1. Scope
This notice applies to PDFit.pro websites, accounts, Community, current online PDF tools, the PDFit Core Job API, and support interactions. Additional notices may apply to future Standalone, Connected, billing, Workspace, OCR, or AI features before those features are enabled.
2. Information PDFit processes
Uploaded documents and results
PDFit receives files you deliberately submit to a processing tool. Anonymous tool and Workspace files remain temporary. When you are signed in and use Workspace, PDFit stores the uploaded document and each completed edit as a recoverable version in your tenant-isolated document library. PDFit does not use document contents for advertising or unrelated analytics.
Job and operation metadata
The service processes the selected operation, safe option values, approximate file and page limits, timestamps, job status, result type, expiration, and random access-token hashes needed to deliver and protect a result.
Technical and security data
Web and application logs may contain IP address, user agent, requested endpoint, timestamp, response status, rate-limit events, safe error category, and security/audit events. Credentials and full job access tokens should not be written to logs.
First-party product analytics
PDFit may record a bounded event when a live tool opens, a tracked tool card is selected, a tool form is submitted, a JavaScript-managed result download begins, or a visitor selects a launch offer on Pricing. The event contains an allowlisted event name, tool or pricing identifier, placement, one-time random event ID, account association when already signed in, and NovaCore tenant/plan context. The browser payload does not include a URL, referrer, filename, document data, credential, IP address, user agent, or persistent visitor ID.
Account and support data
If you register, NovaCore stores your PDFit tenant, login, display name, optional email, password hash and salt, role, saved theme and language, security state, session records, and account audit events. PDFit stores document names, version metadata, integrity hashes, processing actions, and tenant-scoped storage references for signed-in Workspace documents. The document library exposes this information only to the authenticated workspace owner.
When you use the protected contact form, NovaCore stores the name, reply email, topic, product, message, request status, timestamps, optional signed-in account reference, IP address, and user agent needed to answer the request, preserve tenant isolation, enforce limits, and investigate abuse. The form does not accept document attachments, and its contents are not sent to product analytics or 4UL.ink.
Community data
Anyone can read published Community posts. When you use Community with an account, PDFit stores the post type, title, description, category, public status, account author reference, vote, report reason, optional report details, and moderation status needed to operate and protect the feature. Do not place documents, document contents, personal data, credentials, passwords, access tokens, or other confidential information in a post or report.
Billing data
When you start or complete paid beta checkout, PDFit and NovaCore process your account reference, product and offer codes, amount, currency, Stripe customer, Checkout Session and payment references, payment status, timestamps, refund or dispute state, and the applicable 365-day clean_exports and unlimited_processing entitlements. Stripe receives and processes payment details; PDFit does not receive or store full card numbers or security codes.
3. Why the information is used
- Perform the document operation you requested.
- Protect result access, enforce limits, and prevent abuse.
- Recover or expire queued jobs and remove temporary data.
- Measure reliability, capacity, and privacy-safe feature usage.
- Publish Community posts and votes, review reports, and moderate abuse.
- Investigate failures, security events, and support requests.
- Reconcile Clean Pass payments, refunds, disputes, expiry, and clean-export access.
- Meet applicable legal obligations and enforce the Terms.
4. Retention and deletion
Synchronous anonymous tool inputs and results are intended to be removed after delivery, with a cleanup fallback. Job API files expire under the active retention policy and may be deleted earlier through the protected delete endpoint. Signed-in Workspace documents remain in the document library until moved to Trash. Trashed documents are scheduled for permanent deletion after 30 days and can be restored before that deadline.
The account History screen returns up to the latest 100 operation events. Document lifecycle audit records and underlying account or security audit records may be retained longer for service integrity, abuse prevention, disputes, or legal obligations. Community posts and votes remain until removed through moderation, account/data handling, or a verified request; reports and moderation records may be retained longer to prevent repeated abuse and document decisions. Additional notices will be published before connected cloud backup, OCR, or AI features transmit document contents to another provider.
