Privacy Policy
Last updated:
π The short version
- Core editing, page, signing, protection, and many conversion workflows process selected files in your browser.
- AI features may send extracted text, rendered page images, uploaded images, or a PDF through EditPDF AI server routes to configured processing providers.
- The application code does not write document content to its database or object storage. Processing providers handle request data under their own terms and policies.
- Payment fields are provided by Stripe; EditPDF AI stores subscription identifiers and status rather than card numbers.
1. What we collect
When you use EditPDF AI, we may collect:
- Account information when you sign up (name, email address) via Clerk
- Usage data: which tools you use and how many AI features you access per day
- Payment fields and billing details are handled by Stripe. EditPDF AI stores the customer, subscription, price, and status identifiers needed to administer access; it does not receive a full card number from those fields.
- Configured analytics events such as page paths, page titles, referrers, and deliberately named product events
Document content is handled only when needed for the core browser workflow or AI feature you trigger. The application does not insert PDF, image, or extracted-text content into its Supabase tables or an object-storage bucket.
2. How your files are processed
Browser-based PDF tools. Core editing and page tools identified as browser-based process the selected document on your device and do not send its contents through an EditPDF AI document-processing route. Some tools load required code, workers, or fonts from third-party content delivery networks.
Conversion tools. Conversion processing depends on the tool. Browser-based conversions rebuild the output on your device. AI-assisted PDF-to-Word, PDF-to-Excel, and PDF-to-PowerPoint actions send extracted text through an EditPDF AI server route to the configured AI provider.
OCR. PDF OCR opens and renders the source PDF in your browser. When a page needs OCR, the rendered page image is sent through an EditPDF AI server route to the configured AI provider; the application does not deliberately store the source PDF or OCR image in its database or object storage.
AI tools. AI tools send only the content required for the selected action, which can include extracted text, rendered page images, uploaded images, or a PDF, through EditPDF AI server routes to configured processing providers. AI output can be inaccurate or incomplete. Review results against the source document before relying on them, especially for legal, medical, financial, or other high-stakes use.
Summaries, chat, translations, mind maps, quizzes, and other text-based AI actions send extracted document text. Scan detection and visual form-field detection send rendered page images. Form-filling workflows can send user-entered details, an identity-document image, a rendered form page, or a complete PDF when document-level context is requested.
Some form-processing routes can also forward a PDF to the configured document-processing backend. Request bodies are handled by the application server and applicable processing provider. This codebase does not establish or control a provider-wide deletion schedule, so the provider's own retention terms also apply.
3. Cookies and analytics
The site includes Vercel Speed Insights for web-performance telemetry. When their environment identifiers are configured, it also loads Cloudflare Web Analytics, PostHog, and Google Analytics 4.
PostHog is configured with in-memory persistence, cookieless page views and named product events, person profiles set to βnever,β and session recording disabled. Google Analytics starts with analytics and advertising storage denied, Google signals disabled, and advertising personalisation disabled. EditPDF AI's analytics calls remove URL query strings and do not deliberately send document content, file names, or email addresses.
Authentication (sign-in sessions) uses cookies managed by Clerk. These are necessary for keeping you signed in and are not used for advertising.
4. Third-party services
- Clerk β authentication and user account management (clerk.com)
- Stripe β payment fields and subscription processing. EditPDF AI stores Stripe customer/subscription identifiers, price identifiers, and subscription status.
- Anthropic (Claude) β processing of extracted text, rendered page images, uploaded images, and PDFs for the AI features described above. Anthropic's terms and privacy policy apply to data its API receives.
- Configured document-processing backend β form detection or filling routes may forward a PDF to the backend URL configured for that service.
- Supabase β database for subscription status and daily AI usage counts. No document content is stored.
- Vercel Speed Insights β web-performance telemetry.
- Cloudflare Web Analytics β traffic and performance measurement when its site token is configured.
- PostHog β cookieless aggregate page views and deliberately named feature-usage events; session recording and individual profiles are disabled.
- Google Analytics 4 β cookieless aggregate page views and traffic attribution; advertising storage and personalisation are disabled.
- Third-party content delivery networks β some browser tools load required PDF workers, conversion libraries, or fonts. Those requests fetch software assets; EditPDF AI does not deliberately attach the selected document to them.
5. Data retention
Clerk manages account identity. EditPDF AI's database stores subscription records and one dated AI usage-count row used to enforce the free daily allowance.
No automated deletion schedule for AI usage-count rows is implemented in this codebase. Contact support to request review or deletion of account-associated data, subject to records that must be retained for subscription or service administration.
The application does not deliberately persist PDF, image, file-name, or extracted-document content in its database or object storage. Server and processing-provider handling remains subject to their operational logs and retention policies.
6. Your rights
Depending on applicable law, you may be able to request:
- The right to access the data we hold about you
- The right to request deletion of your account and associated data
- The right to correct inaccurate information
- The right to data portability
To make a request, email us at support@editpdfai.com. The request will be reviewed and the data and options available for the associated account will be explained.
7. Security
Production URLs are normalized to HTTPS. Subscription and AI usage database access uses server-side credentials. No security control makes processing risk-free; review the feature-specific data flow before submitting sensitive material to an AI feature.
8. Children
EditPDF AI is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us personal information, please contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced on this page with an updated date. Continued use of the service after changes constitutes acceptance.
10. Contact
For privacy questions, data deletion requests, or any concerns:
EditPDF AI