Ten browser-local tools are live. OCR, paid workflows, uploads, and billing remain disabled until production acceptance passes.

Updated July 23, 2026

Privacy notice

PDFOnline privacy and document-retention summary.

Product-ready technical notice; counsel review is required before accepting paying customers.

Data we use

Account data includes email, session records, Workspace membership and security events. Billing data includes plan, entitlement, provider event identifiers, amounts and receipts. Workflow metadata includes opaque identifiers, state, versions, page counts, cost buckets and error codes.

Customer content includes uploaded PDFs, page renderings, OCR output, extracted candidates, corrections and exports. Filenames, document text, extracted values, hashes, signed URLs and email addresses are excluded from product analytics events.

Browser-local tools

The one-off PDF tools process selected files on your device. PDFOnline does not receive their file bytes, filenames, page count, thumbnails, content hash or extracted text.

Cloud invoice workflow

The production cloud workflow remains disabled while release acceptance is No-Go. Enabling uploads requires an account, explicit confirmation, and disclosure of the verified processing region, estimated credits and retention before bytes are accepted. The processing contract permits only PDFOnline's self-hosted stack.

Source and derived content expires 24 hours after processing first reaches a terminal state, or earlier on request. Online objects, derived files, multipart uploads and backup expiry must all be verified before a deletion receipt is final.

Service providers

The planned service uses infrastructure, transactional-email and hosted payment providers. Full card numbers and CVC values remain outside PDFOnline. The final subprocessor list and exact regions must be frozen in the release manifest before cloud processing is enabled.

Your choices

Controls support sign-out, session revocation, batch-content deletion and account closure. A durably accepted closure revokes sessions, fences new business data, starts subscription cancellation where applicable, and sends every batch through the verified deletion lifecycle.

Profile, authentication, OAuth, session and payment-customer identity data is deleted or irreversibly anonymized at the 30-day boundary. A content-free receipt capability reports cancellation, deletion and anonymization progress. PDFOnline stores only its keyed digest and never places the raw capability in database records, logs or URLs.

The minimum financial records retained where legally required are:

  • payment-order amount, currency, status, policy and paid-at time;
  • invoice amount, currency, billing period and paid-at time;
  • refund or dispute amount, currency, status and event time;
  • credit-ledger amount, type, expiry and policy reference;
  • content-free financial audit events; and
  • a subscription reference only while requested cancellation is retrying.

Contact privacy@pdfonline.io for access, correction or deletion requests. Do not email customer PDFs unless support has provided an approved secure channel.

Privacy notice