1. Introduction
PrivacyScanPDF (“we”, “us”, “our”) operates the website privacyscanpdf.comand the browser-based PDF and image toolkit available there (the “Service”). We are a privacy-first document tool provider: every conversion, scan, merge, split, compress, watermark, rotate, and OCR operation is performed entirely inside your web browser using client-side JavaScript, WebAssembly, and your device's CPU.
This Privacy Policy describes how we handle information when you visit or use the Service. Because the Service is browser-based and does not require you to upload files to our servers, the policy is short on collection and long on commitments — we collect as little as possible by design.
This policy applies to visitors, free-tier users, Pro subscribers, Lifetime Deal customers, and Enterprise customers. Where a separate Data Processing Agreement (DPA) applies to Enterprise customers, the DPA controls and is available at /dpa.
2. Information We Collect
We do not collect personal data about you. The Service is designed so that your documents, your usage history, and your browsing behavior are not transmitted to us in a form that identifies you.
2.1 Your Files and Document Contents
When you use any PrivacyScanPDF tool, the file you select is opened directly in your browser tab. It is parsed, transformed, and offered back to you for download — all locally. Your file is never uploaded to our servers, our databases, our logs, or any third-party processing endpoint. Closing the tab clears the file from your device memory.
We do not have access to your file names, file contents, file sizes, page counts, scan results, or any output you generate. We cannot recover a document you converted, even if you ask us to — we simply never had it.
2.2 Information You Provide Voluntarily
If you contact us by email (e.g. at support@privacyscanpdf.com or privacy@privacyscanpdf.com), we receive the email address and content you choose to send. We use that information only to respond to your request and retain it for as long as needed to resolve the conversation.
If you fill out the Enterprise lead-capture form on /enterprise, we store the name, email, company name, company size, and message you provide in our database so our sales team can follow up. You can request deletion of this record at any time using the contact details in Section 11.
2.3 Billing Information
When you upgrade to Pro or purchase a Lifetime Deal, payment is processed by our payment processor, Lemon Squeezy. We never see, store, or transmit your card number, CVV, or full cardholder data. Lemon Squeezy provides us with a limited set of transaction metadata (order ID, plan name, customer email, country, and subscription status) so we can provision your access. See Section 5 for details.
2.4 Automatically Collected Technical Information
Our hosting infrastructure may log standard request metadata (IP address, user agent, request timestamp, and HTTP status) for security, abuse prevention, and uptime monitoring. These logs are retained for no more than 30 days and are not associated with any user account or document.
If you have consented to analytics via our cookie banner, we collect aggregated, pseudonymous usage statistics as described in Section 3.
3. How We Use Information
Because we do not collect personal data from your use of the Service, there is very little to “use”. Specifically:
- We use server logs only for security, abuse prevention, and reliability monitoring.
- We use the email address you provide when contacting us or submitting an Enterprise lead solely to respond to that inquiry.
- We use the limited transaction metadata returned by Lemon Squeezy solely to provision and administer your subscription, send renewal/cancellation notices, and provide support.
- If you have consented to analytics, we use aggregated, pseudonymous data to understand which tools are most used, where users drop off, and how to improve the Service.
We do not:
- Sell or rent your personal data to anyone.
- Share your personal data with advertisers.
- Use your documents or their contents for any purpose — including AI training, product analytics, or quality assurance.
- Build personal profiles or behavioral advertising segments.
5. Third-Party Services
We rely on a small number of carefully chosen third parties to operate the Service. Each is a separate controller or processor of any personal data they collect, under their own privacy policy.
5.1 Lemon Squeezy (Payments)
Lemon Squeezy is our Merchant of Record for Pro subscriptions and Lifetime Deal purchases. They process your payment, handle VAT/Sales Tax, and issue invoices. Lemon Squeezy receives your name, email, billing address, and payment instrument — we never see your full card data. Privacy policy: lemonsqueezy.com/privacy.
5.2 Google Analytics (Analytics, Opt-In)
If you consent to analytics cookies and GA4 is enabled, Google Analytics collects pseudonymous usage data (page view, session duration, referrer, approximate geolocation based on IP). Google is a controller for this data; its privacy policy is at policies.google.com/privacy.
