Privacy policy
1. Privacy-by-design approach
PDFine processes documents on the user device. PDF files are not uploaded to servers for editing.
Product principle: what we do not want for ourselves, we do not want for others.
2. Data controller
Controller: Legal owner of PDFine (see legal notice).
Privacy and data rights contact: support@pdfine.net
If a Data Protection Officer (DPO) is legally required and appointed, their contact channel will be published here.
3. Data processed
- Document data: processed locally in the browser to run PDF tools.
- Minimal technical data: technical records the hosting provider may generate to operate and protect the service.
- No commercial profiling and no sale of personal data.
4. Legal basis (where GDPR or equivalent applies)
- Performance of the service requested by the user.
- Legitimate interest in security, stability and technical service improvement.
5. No in-app usage tracking
PDFine does not include in-app usage monitoring or send navigation events to a statistics service. Basic hosting may generate technical security and delivery logs that are unrelated to the contents of your PDFs.
6. Retention
- Local browser data (preferences, cache, IndexedDB) remains on the user device.
- Strict confidential mode reduces local persistence when session/browser closes.
7. User environment security
The confidentiality of local processing also depends on the user environment, including the device, browser, operating system, installed extensions, and the user's own security measures.
PDFine cannot guarantee confidentiality when the user's device or browser is compromised by malware, unauthorized access, invasive third-party software, or insecure configurations outside the service.
8. Data subject rights
Where applicable (GDPR, CCPA or equivalent), you may exercise rights of access, rectification, erasure, objection, restriction and portability via the published legal contact channel.
9. International transfers
If any technical provider processes data outside your country, the controller must apply adequate safeguards (standard contractual clauses or another valid transfer mechanism).
10. Supervisory authorities
You may lodge a complaint with the competent data protection authority in your jurisdiction.