Privacy policy
The short version
Most privacy policies need 3,000 words to say something dishonest. Ours needs them to say something honest. Here’s the summary; the full version is below.
- We never see your files. Every PDFluna tool processes your documents in your browser. The file goes from your device to our website’s JavaScript, then back to your device as a download — no upload happens.
- No account, no profile. You never type your name, email, or any identifier to use a tool. We have nothing to log against you because there is no “you” in our database.
- Anonymous analytics. We count page views and tool usage with Google Analytics 4 (and Plausible as a cookieless fallback for visitors who reject consent). No personal identifiers, no document content.
- Ads support the site. Display ads on tool pages cover hosting and development. You can reject ad personalisation in the cookie banner; the tools still work the same way.
- Email if you write to us — only then. The contact page tells you which email address handles which topic; we read everything and don’t feed your messages into anything.
For specific questions, jump to the relevant section below or email [email protected].
1. Who runs PDFluna
PDFluna (the website at pdfluna.com) is operated by a small independent team. We are the “data controller” for any personal information processed via this site under the EU GDPR and the UK GDPR, and the “business” for purposes of the California Consumer Privacy Act (CCPA) and CPRA.
For data-protection inquiries, write to [email protected]. The about page has more on who builds the project; the contact page lists every email address you might need.
2. What we don’t collect
The genuinely interesting paragraph in any privacy policy is this one. Most of what would be in a typical policy isn’t here because we don’t collect it in the first place:
- Document content. The PDFs, images, spreadsheets, and Word documents you process never leave your device. We don’t see filenames, page counts, embedded text, or any other content. Verify it yourself: open DevTools → Network in your browser before using a tool, then watch for any outbound request that carries your file. There aren’t any.
- Account data. No sign-up, no login, no profile, no name, no email collection at the tool level. There’s no “your account” because there’s no account.
- Persistent identifiers about you specifically. No fingerprinting, no cross-site tracking pixels, no “data brokers we sell to.” Cookies (covered below) are limited to anonymous analytics and, when you consent, ad personalisation; none of them tie back to a real-world identity we store on our side.
- Document content for AI training. We don’t collect documents (see point one), so there is nothing to feed into AI training. We don’t use anonymised analytics for AI training either.
- Sensitive categories of personal data. Health information, biometric data, sexual orientation, political opinions, religious beliefs, union membership, genetic data, criminal records — we collect none of these. If your file happens to contain any of them, see the first bullet: we don’t see your file.
3. What we do collect
The site does collect a small amount of data — mostly anonymous, mostly to keep the lights on. Here’s exactly what:
3.1. Anonymous analytics
Page views and tool usage counts via Google Analytics 4 (measurement ID G-TJKZSLDM8Z). The data points are aggregated: which tool was opened, roughly which country (city-level only, not address), browser version, device type. No file content, no filenames, no account identifiers (because there are no accounts). For visitors who reject the cookie banner, GA4 is replaced with Plausible — a cookieless analytics service that doesn’t use any persistent identifier at all.
3.2. Server access logs
Standard web server logs at our hosting provider record the URL requested, timestamp, IP address (truncated where possible), HTTP status code, and user agent. These are kept for security troubleshooting (DDoS investigation, abuse detection) and rotated automatically. They contain no document content.
3.3. Email correspondence
If you write to us at [email protected] or [email protected], the email and any attachment you include land in our shared inbox. We keep email threads while the conversation is active and archive them afterwards. Email [email protected] with your original thread to have records erased — we’ll do it within 30 days.
3.4. Advertising data
Tool pages display ads served by Google AdSense. When you consent to ad personalisation via the cookie banner, AdSense uses standard ad-tech cookies to limit ad frequency, prevent click fraud, and serve relevant ads. When you reject personalisation, AdSense serves non-personalised ads (which still set a small subset of cookies for fraud prevention) and PDFluna analytics falls back to the cookieless Plausible service. Full details of what AdSense collects and how to opt out at the Google level are at policies.google.com/technologies/ads.
