Skip to content

Privacy policy

Last updated: August 8, 2026

The legal companion to our technical privacy page: what little personal data this site touches, and the rights you have over it.

The short version

Your files are opened and edited on your own device and are never sent to us, so most of what a privacy policy usually has to cover simply does not happen here.

We hold personal data in three cases only: you sign in, you buy a pass, or you send us a message. Everything else, including our page-view counting, is anonymous by construction.

How the file claim is enforced, and how to verify it yourself, is on the technical privacy page.


Who is responsible

discreetpdf.com is independently operated by its developer. A US limited liability company is being formed to take over operation and will be named here once registration completes. Until then, where the EU or UK GDPR applies, the developer is the controller of the personal data described on this page.

For anything in this policy, reach us through the contact page.

What we collect, and when

The complete list, by situation. If a situation is not listed here, we collect nothing in it.

When you just visit

The pages set no tracking cookies, load no analytics script, and build no profile of you. When a page is served, we count the view in a record that holds four things: which page, a coarse source label such as "google" or "direct" (never the full linking address), a two-letter country code, and the number one, stamped with the time it was written. It contains no IP address, no browser details, and no identifier of any kind, so there is nothing in a record that links it to you or to any other record. We built them so they cannot be joined; we keep the fields coarse precisely because a rare country and a rare page at an unusual moment would otherwise be a small crowd.

Separately, Cloudflare, the infrastructure the site runs on, keeps standard request logs (IP address, browser user agent, response status) on its own systems for security and abuse protection, as virtually every host does. We read that log data only as aggregate totals, never per visitor.

When you use the PDF tools

Nothing. Your file is processed inside your browser and its contents never reach us. Anything the editor remembers for you (recent files, unsaved work, saved signatures) is stored only in this browser on this device; you can turn that off or clear it at any time, and it is never transmitted.

If you sign in (optional)

Signing in with Google or GitHub gives us your verified email address, the account ID your provider assigns, and the display name it reports. We store those in your account record along with any pass licenses, the date the account was created, and when each connected provider was last used to sign in, plus one record per sign-in: when the session started, when it was last used, and your browser's user-agent string capped at 200 characters, so you can recognize your own sessions and sign out of all of them at once. Signing in with a passkey instead tells us nothing new about you: it only proves you hold a key your account already lists. Each passkey you add is stored as its public key and credential ID, a code for the kind of authenticator that made it, how it connects, which optional features it supports, a signature counter, whether your device reports it as backed up, and the dates it was added and last used. We never receive the private key, your PIN, or your biometrics. Sessions are kept with a cookie that exists only to keep you signed in and expires after 7 days (short-lived cookies protect the sign-in handshake itself: ten minutes for Google and GitHub, five for a passkey, each deleted as soon as sign-in finishes). Your browser also keeps a local copy of your account details so the page can show you as signed in instantly; it never leaves your device and is removed when you sign out. If you add an extra email address to your account, we add it only once you confirm it through the link we send; until then the address exists only in a pending-confirmation record (15 minutes) and an anti-abuse counter (24 hours), both of which expire on their own.

If you buy a pass

Payments run through Paddle, which sells the pass as merchant of record. Your card details are entered on Paddle's hosted checkout and never touch our server. On our side we store the email address you used at checkout (it becomes the email on your account record, even if you have not signed in yet) along with the Paddle customer and subscription IDs, an internal license ID, which pass you bought, its status, and when it runs out; a short-lived reference to the checkout session is kept for 30 days to prevent duplicate processing. We also send you a purchase confirmation email, with no tracking pixels in it.

If you contact us

The contact form sends us your name, email address, subject, and message as an email so we can reply. We do not copy the message into any database. To keep the form from being abused, we keep a counter keyed by your IP address for one hour. The passkey sign-in endpoints keep the same kind of counter, also keyed by your IP address, for ten minutes. Those two counters are the only places an IP address appears in our own storage, and both expire on their own.

