation
- No file name, document identifier, content hash, page text, page image, or output content
5. Cookies, local storage, and analytics
pdfity uses only first-party authentication and security cookies needed to sign you in, protect sign-in flows, prevent request forgery, and keep the service secure. The normal signed-in session can persist when the browser is closed and reopened.
pdfity does not use advertising or marketing cookies. It does not use Google Analytics, Meta Pixel, cross-site tracking, behavioral profiling, or cookies for selling or sharing personal data.
Vercel Web Analytics and Speed Insights may be used in cookieless mode for aggregate traffic and performance measurement. The cookie notice acknowledgement is stored locally in the browser and is not an advertising consent profile.
6. Billing data and Polar
Polar acts as Merchant of Record for supported purchases. Polar and its payment processors handle checkout, payment methods, taxes, invoices, and payment compliance under their own terms and privacy notices.
pdfity receives and stores only the normalized billing information needed to grant and remove Pro access, reconcile checkout state, prevent duplicate event processing, and answer billing questions.
- Polar customer, checkout, subscription, product, price, and event identifiers
- Subscription status, billing period dates, cancellation state, and grace period state
- Checkout status and completion timestamp
- No full card number, card security code, bank credential, or raw Polar webhook payload
7. Google Drive, Dropbox, and other provider actions
Cloud import or save actions begin only when you explicitly choose them. The selected provider processes the action under its own terms and privacy policy.
pdfity does not retain persistent cloud provider OAuth tokens in its server database. Temporary browser-held authorization can end when the tab, browser session, provider session, or authorization window ends.
Files selected from or saved to a cloud provider are handled between your browser and that provider for the requested action. They are not converted into pdfity server-side document storage.
8. Purposes and legal bases
We process account, entitlement, usage, and security data to provide the service you request, perform our agreement with you, protect the service, enforce plan limits, prevent fraud, maintain reliability, and comply with applicable obligations.
Where applicable law requires a legal basis, these purposes rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where specifically requested. We do not use legitimate interests to justify advertising tracking that pdfity does not perform.
9. Retention and deletion
pdfity applies the following default retention schedule unless a shorter period is technically practical or a longer period is required for fraud prevention, dispute handling, chargebacks, or law.
- Account identity and current plan data: until account deletion
- Raw operation records: up to 15 months
- Daily limit counters: up to 45 days
- Annual pdfity Wrapped summaries: until account deletion
- Abandoned or failed checkout records: up to 90 days
- Normalized subscription and billing event records: up to 24 months after the account or subscription relationship ends
- Security and operational logs: normally up to 30 days
- Encrypted backups containing deleted records: overwritten within 30 days under the normal backup cycle
10. Account deletion
You can request account deletion from the dashboard when the feature is available or by emailing contact@pdfity.com. Active paid subscriptions must be canceled before or as part of deletion so that account deletion does not leave an unintended renewal.
Account deletion removes the account, provider identity links, usage records, dashboard aggregates, and Wrapped summaries from the active database. Limited normalized billing or security records may be retained for the periods above when necessary for disputes, fraud prevention, chargebacks, or legal obligations.
11. Sharing and processors
pdfity does not sell personal data. It does not share personal data for cross-context behavioral advertising.
We use service providers only for functions needed to operate pdfity, including hosting and performance through Vercel, database hosting through the configured infrastructure provider, identity providers selected by the user, and billing through Polar and its processors. Providers process data under their own terms and applicable data processing commitments.
12. International processing
Service providers may process account, billing, or operational data in countries outside your own. Where required, pdfity will use appropriate contractual or legal safeguards for restricted transfers.
The document content boundary remains the same: standard document bytes are processed locally in the browser and are not transferred to pdfity servers.
13. Security
pdfity uses measures appropriate to the service boundary, including encrypted transport, restricted production access, signed authentication sessions, request forgery protection, rate limits, webhook signature verification, data minimization, and separation of document processing from server infrastructure.
No service can guarantee absolute security. If you believe an account or service incident has occurred, contact contact@pdfity.com promptly.
14. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, and to withdraw consent where processing is based on consent.
Send a request from the email address connected to your account to contact@pdfity.com. We may ask for proportionate verification before acting. You may also complain to the competent data protection authority in your location.
15. Children
pdfity is not directed to children under 16. A person under 16 should not create an account or purchase Pro without authorization from a parent or legal guardian where applicable.
16. Changes and contact
We may update this policy when the product, providers, law, or company structure changes. Material changes will be posted here with a revised date and, when appropriate, communicated in the product.
Questions and privacy requests can be sent to contact@pdfity.com.
Need a clear answer?
Write to us directly. Do not attach a document or send full payment-card details.
contact@pdfity.com