Privacy Policy
Last updated 2026-09-25
This Privacy Policy explains what personal data is processed when you use Pdfiqo at pdfiqo.com (the "Service"), why, and what rights you have. We have written it in plain language. The short version: your files stay on your device.
1. Who is responsible for your data
The controller of your personal data is:
- Pdfiqo
- Email: hello@pdfiqo.com
You can contact us at any time about anything in this policy using the email address above.
2. How the Service works
All PDF tools on Pdfiqo run entirely in your web browser, using JavaScript and WebAssembly. When you choose a file:
- the file is read and processed locally on your device;
- the file and its contents are never uploaded to our servers or to anyone else;
- the result is created on your device and downloaded directly by your browser.
The code, fonts and OCR language data the tools need are downloaded from our own domain. Downloading them does not send your files anywhere.
3. What we do NOT collect
We do not collect, receive or store:
- the files you process, their contents, or their file names;
- passwords you enter to protect or unlock a PDF;
- text you type into a document, signatures you draw, or form data you fill in;
- account data, because there are no user accounts;
- payment data, because we do not currently take payments.
We do not use advertising and we do not use tracking cookies.
4. What data is processed
4.1 Server logs (hosting)
When your browser loads the website, our hosting provider automatically processes standard technical data, such as:
- IP address;
- browser type and version (user agent);
- the page or file requested, date and time of the request;
- the referring page, if your browser sends one.
This is needed to deliver the website to you and to keep it secure (for example, to detect abuse or attacks).
4.2 Privacy-friendly analytics (if enabled)
We may use a cookieless, privacy-friendly analytics tool to understand how the Service is used in aggregate. It does not use cookies and does not build profiles of individual visitors. It may record:
- aggregate page views (for example, which pages are visited, referring website, country, device type and browser);
- anonymous tool events, limited to the name of the tool used, a duration bucket (for example, "under 5 seconds") and a file size bucket (for example, "1–10 MB").
Analytics never receives your file names or file contents.
4.3 Error monitoring (if enabled)
We may use an error monitoring service to find and fix bugs. If something goes wrong in the Service, technical information about the error may be sent, such as:
- the error message and technical stack trace;
- the page and tool where the error happened;
- browser, operating system and device type;
- IP address, as part of the network request.
Error reports are designed not to include your files or their contents.
4.4 Emails you send us
If you email us, we process your email address, the content of your message and any details you choose to share, so that we can reply.
4.5 Local storage on your device
The Service may save small UI preferences (for example, your theme or recently used settings) in your browser's local storage. This data stays on your device and is not sent to us. See our Cookie Policy for details.
5. Why we process data (legal bases)
We process personal data only where the GDPR allows it:
- Delivering and securing the website (server logs): our legitimate interest in providing a working, secure service (Art. 6(1)(f) GDPR).
- Analytics (if enabled): our legitimate interest in understanding aggregate usage and improving the Service (Art. 6(1)(f) GDPR). The analytics are cookieless and anonymous by design.
- Error monitoring (if enabled): our legitimate interest in keeping the Service reliable (Art. 6(1)(f) GDPR).
- Replying to your emails: our legitimate interest in answering your questions (Art. 6(1)(f) GDPR), or taking steps at your request before entering into a contract (Art. 6(1)(b) GDPR), where relevant.
- Legal obligations, such as handling complaints or keeping records required by law (Art. 6(1)(c) GDPR).
Where we rely on legitimate interests, you have the right to object (see section 9).
6. Who we share data with (processors)
We do not sell your data. We use a small number of service providers who process data on our behalf, under data processing agreements, and only for the purposes described above:
- Hosting and content delivery, such as Vercel — serves the website and processes server logs.
- Privacy-friendly analytics (if enabled), such as Plausible Analytics — cookieless, aggregate usage statistics.
- Error monitoring (if enabled), such as Sentry — technical error reports.
- Email provider — to receive and answer your messages.
The Pro access request form on the pricing page does not transmit or store what you type: it only shows a confirmation in your browser. If you want to talk to us about Pro, email us instead.
We may also disclose data to public authorities where the law requires us to.
7. How long we keep data
- Server logs: for a limited period set by our hosting provider, unless needed longer to investigate a specific security incident.
- Analytics: aggregate statistics may be kept for as long as the Service runs; they do not identify you.
- Error reports: for a limited period set in our error monitoring provider, after which they are deleted automatically.
- Emails: for as long as needed to handle your request, and afterwards for as long as we may need them to handle possible claims or as required by law.
Your files are not kept at all, because we never receive them.
8. International data transfers
Some of our service providers may process data outside the European Economic Area (EEA), for example in the United States. When that happens, we make sure the transfer is protected by an appropriate safeguard, such as:
- an adequacy decision of the European Commission (including the EU–US Data Privacy Framework, where the provider is certified); or
- the European Commission's Standard Contractual Clauses.
You can ask us for more information about these safeguards at hello@pdfiqo.com.
9. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you and get a copy;
- rectification of inaccurate data;
- erasure of your data ("right to be forgotten");
- restriction of processing;
- data portability, where applicable;
- object to processing based on our legitimate interests;
- withdraw consent at any time, where processing is based on consent, without affecting processing done before withdrawal.
To use any of these rights, email us at hello@pdfiqo.com. We will respond within one month, as required by the GDPR. Because we collect very little data and no accounts exist, we may need some details from you to find the data you are asking about.
You also have the right to lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl). You may also contact the supervisory authority in the EU country where you live or work.
10. Automated decisions
We do not make decisions about you based solely on automated processing, including profiling.
11. Children
The Service is not directed at children. We do not knowingly collect personal data from children. If you believe a child has sent us personal data (for example, by email), please contact us and we will delete it.
12. Security
Because your files are processed on your device, they are never exposed to our servers. For the website itself, we use HTTPS encryption and reputable providers. Please keep your own device and browser up to date.
13. Changes to this policy
We may update this policy when the Service or the law changes, for example if we introduce a paid plan. The date at the top shows when it was last updated. If we make significant changes, we will make that clear on the website.
14. Contact
Questions about privacy? Email us at hello@pdfiqo.com or write to Pdfiqo.