Why we may process it (legal bases)

Where the EU or UK GDPR applies: account, session, license, and billing records are processed because they are necessary to provide the service you asked for (Article 6(1)(b), contract). Contact messages, abuse protection, rate limiting, and aggregate infrastructure logs rest on our legitimate interest in answering you and keeping the service secure and available (Article 6(1)(f)). The page-view record is designed to contain no personal data at all. We do not rely on consent today, because we do nothing that would need it.

Who else touches your data

We do not sell or rent your personal data, and we do not share it beyond the services named here. Cloudflare and Resend process it on our behalf, under their data-processing agreements, and only for the purposes above. The other two are not our processors and do not act on our instructions: Paddle sells the pass in its own name as merchant of record, and a sign-in provider is involved only if you choose one. Each of those decides for itself how it handles what the sale or the sign-in gives it.

  • Cloudflare: runs the site's hosting, storage, and networking, and keeps the infrastructure request logs described above.
  • Resend: delivers our transactional email: contact-form messages, email-confirmation links, and purchase confirmations.
  • Paddle: sells the passes as merchant of record and handles payment, tax, and subscription billing. Card details stay with Paddle.
  • Google / GitHub: act as your sign-in provider, only if and when you choose one. They are independent controllers rather than our processors: what they do with the sign-in is governed by their own privacy policies, not by any agreement with us.

These providers are based in the United States and may process data there and in other countries. Where EU or UK data-protection law applies, transfers to Cloudflare and Resend are covered by their data-processing agreements with us, including standard contractual clauses where required. Paddle and the sign-in providers are not our processors, so their transfers rest on their own arrangements, set out in their privacy policies.

How long we keep it

  • Account, license, and billing records: until you delete your account. Deletion is self-service on your account page, takes effect on our side straight away (a signed-in session elsewhere can take up to a minute to fall over), and also cancels any active subscription. Session records expire on their own after 7 days.
  • Page-view records: kept for 90 days in the analytics store, then dropped. Nothing about a single view outlives that window; the only things that can outlast it are plain aggregate counts with no personal data in them.
  • Paddle keeps transaction records on its side for tax and accounting reasons even after you delete your account; those records stay with Paddle, but nothing on our side is linked to them any more.
  • Contact messages: kept in our mailbox for as long as needed to handle your request.

Your rights

If EU or UK data-protection law applies to you, you have the right to ask for access to, correction of, or erasure of your personal data; to restrict or object to processing; to receive a copy in a portable format; and to complain to your supervisory authority. Exercising any of these is free.

If you never signed in, bought a pass, or wrote to us, we hold nothing that can identify you, so there is usually nothing to look up, hand over, or erase. The counting records cannot be tied to you even by us. If you have an account, most rights are self-service: the account page shows the core data we hold, lets you sign out everywhere, and can delete the whole account outright.

For everything else, use the contact page; we answer within the time the law sets (one month for GDPR requests, which the law lets us extend by two further months for complicated ones, in which case we tell you why). Requests reach the same mailbox as everything else and are handled by hand, not by a ticketing system.

California

We do not sell personal information and do not share it for cross-context behavioral advertising, and we never have. California residents have the rights to know, delete, and correct their personal information, and to not be discriminated against for exercising them. Use the contact page. Because we hold so little, the most common honest answer will be that there is nothing on file about you.

Children

The service is not directed at children and we do not knowingly collect personal data from them; we collect almost none from anyone. Signing in requires a Google or GitHub account, which carry their own age requirements.

Changes to this policy

When this policy changes, we update this page and the date at the top. Anything material, above all any change to where your files are processed, is announced on the site in advance, as our privacy pledge promises. We never make that kind of change quietly.

Related pages

  • Privacy: the technical page: how the no-upload claim is enforced, and how to check it yourself.
  • Our privacy pledge: the version-stamped promise about your files and any future paid features.
  • Terms of service: the rules for using the site.

All PDF tools

All free, all in your browser. Pick the task you need.