Privacy Policy
Last updated: September 8, 2026
pdftap combines a browser-based interface with a server that performs PDF operations. This page explains what is sent, what is kept, and which service providers are involved.
Files
When you run a PDF operation — including applying edits, OCR, compression, conversion, or merging — your file and the options you selected are uploaded to our backend over HTTPS. The server processes the request and returns the result. The application does not intentionally retain uploaded documents after the request.
The upload framework and isolated OCR worker may temporarily spool request data to private operating-system-managed storage while a request is in progress. Those temporary files are not a document library and are removed when request handling finishes. We do not log document contents.
Page previews and editing controls run in your browser. The actual output file is produced by the backend after you start an operation or select Apply.
Cookies
The paid-access flow uses two strictly operational cookies. The pdfedit_sessioncookie holds a signed token that identifies an active day-pass entitlement. The short-lived pdfedit_checkout_claim cookie lets the same browser recover access if the Stripe return tab is closed or interrupted. Both are httpOnly, SameSite=Lax, and Secure. The claim cookie expires after 48 hours; the session cookie expires with the purchased access window. They are operational, not analytical.
During Checkout, the browser also stores a nonsensitive marker containing only the plan name and start time for up to 48 hours. It contains no Stripe Session ID, payment data, email address, or claim credential, and is cleared after completion, cancellation, terminal failure, or expiry.
We do not set tracking cookies. We do not set advertising cookies. We do not set analytics cookies.
Analytics & tracking
We use first-party daily counters to understand which tools are opened, whether PDF operations succeed, and where the upgrade flow stops. The counters store only the UTC day, a fixed event name, tool, language, and total count for up to 90 days. They do not store visitor IDs, IP addresses, browser fingerprints, full URLs, filenames, document contents, or individual event histories. They cannot identify or follow a person between visits.
These measurements stay on our server. We do not use third-party analytics, advertising pixels, or session recording. Optional counter requests contain no cookies. We respect Do Not Track and Global Privacy Control, exclude known automated testing, and offer the browser-specific choice below. Necessary security logs and payment records are separate from these optional measurements.
You can turn off optional usage counts at any time. Only this preference is saved in your browser; it contains no identifier.
Our web server keeps access logs for security, debugging, and abuse handling. They contain masked IP prefixes, timestamps, HTTP details, and request paths, but not uploaded file contents. The deployment is configured to rotate these logs daily and retain up to 14 rotations.
Payments
All payments are handled by Stripe. We never see your card number, expiry, or CVC — those go straight from the browser to Stripe's servers. Stripe stores the checkout and payment record on their side. Depending on the Checkout configuration, that record may include your email, billing address, tax-calculation details, and payment-method metadata, governed by Stripe's privacy policy. Stripe sends pdftap checkout and payment-status identifiers needed to grant paid access. These do not contain your full card number.
To make fulfillment reliable, pdftap stores an opaque Checkout Session identifier, a one-way hash of the browser claim token, entitlement timestamps, and Stripe event identifiers. We do not store the raw claim token, customer email, payment-method details, or document information in this billing database. Cleanup runs during billing activity: pending records become eligible after 48 hours, expired day-pass records after 30 additional days, and processed event identifiers after 30 days. On a quiet service, an eligible record can remain until the next cleanup pass.
Service providers
Hetzner Online GmbH provides the server infrastructure that serves the application and processes PDF requests. Stripe provides the payment checkout and billing infrastructure described above. Fonts are self-hosted (or served via the system font stack), so we do not phone home to a font CDN. There are no third-party error trackers, chat widgets, embedded video players, or social pixels.
GDPR data portability
pdftap does not currently provide user accounts or a document history. Depending on your use, personal data may still exist in operational logs, pdftap's short-lived entitlement records, and Stripe's payment records. Applicable law may give you rights to access, correct, delete, restrict, or export personal data.
To make a privacy request, email us using the address below. We may need enough information to locate the relevant payment or log record and verify that the request belongs to you.
Contact
For privacy questions, email support@ideasallday.com. We answer.