4. Cookies and similar technologies
Below is the complete list of cookies the site sets, what each one does, how long it lasts, and who sets it. We don’t use any others. The full cookie policy with opt-out mechanics is at /cookies/.
| Cookie | Purpose | Duration | Source | Type |
|---|---|---|---|---|
_ga, _ga_TJKZSLDM8Z |
Anonymously identifies a returning browser so we can count unique visitors and aggregate page-view stats. No personal identifiers. | 2 years (expires automatically) | Google Analytics 4 | Analytics |
pdfluna_consent |
Stores your cookie-banner choice (accept / reject) so we don't re-prompt every page. Set only after you interact with the banner. | 6 months | PDFluna (first-party) | Strictly necessary |
__gads, __gpi, IDE |
Set by Google AdSense to limit ad frequency, prevent click fraud, and serve relevant ads when you have not opted out of personalisation. EU visitors who reject consent see non-personalised ads, which still set a small subset of these for fraud prevention. | 13 months (max) | Google AdSense | Advertising |
EU and UK visitors see a cookie banner before any non-essential cookies are set; non-EU visitors get default consent under the local law that applies. You can change your choice anytime from the footer link “Cookie preferences”.
5. How we use the data
We process the small amount of data we do collect for a small set of clearly-scoped purposes. Each maps to a lawful basis under GDPR Article 6:
- Operating the site. Server logs, basic security telemetry. Lawful basis: legitimate interest (running the site).
- Understanding aggregate usage. Analytics page views, tool usage counts. Lawful basis: consent in jurisdictions that require it (EU/UK), legitimate interest elsewhere. We honour Do Not Track and Global Privacy Control signals where the browser sends them.
- Funding the site through ads. Display advertising via Google AdSense. Lawful basis: consent in jurisdictions that require it; for users who decline, non-personalised ads run under legitimate interest.
- Responding to your messages. When you email us. Lawful basis: legitimate interest (responding to inbound questions); contractual where you’re a press / business contact.
We do not use any of this data for: building a profile of you across sites, selling to data brokers, training AI models, automated decision-making with legal effect, or any purpose not listed above.
6. Third parties we work with
A short, complete list of companies that touch any data flowing through the site. We don’t use any others without updating this section first.
- Google (Analytics 4 + AdSense). Operates the analytics and advertising stack. Their privacy policy: policies.google.com/privacy. Google may transfer data to the United States; their EU representative and Standard Contractual Clauses cover the transfer.
- Plausible Analytics. Cookieless analytics fallback for users who reject consent on the cookie banner. EU-hosted; no cookies, no personal identifiers, GDPR-compliant by design. Privacy policy at plausible.io/privacy.
- Cloudflare. Content-delivery network and security layer. Sees the same connection-level data your ISP and any CDN sees: IP, request URL, user agent. Doesn’t see file content (it’s never sent). Privacy policy at cloudflare.com/privacypolicy.
- Hosting provider. ADM.tools (cPanel-style shared hosting). Stores the static HTML/PHP/CSS/JS files that make up the site, plus server access logs as described in section 3.2.
- JavaScript libraries served from public CDNs (jsdelivr, unpkg, cdnjs). The browser fetches these directly when you load a tool page. The CDN sees a request from your IP for a public file, exactly as it does for any visitor to any site using that CDN. No personal data is sent. We pin specific versions of every library; full list on the about page.
7. Your rights
Under GDPR (EU/UK), CCPA / CPRA (California), and similar laws, you have a defined set of rights about personal data we hold on you. Even where the law doesn’t formally apply to you, we honour these requests on principle:
- Right to know / access. Ask what personal data we hold on you. For most visitors the honest answer is “none we can identify with you specifically” — analytics is anonymous. If you’ve ever emailed us, the email thread is what we have.
