Privacy Policy
Last updated:
This policy separates selected PDF content from the other data a website may process. Browser-local PDF work does not mean that accounts, subscriptions, consent choices, contact messages, analytics, or error reporting disappear.
1. Summary
The current compression and merge tools process selected PDF content in browser workers. BytesPDF does not provide a PDF upload endpoint for those operations. Working blobs stay in the current tab's memory and are not persisted in IndexedDB, Cache Storage, or BytesPDF server storage.
The site still uses or can use the service providers and data categories described below. Google Analytics measures traffic unless the visitor opts out. Advertising cookies are not used. First-party product-usage logs are written only after analytics is accepted in the cookie banner.
2. Selected PDFs and downloaded output
- The browser reads the selected PDF and performs the current operation locally.
- Working document blobs remain in tab memory. Closing or reloading the tab releases application references; browser and operating-system memory management determine the exact cleanup timing.
- A result saved through the browser remains in the download location chosen by the user.
- The service worker caches application, worker, codec, and related program assets—not selected PDF content.
- Device malware, browser extensions, screen access, downloaded-file storage, and the later recipient remain outside BytesPDF's document-ingress claim.
3. Other data we process
Account and profile
If you register, Supabase can process an account identifier, email, authentication records, name/profile fields, role, account dates, and Early Bird status. Password credentials are handled by Supabase authentication rather than stored as readable passwords by BytesPDF.
Subscriptions
The footer and pricing update form submit the email address and source label to the subscriber table, plus any campaign attribution parameters present at signup (UTM source, medium, campaign, content, and landing page path — never recipient identifiers). This is used for occasional product communication and measuring which campaigns drive signups, and can be removed on request.
Consent audit
Consent choices are stored locally and a best-effort audit entry can record categories, schema version, source, timestamp, and user-agent string. It intentionally excludes the account ID and PDF content.
Optional product-usage logging
After analytics is accepted in the cookie banner, BytesPDF can log the tool, input byte size, output ratio, source path, and file count to Supabase with a null user ID. This is aggregate product telemetry, not an account document history, and it stays off until that choice is saved.
Contact and error data
A contact submission includes what the sender enters. Configured error reporting can include page, browser, stack, and technical context. Do not attach or paste a PDF or sensitive document content into a support message.
4. Cookies, local storage, and caches
| Item | Purpose | Category |
|---|---|---|
| Consent choice | Remembers categories and version | Essential preference record |
| Supabase authentication storage | Maintains an optional signed-in session | Essential when using an account |
| Banner dismissal | Remembers that the launch notice was closed | Preference |
| Service worker cache | Caches application worker and codec assets | Essential application asset cache |
| Google Analytics storage | Measures site traffic unless you opt out | Analytics, advertising cookies off |
Use Manage privacy choices in the footer to opt out of analytics. Opting out disables the integration and removes first-party _ga cookies available to this origin.
5. Analytics and advertising status
Google Analytics loads for traffic measurement unless you opt out. BytesPDF does not run AdSense or advertising cookies, and it does not intentionally send PDF content or the BytesPDF account ID to Google Analytics. Google can process network and device information under its own terms, so this policy does not describe analytics as anonymous in an absolute sense.
Advertising is not currently enabled in the application. If advertising or marketing storage is introduced, the consent interface and this policy must be updated before activation. Marketing remains disabled in the current consent implementation.
6. Service providers
| Provider | Purpose | Relevant data |
|---|---|---|
| Supabase | Authentication, profiles, subscribers, consent audit, and consented anonymous usage logs | Account/profile fields; subscriber email; consent categories, source, time and user agent; anonymous tool/size/path metrics after consent |
| Google Analytics | Website traffic measurement; advertising cookies are not used | Page and event data, device/browser and acquisition information handled under Google's terms; no PDF content or BytesPDF account ID is intentionally sent |
| Formspree | Contact-form delivery when configured | The name, email, subject, message, and technical request data involved in the submission |
| Sentry | Error reporting when configured | Error, stack, browser, page, and related technical context; users should not include document content in feedback fields |
These providers can process data in the United States or other regions according to their infrastructure and terms. Applicable transfer mechanisms and rights depend on the user's location and the provider's current legal arrangements.
7. Retention and deletion
- Selected PDFs have no BytesPDF server-retention period because the current core tools do not send document content to BytesPDF.
- Downloaded output remains under the user's control.
- Account and profile data remains while the account is active and as needed for legitimate security, legal, or operational purposes.
- Subscriber data remains until unsubscribe or a valid deletion request, subject to necessary suppression or legal records.
- Consent, analytics, contact, and error records follow the applicable provider settings, operational need, and legal obligations.
Automated self-service account deletion is not currently available on this static site. Send a request from the account email to privacy@bytespdf.com. Do not include a PDF or sensitive document with the request.
8. Choices and privacy rights
Depending on applicable law, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent. Requests can be sent to the privacy address. Identity verification may be required, and some data may be retained where law permits or requires it.
- Use the site without creating an account.
- Keep analytics off or withdraw consent through the footer control.
- Unsubscribe from product email.
- Request profile, subscriber, contact, or consent-record access or deletion where applicable.
9. Security and important limits
BytesPDF uses browser isolation, local workers, HTTPS-hosted assets, and provider security controls as parts of its design. No system is risk-free. A compromised device, extension, origin, dependency, account, download location, or recipient can expose data despite local PDF processing.
Read the security threat model →10. Regulated and children's data
BytesPDF is not a HIPAA Business Associate and does not offer a BAA. Browser-local processing reduces one transfer path but does not establish HIPAA, GDPR, or other compliance for an entire workflow. Follow the approved process for regulated, privileged, classified, or organization-controlled documents.
The service is not directed to children under 13. A parent or guardian who believes a child submitted personal data can contact the privacy address.
11. Changes and contact
This policy can change as product behavior, providers, or legal requirements change. The dated version above identifies the current text. Material changes should be presented visibly rather than hidden behind an unchanged date.
