Legal / Privacy Policy

Privacy Policy

Last updated 29 July 2026

The short version

We collect your account email and usage data, and process the document data you send only to render your document (we do not store it unless you opt in). We rely on the contract, our legitimate interests, legal obligations and, for anything optional, your consent. We never sell your data, and you can access, correct or delete it at any time.

Who We Are

This Privacy Policy explains how Islam Mokrane ("PDFglyph", "we", "us"), an entrepreneur individuel (sole trader) registered at 22 Rue Léonard de Vinci, 91300 Massy, France under RCS Évry 934 949 033, processes personal data. For the personal data described here, we act as the data controller.

Privacy contact: privacy@pdfglyph.dev. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; you can reach us on any privacy matter at privacy@pdfglyph.dev.

The Data We Collect

We collect:

  • Account data you provide: your email address and a hashed password.
  • Usage and log data: API requests, template and generation identifiers, timestamps, status codes, error details, IP address and approximate location, and device or browser information.
  • Document data: the data you send to the generation API to render a document. We act as a processor for this data on your behalf (see our DPA); we do not store the generated document, and we store request payloads only where you enable per-template input storage.
  • Billing data: name, billing address and payment details, handled by our payment processor (Stripe). We do not store full card numbers.
  • Cookies: see our Cookie Policy.

Your Document Data

The data you submit to generate documents is processed solely to render and return your document, on your instructions, under our Data Processing Agreement. We do not sell it, use it to train models, or use it for our own purposes. We do not retain the generated document, and request payloads are stored only where you turn on per-template input storage.

Recipients and Sub-processors

We share personal data only with:

  • Service providers that help us run PDFglyph: cloud hosting and our database (Railway, hosted in the EU), transactional email (Resend), payment processing (Stripe), and cookieless audience measurement on our public website (Umami Cloud, EU region). They act on our instructions under written contracts. Those that handle data you entrust to us are listed as sub-processors, with each one's role and location, in Annex 3 of our Data Processing Agreement; audience measurement is not among them, because it never sees your account or your document data.
  • Authorities or advisers where required by law or to establish, exercise or defend legal claims.

We do not sell personal data or share it for third-party advertising.

International Transfers

Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision where one exists, or otherwise on appropriate safeguards, principally the European Commission's Standard Contractual Clauses, together with any supplementary measures required. You may request a copy of the relevant safeguards at privacy@pdfglyph.dev.

How Long We Keep Data

We keep personal data only as long as necessary:

  • Account data: while your account is active, then deleted or anonymised within 30 days of closure.
  • Usage and generation logs (metadata only — we never store the generated document): kept for your plan's retention window, from 7 days on Free up to 365 days on Scale, then purged automatically.
  • Document request payloads (only where you turn on per-template input storage): until you delete them or close your account.
  • Billing records: as required by tax and accounting law (in France, typically 10 years).
  • Backups: encrypted and cycled out within 30 days.

Your Rights

Under the GDPR you have the right to: access your data; have it rectified; have it erased; restrict or object to processing; data portability; and, where we rely on consent, to withdraw it at any time (without affecting processing already carried out).

To exercise any right, contact privacy@pdfglyph.dev. We respond within one month (extendable by two further months for complex requests). You also have the right to lodge a complaint with a supervisory authority — in France, the Commission Nationale de l'Informatique et des Libertés (CNIL).

Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling for such purposes.

How We Protect Data

We use appropriate technical and organisational measures, including encryption in transit (TLS), hashed passwords and API keys, access controls, server-side screening of external resources (SSRF protection) and time-bounded rendering. No system is perfectly secure, but we work to protect your data and to notify you and any regulator of breaches as required by law.

Children

PDFglyph is a developer tool and is not directed to children. We do not knowingly collect personal data from anyone under 15. If you believe a child has provided us data, contact privacy@pdfglyph.dev and we will delete it.

Changes to This Policy

We may update this Policy. We will post the updated version with a new "last updated" date and, for material changes, give reasonable notice (for example by email or in-app).

Contact Us

Questions or requests about this Policy or your data: privacy@pdfglyph.dev Islam Mokrane, 22 Rue Léonard de Vinci, 91300 Massy, France.