Privacy Policy

Last updated: 31 August 2026

pdfdw was built around a simple architectural decision: whenever a job can be done on your own device, it is. This policy explains exactly what that means, what happens in the cases where it is not possible, and what rights you have over your data.

The short version

  • • Merge, split, rotate, reorder, delete pages and the visual PDF editor run entirely in your browser. Those files are never uploaded, so we could not read them if we wanted to.
  • • Tools that need a server receive your file, process it, return the result and delete it immediately. We keep no archive of your documents.
  • • We never use your document contents for advertising, and never share them with advertising partners.
  • • We never see your card details. Payments are handled by Lemon Squeezy as merchant of record.
  • • Advertising cookies are set only if you accept them.

1. Who we are

pdfdw provides online PDF tools at https://pdfdw.com. For the personal data described here we act as the data controller. You can reach us at privacy@pdfdw.com.

2. How we process your files

Our tools fall into three categories, and the difference matters, so we describe each one rather than making a single blanket claim.

A. Browser-based tools — nothing is uploaded

These run entirely inside your browser using JavaScript libraries loaded into the page. Your file is opened, changed and saved on your own device:

Because the document never reaches our infrastructure, we cannot view, store, scan or disclose it — including in response to a legal request. This is a property of the architecture, not a promise about our conduct.

One clarification about the editor: adding content to a page happens entirely on your device, and the finished file is assembled in the browser. Signing in is still required and a credit is still used, because that is how the tool is paid for — but the request that checks your account carries only the layout you designed (positions, sizes, colours, the text you typed), never the document itself. Its separate "Replace text" mode does upload, and is covered in section C.

B. Server-side tools — processed, returned, deleted immediately

Some work cannot run in a browser: optical character recognition, PDF/A conversion, compression and Office conversion all need server-side engines. For these, your file is uploaded, processed and the result returned to you, after which the file is deleted immediately. Tools in this category include compression, OCR, password protection, watermarks, page numbers, PDF/A conversion, cloud merge, batch processing and the Office and PDF converters.

We do not retain copies for training, analytics or quality review, and we do not index document contents. Uploads are size-limited and, in most cases, streamed through memory rather than written to disk.

C. Text Replacement — brief temporary storage

The Edit PDF Text tool is the one exception worth spelling out, because it is interactive: it has to hold your file between the moment you draw a selection and the moment you apply the edit. Replacing existing words means reading the original page — its fonts, its spacing, the colour behind the text — which is work a browser cannot do, so the file has to reach us. The same applies to the "Replace text" mode built into the PDF editor, which uses this identical machinery. For both:

  • Your PDF is written to a private server directory that is not reachable from any public URL.
  • Access runs through authenticated endpoints, so another signed-in user cannot reach your file.
  • Stored names carry a random prefix, so filenames cannot be guessed.
  • The upload is deleted as soon as your edits are applied, the output is deleted once downloaded, and any stragglers are purged automatically.

D. Third-party processing engines

Server-side jobs are executed by processing engines we operate as part of our own infrastructure, acting as processors on our instructions. Your documents are not sent to third-party AI services, data brokers or advertising networks.

3. Account, billing and usage data

  • Account details. Your email address, username and a securely hashed password. We never store your password in a readable form.
  • Social sign-in. If you sign in with Google or GitHub, we receive basic profile information such as your email address from that provider.
  • Session data. HTTP-only cookies that keep you signed in.
  • Usage and credits. Counts of operations performed so we can apply plan limits and prevent abuse. This records that a tool ran, not what your document said.
  • Billing. Lemon Squeezy is our merchant of record and processes all payments. Card details are entered on their systems and never reach ours; we store only identifiers linking your account to your subscription, plus invoice metadata such as plan and status.
  • Newsletter. If you subscribe, we store your email for that purpose until you unsubscribe.
  • Server logs and security data. Standard technical logs, including IP address and request metadata, used to keep the service available and to enforce rate limits.

4. Advertising

Advertising is what keeps the free tools free. Where ads are displayed, they are served by Google AdSense. Google and its partners may use cookies and device identifiers to select and measure ads and to cap repetition, and for that activity Google acts as an independent controller under its own partner-sites policy.

Two commitments apply without exception:

  • The advertising code is not loaded until you accept it. Choose Reject non-essential and no advertising script runs and no advertising cookie is set. You can change this later via Cookie settings in the footer.
  • Your documents are never used for advertising. We do not send file contents, filenames or extracted text to any advertising partner, and we do not build profiles from what you process.

Full detail, including the cookie tables, is in our Cookie Policy.

5. Legal bases for processing

Where the UK GDPR or EU GDPR applies, we rely on:

  • Contract — to provide the tools, run your account and process transactions you have asked for.
  • Consent — for advertising cookies and for marketing email. You may withdraw consent at any time.
  • Legitimate interests — to keep the service secure, prevent abuse and enforce plan limits, balanced against your rights.
  • Legal obligation — to retain records such as tax and accounting data.

6. How long we keep data

  • Documents: deleted immediately after processing. Browser-based tools upload nothing at all.
  • Account data: kept while your account is open, then deleted or anonymised after closure, except where we must retain records by law.
  • Billing records: retained as long as tax and accounting rules require.
  • Logs: kept for a short operational period, then rotated out.
  • Newsletter: until you unsubscribe.

7. Who we share data with

We do not sell your personal data. We share only what is necessary with:

  • Lemon Squeezy — payments, subscriptions, invoicing and tax.
  • Google AdSense — advertising, and only after you consent.
  • Hosting and infrastructure providers — to run the service.
  • Email delivery providers — for account and, if you opted in, newsletter email.
  • Authorities — where we are legally required. Note that for browser-based tools there is nothing to hand over.

8. International transfers

Some providers operate outside your country, including in the United States. Where personal data is transferred out of the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.

9. Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and associated personal data.
  • Restrict or object to certain processing, including direct marketing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Complain to your data protection authority, such as the ICO in the United Kingdom.

To exercise any of these, email privacy@pdfdw.com. We respond within the timeframes the applicable law requires, normally one month. We may need to verify your identity first. One practical note: because documents are deleted immediately after processing, there is generally no stored file for us to return or erase.

10. Security

We use HTTPS in transit, hashed passwords, HTTP-only session cookies, authenticated access controls, rate limiting and prompt deletion of processed files. Minimising what we hold is itself part of the design. No system is perfectly secure, so we do not claim otherwise.

11. Children

pdfdw is not directed at children and accounts are not intended for anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

If we change how we handle personal data we will update this page and the date above. Where a change requires consent — a new cookie category, for example — the consent banner will ask again rather than carry over your previous answer.

13. Contact

Privacy queries: privacy@pdfdw.com. General support: contact page.