5. Platform and service providers
PDFit uses NovaCore contracts for shared platform functions such as tenant context, accounts, sessions, contact-request storage and workflow, Community persistence and moderation, plans, usage, analytics, and audit. Hosting and infrastructure providers process technical data needed to operate the service.
The live interface requests its versioned language pack from an exact same-origin NovaCore endpoint. That request includes the selected two-letter language in the URL but omits browser credentials; the PDFit proxy also strips Cookie and Set-Cookie. NovaCore may apply a tenant-specific wording override, but the request does not contain a document, account identifier, filename, referrer, or persistent visitor ID. A matching local catalog snapshot is used by Standalone installations and when Core is unavailable.
Selected tool-entry links use owned 4UL.ink / NovaLink aliases. The link service may record the alias, timestamp, approximate country, device category, referrer host, and technical request data to measure click-throughs and campaigns. It does not receive the PDF uploaded to PDFit.
The PDFit first-party event endpoint is separate from 4UL.ink. It is same-origin, limited to 2 KB, accepts only a fixed event/tool/placement vocabulary, uses a one-time ID only for deduplication, and deliberately omits IP address and user agent from its NovaCore analytics and audit records. Ordinary infrastructure access logs may still process the technical request data described above.
Stripe processes Clean Pass payment data as PDFit's payment provider. Connected OCR, AI, translation, backup, or email providers will be named or described before their features transmit user data.
6. Cookies and local browser data
Anonymous tools do not require an advertising profile. First-party analytics does not create a tracking cookie or store an identifier in localStorage or sessionStorage, and the browser module respects enabled Global Privacy Control or Do Not Track signals. The language selector may store only the selected two-letter language code under pdfit.language in localStorage so the interface stays in the chosen language; the value is not a visitor identifier and is not included in analytics. The localization catalog is cacheable as a public product resource and does not use the account cookie. If you register or sign in, PDFit uses an essential, host-only NovaCore session cookie with HttpOnly, Secure, SameSite=Strict, expiry, and root-path controls. Local browser processing may be used for page previews; for example, Organize renders thumbnails on the user's device before upload.
Workspace may save unfinished object layers in this browser's IndexedDB so a draft can be recovered after a refresh, tab closure, or browser interruption. A local draft can include added text, coordinates, drawing or eraser strokes, and image blobs deliberately added as layers. The original PDF is not copied into this recovery store. Drafts expire after seven days, are limited to the eight most recently used documents, are removed after the composition is successfully applied, and can be discarded from the recovery notice or by clearing site data. These local drafts are not analytics and are not transmitted merely because they were saved in the browser.
7. Security
PDFit uses transport encryption, strict upload validation, resource and rate limits, isolated job identifiers, hashed access tokens, protected result routes, tenant isolation, Community role and origin checks, security headers, logging controls, and automatic cleanup. No internet service can guarantee absolute security, so users should avoid submitting a document when the current tool and retention model are unsuitable for its sensitivity and should treat Community as public.
8. Your choices and rights
You may use basic tools and read Community without an account, enable Global Privacy Control or Do Not Track, update current profile preferences in Settings, sign out to revoke the active session, choose not to upload a document or publish a post, report Community content, delete a protected job when the API supports it, and avoid optional 4UL.ink attribution by using the direct canonical tool URL. Tool functionality remains available when the analytics module is blocked. Requests for account access, Community-post correction or deletion not available in the interface, restriction, or another applicable privacy right can be submitted through the protected contact form. Verification may be required before fulfilling a request.
9. Children
PDFit is not directed to children who cannot lawfully consent to online services in their location. Do not submit a child's personal information without appropriate authority.
10. Changes and contact
Material changes will update the effective date and appear in the Changelog when appropriate. Submit privacy questions and rights requests through the protected contact form. Do not include confidential documents, passwords, API keys, or access tokens.