- Right to deletion / erasure. Ask us to delete data we hold. For email correspondence, this is straightforward; we’ll erase the thread within 30 days.
- Right to correction / rectification. Ask us to fix inaccurate data. Same channel as deletion.
- Right to opt out of sale / sharing (CCPA). We do not sell personal information. We do not share it with third parties for cross-context behavioural advertising in the CCPA-defined sense.
- Right to opt out of analytics + advertising. Reject the cookie banner; analytics falls back to cookieless Plausible and ads run as non-personalised. Or use the standard browser controls (Do Not Track, Global Privacy Control).
- Right to lodge a complaint. If you think we’ve mishandled your data, you can complain to your local supervisory authority. EU residents: your national Data Protection Authority. UK: the ICO. We prefer you give us a chance to fix it first — email [email protected] — but the right exists regardless.
To exercise any of these rights, email [email protected] with the subject prefix [Privacy] and a brief description of the request. We respond within 30 days (the statutory deadline under GDPR); typically much faster. We may ask for proof of identity if the request is ambiguous, since we have no account-level way to verify it.
8. How long we keep data
Concrete retention periods, no “as long as necessary” vagueness:
- Document content: never received, never retained.
- Server access logs: 30 days, then automatically rotated.
- Anonymous analytics (GA4): 14 months, then aggregated and the user-level data dropped per Google’s default GA4 retention setting.
- Anonymous analytics (Plausible): indefinitely, but with no personal identifiers anywhere — the data is statistical from the moment it’s collected.
- Cookies: as listed in the cookies table in section 4.
- Email correspondence: kept while the conversation is active, archived for up to 3 years afterwards for context if you ever write back, then deleted. Or sooner on your request.
9. International data transfers
The site is hosted in the EU (specifically by ADM.tools). Some third parties we use process data in other regions:
- Google (Analytics, AdSense): may transfer data to the United States. Google relies on the EU-US Data Privacy Framework and Standard Contractual Clauses for the transfer.
- Cloudflare (CDN): uses a globally-distributed network; connection-level data may be processed in any of their data centres depending on which is closest to you. Cloudflare relies on Standard Contractual Clauses for cross-border transfers.
If your data subject rights or local regulations require additional safeguards, email [email protected].
10. Children’s privacy
PDFluna isn’t intended for users under 16 years old, and we don’t knowingly collect data on children. The site requires no account, so we’d have no way to verify age in any event. If you’re a parent or guardian and believe your child has had data of theirs processed via the site, email [email protected] and we’ll delete anything we can identify.
11. Security
The strongest security posture is not having the data in the first place, and that’s our default for document content. For the data we do hold:
- HTTPS everywhere. All site traffic is served over TLS; the CDN and origin both enforce HTTPS. HTTP requests are 301-redirected to HTTPS.
- Server hardening. Deny rules for sensitive paths (
/includes/*returns 403), strictX-Content-Type-OptionsandReferrer-Policyheaders, restrictivePermissions-Policyon camera / microphone / geolocation. - Email security. Our email accounts use 2-factor authentication; access is limited to people who need it.
- No promises we can’t keep. No system is perfectly secure. If a breach ever does affect data we hold on you, we’ll notify the relevant supervisory authorities within 72 hours under GDPR Article 33 and let you know directly via your last-known email.
12. Changes to this policy
We update this policy when there’s a real change — new feature, new third party, new lawful basis, new retention period. The “Last updated” date at the top of the page reflects the most recent meaningful change; minor copy edits don’t bump it.
If a change affects how your existing data is processed (rare but possible), we’ll surface the change with a banner on the homepage for 30 days. For users who’ve given us an email, we’ll also send a direct notice.
13. How to contact us
For anything related to your data or this policy, the right inbox is:
Include the subject prefix [Privacy] and a brief description of what you’re asking for; the dedicated mailbox triages faster than the general one. For non-privacy topics (general questions, bug reports, press), see the full contact page.