PDFnizer
Privacy Policy
Version 2026-07-28 · Last updated: July 28, 2026
Your documents should stay yours. This policy describes what PDFnizer processes, why we process it, and the choices available to you.
What this policy covers
This Privacy Policy explains how PDFnizer handles information when you use our website, browser-based PDF tools, accounts, workflows, and paid features. PDFnizer is operated as a local-first service: the standard PDF tools process files in your browser and do not upload the PDF contents to our servers.
Information processed in your browser
When you use a standard PDF tool, your selected files, filenames, document contents, page previews, passwords, and generated results are processed locally in your browser. We do not receive or store those files as part of that workflow. Your browser may temporarily hold local data such as object URLs while the tool is open; the application releases those resources when they are no longer needed.
Account information
If you create an account, we collect your email address, account identifier, verification status, authentication-provider details, and a securely hashed password when password sign-in is used. We also process session and refresh-token records so you can remain signed in. Access tokens last 15 minutes; refresh tokens are stored in your browser's localStorage and expire after 7 days unless you sign out sooner. Verification or password-reset codes help secure your account, and we do not store your plaintext password.
Workflows and optional cloud data
Pro workflow features automatically save the workflow name, workflow graph and settings, timestamps, and account ownership so you can reuse workflows. Workflow output and source passwords are encrypted before backend storage when configured in a saved workflow. A watermark image uploaded to a saved workflow is stored remotely in R2 with its type, size, checksum, and object identifier; images used only by the public watermark tool remain local in your browser. PDF files processed while running a workflow are not retained as ordinary uploaded documents.
Payments
When you subscribe, payment processing is handled by Stripe. PDFnizer stores subscription and entitlement information needed to provide Pro access, such as Stripe customer, subscription, price, plan, status, trial, and billing-period identifiers. We do not store your full payment-card number.
Analytics and essential storage
We use optional, privacy-conscious analytics to understand tool usage and improve workflows. Analytics may include a short-lived session identifier, tool and workflow events, counts, and coarse file-size buckets. We do not send PDF contents, filenames, passwords, document metadata, or raw error messages. Essential browser storage remembers language and privacy choices; authentication access and refresh tokens are stored in localStorage so the sign-in session can persist. You can change the analytics preference through PDFnizer’s privacy controls; Google’s CMP provides the advertising controls.
Analytics may also include sanitized routes, locale, processing durations, and a per-operation identifier.
Security and service providers
We use Cloudflare for hosting, delivery, database or object-storage infrastructure, and security controls; Stripe for payments; and an email provider to send verification and password-reset messages. These providers process information only as needed to provide their services, under their own terms and privacy policies. We retain operational security records such as rate-limit and challenge information only as needed to protect accounts and the service.
Who controls your information
PDFnizer is the service operator and controller for the information described here. The legal controller name, address, jurisdiction, and privacy contact are listed below. Send privacy requests or complaints to the privacy contact; you may also complain to your local data protection authority. We do not describe the privacy mailbox as a DPO contact unless an appointed DPO is configured below.
Data inventory and processing purposes
Browser PDF data: selected files, filenames, document contents, previews, passwords, and generated results are processed locally to provide the requested PDF tool. Account and authentication data: email, account ID, full name when provided, authentication provider, Firebase identifier, verification status, password hash, session records, reset records, and security metadata are processed to create and protect accounts. Workflow data: saved names, graphs, settings, encrypted PDF password settings, timestamps, ownership, and watermark image metadata are processed to provide saved Pro workflows. Billing data: Stripe customer, subscription, plan, trial, status, and billing-period identifiers are processed to provide paid access. Analytics and advertising data: consent choices, analytics events, coarse file-size buckets, session identifiers, device/browser information, and ad-delivery data may be processed when those features are enabled. Operational data: request IDs, route/status/latency information, and bounded security events are processed to protect and operate the service.
Analytics may also include sanitized routes, locale, processing durations, and a per-operation identifier.
Lawful bases and purposes
We rely on contract or requested pre-contract steps for accounts, workflows, and paid features; consent for optional analytics and advertising where required; legitimate interests for security, abuse prevention, and service reliability; and legal obligations for billing and required records.
Recipients and international transfers
We share information with Cloudflare for hosting, D1, R2, delivery, and security; Stripe for payments and billing; Resend for transactional email; Firebase for authentication; and Google Analytics and Google AdSense when enabled. These providers may process information in countries other than where you live. We use the providers' applicable contractual, technical, and organizational safeguards and retain provider-specific settings and agreements.
Retention
Browser PDF data and public watermark-tool images remain in your browser for the tool session and are not uploaded by standard tools. Account, consent, saved-workflow, and encrypted workflow-secret records are retained while the account is active; after account closure, records are retained only as needed for legal, billing, security, fraud-prevention, and provider obligations. Email challenge codes expire after 15 minutes, access tokens after 15 minutes, and refresh tokens after 7 days; expired authentication records are retained for up to 30 days after expiry for security operations and are then pruned opportunistically on authentication requests. Stripe webhook deduplication records are retained for 30 days. Cloudflare, Stripe, Firebase, Resend, Google Analytics, Google AdSense, and observability logs may retain copies under their configured periods, contracts, and legal obligations.
Advertising and cookies
When advertising is enabled, Google AdSense and its advertising partners may use cookies, local storage, device information, approximate location, and usage information to deliver or measure ads. Google’s certified Privacy & Messaging CMP controls advertising consent and provides its applicable consent and revocation controls; PDFnizer only renders ad units after the CMP makes the advertising consent state available. Advertising consent is separate from PDFnizer’s analytics preference.
Your choices and rights
You may use the standard tools without creating an account, decline optional analytics and advertising, update your account information, or request account deletion by contacting privacy@pdfnizer.com. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to processing, receive a portable copy, or withdraw consent. We may verify your identity before responding and will explain any legal reason we cannot fulfill a request. Provider-held billing, authentication, advertising, analytics, and security records are governed by those providers' retention rules and applicable law.
Children
PDFnizer is not directed to children. We do not knowingly collect personal information from children or adolescents who are below the minimum digital-consent or account age that applies in their location. Where local law requires parental or guardian consent, a minor must not create an account without that consent. If you believe a child or adolescent provided information, contact the privacy address so we can investigate and delete it where required.
Version history and contact
Version 2026-07-28 is the initial publication dated July 28, 2026. We review this policy at least annually and whenever processing, providers, jurisdictions, or legal requirements materially change; we publish the new effective date and preserve prior versions for review on request. For privacy questions or requests, contact the privacy address listed below.
Controller details
Jurisdiction: Brazil
Appointed DPO contact: privacy@pdfnizer.com