5.3 Google AdSense (Advertising, Opt-In)
If you consent to advertising cookies and AdSense is enabled, Google may set advertising cookies and serve interest-based ads. You can opt out of personalized advertising at adssettings.google.com.
5.4 CDN & Hosting
The site is hosted on a managed Next.js hosting provider and serves static assets (fonts, JavaScript, images) through a CDN. These providers may log request metadata (IP, user agent) for security and performance, in line with their own privacy policies.
5.5 Sub-processors for Enterprise Customers
For Enterprise customers who have signed a DPA, the current list of sub-processors is maintained in Section 7 of our DPA. We will give at least 30 days' notice before adding or replacing a sub-processor.
6. Data Retention
We do not retain your documents. Files are processed in your browser and never persisted on our infrastructure. There is nothing to delete because there was nothing to store.
For the small amount of data we do process:
- Server logs: retained for up to 30 days for security and abuse prevention, then automatically purged.
- Enterprise leads: retained for up to 24 months after the last contact, unless you ask us to delete them sooner.
- Billing metadata from Lemon Squeezy: retained for the duration of your subscription plus the period required by applicable tax and accounting law (typically 7 years). Card data is held by Lemon Squeezy, not us.
- Support emails: retained for up to 24 months after the last message in the thread.
7. Your Privacy Rights
Depending on where you live, you may have specific rights over your personal data. Because we collect so little, exercising these rights is straightforward — and in many cases there is nothing for us to return because we never had the data.
7.1 GDPR (European Economic Area, United Kingdom, Switzerland)
Under the GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure— ask us to delete your personal data (“right to be forgotten”).
- Restriction — ask us to limit processing of your data in certain circumstances.
- Portability — receive your personal data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — at any time, for processing based on consent (such as analytics cookies).
- Lodge a complaint with your local data protection authority. A list of EU supervisory authorities is at edpb.europa.eu.
7.2 CCPA / CPRA (California, USA)
Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to:
- Know — the categories and specific pieces of personal information we collect, the sources, the purpose, and the categories of third parties with whom we share it.
- Delete — request deletion of personal information we collected from you.
- Opt-out of sale or share — we do not sell or share personal information as defined by the CCPA, so this right is automatically honored.
- Limit use of sensitive personal information — we do not process sensitive personal information as defined by the CPRA.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
7.3 LGPD (Brazil)
Under the Lei Geral de Proteção de Dados, Brazilian data subjects have rights substantially equivalent to those under the GDPR: confirmation of processing, access, correction, anonymization, portability, deletion of personal data, and information about sharing. You may also revoke consent at any time and lodge a complaint with ANPD (gov.br/anpd).
7.4 DPDP Act (India)
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), users in India (referred to as “Data Principals”) have the right to:
- Access and correction — obtain a summary of the personal data we process about you and request correction of inaccurate or incomplete data.
- Erasure— request deletion of your personal data, also known as the “right to be forgotten”.
- Grievance redressal — contact our Grievance Officer (below) to resolve any complaint concerning the processing of your personal data.
- Nominate another individual — to exercise your rights under the DPDP Act in the event of your death or incapacity.
- Withdraw consent — at any time, for any processing based on your consent. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Grievance Officer: PrivacyScanPDF has appointed a Grievance Officer as required by the DPDP Act. You may reach them at privacy@privacyscanpdf.com. We will acknowledge complaints within 24 hours and resolve them within the timeframes prescribed under Indian law.
7.5 PIPEDA (Canada)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), individuals in Canada have the right to:
- Know what personal information we hold about them and the purposes for which it is collected, used, or disclosed.
- Access — request a copy of the personal information we hold, at minimal or no cost.
- Challenge accuracy — require us to correct inaccurate or incomplete personal information.
- Withdraw consent — subject to legal or contractual restrictions, withdraw consent to the collection, use, or disclosure of personal information.
If you believe we have not respected your rights under PIPEDA, you may file a complaint with the Office of the Privacy Commissioner of Canada (OPC). We encourage you to contact us first so we can attempt to resolve your concern.
7.6 APPI (Japan)
Under the Act on the Protection of Personal Information (APPI), individuals in Japan have the right to:
- Disclosure — request disclosure of the personal information we hold about them and the purposes of use.
- Correction — request correction of personal information that is inaccurate or incomplete.
- Suspension of use — request that we suspend the use or erase the personal information where it is being processed outside the disclosed purposes or obtained improperly.
Complaints may be lodged with the Personal Information Protection Commission (PPC), Japan's data protection authority.
7.7 PDPA (Singapore)
Under the Personal Data Protection Act (PDPA) of Singapore, individuals have the right to:
- Access — request access to the personal data we hold about them and information about how it has been used or disclosed in the past 12 months.
- Correction — request correction of any personal data that is inaccurate or incomplete.
- Withdraw consent — withdraw consent for the collection, use, or disclosure of personal data given previously.
Concerns about our handling of your personal data may be raised with the Personal Data Protection Commission (PDPC) of Singapore.
7.8 POPIA (South Africa)
Under the Protection of Personal Information Act (POPIA), data subjects in South Africa have the right to:
- Object to processing — for legitimate reasons, object to the processing of their personal data, including direct marketing.
- Request correction or deletion — ask us to correct, update, or destroy personal data that is inaccurate, irrelevant, excessive, or obtained unlawfully.
- Access and information — request confirmation of whether we hold personal data about them, with details of the processing activities.
Complaints may be lodged with the Information Regulator (South Africa) if you believe your rights under POPIA have been violated.
7.9 Australian Privacy Act 1988
Under the Privacy Act 1988 and the Australian Privacy Principles (APPs), individuals in Australia have the right to:
- Access — request access to the personal information we hold about them.
- Correction — request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Complain — lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if they believe we have mishandled their personal information.
7.10 Other Jurisdictions
If your jurisdiction grants additional rights not listed above, we will honor those rights on the same basis as the rights set out in this section.
7.11 How to Exercise Your Rights
Email privacy@privacyscanpdf.com with your request. We will respond within 30 days (or as required by applicable law). To protect against unauthorized access, we may verify your identity using reasonable means — we will never ask for your full identity document or more information than necessary.
8. International Data Transfers
Because the Service is browser-based and we do not collect your files, the question of international transfer of your documents does not arise — they never leave your device.
The limited data we do process (server logs, Enterprise leads, support emails, billing metadata) may be processed by us or our third parties in the United States, the European Union, the United Kingdom, India, or other jurisdictions. Specifically:
- Lemon Squeezy processes payment data in the United States. For EU/UK customers, transfers are protected by Standard Contractual Clauses.
- Google (Analytics, AdSense) processes data in the United States and other regions. Google offers EU-US Data Privacy Framework coverage and Standard Contractual Clauses for in-scope transfers.
- Our hosting infrastructure may process request metadata in multiple global regions. Server logs are short-lived (see Section 6) and do not contain your documents.
For Enterprise customers with a signed DPA, international transfer mechanisms (SCCs, UK IDTA addenda, and the EU-US Data Privacy Framework) are listed in Section 9 of the DPA.
9. Children's Privacy
The Service is not directed to children under the age of 13 (or the minimum age required to consent to data processing in your jurisdiction, whichever is higher). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please email privacy@privacyscanpdf.com and we will promptly delete it.
9.1 COPPA (United States)
Under the Children's Online Privacy Protection Act (COPPA), operators of online services directed to children under 13 must obtain verifiable parental consent before collecting personal information from them. We do not knowingly collect personal information from children under 13. Our Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe we have collected personal information from a child under 13, please contact us immediately at privacy@privacyscanpdf.com and we will delete it.
Upon receiving a credible notice that we have collected personal information from a child under 13, we will delete the information from our systems within a reasonable timeframe (typically 10 business days) and confirm completion to the requesting parent or guardian. If you are a parent or guardian and wish to verify whether we hold personal information about your child, you may contact us at the email above and we will respond in accordance with COPPA and applicable state laws.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If we make material changes — for example, if a new category of data were to be collected — we will provide prominent notice (such as an in-app banner or email to subscribers) at least 7 days before the change takes effect.
You can review the history of this policy by contacting us at privacy@privacyscanpdf.com.
11. Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or your personal data, please contact our Privacy & Data Protection team:
- Email: privacy@privacyscanpdf.com
- General support: support@privacyscanpdf.com
- Enterprise / DPA requests: sales@privacyscanpdf.com
We aim to respond to all privacy inquiries within 5 business days. Pro and Enterprise customers receive priority handling.