Executive Privacy Guarantee
We do not sell, rent, monetize, or broker your personal information. Files uploaded to GentlePDF are processed automatically on ephemeral cloud micro-nodes and permanently wiped within sixty (60) minutes. We never view, index, copy, or use your documents to train artificial intelligence or machine-learning models.
1Privacy by Design & Core Principles
GentlePDF Inc. ("GentlePDF", "Company", "we", "us", or "our") is committed to preserving the highest standards of data protection and digital confidentiality. Our platform architecture is built from the ground up on the internationally recognized doctrine of Privacy by Design and by Default.
Under traditional cloud services, user documents often sit indefinitely in centralized datastores. GentlePDF rejects this model. We treat your files as volatile streams of data that exist exclusively for the fleeting duration required to execute your transformation command (such as merging PDFs, splitting pages, compressing document size, converting formats, or applying watermarks). Once that operation concludes, the data pipeline collapses and your files are scheduled for automatic destruction.
This Privacy Policy applies to all interactions with our web application, desktop utilities, browser extensions, customer support desks, and programmatic application programming interfaces (APIs) located under the domain gentlepdf.com and related regional subdomains.
2Categories of Information We Collect
In the course of providing you with high-speed, secure PDF processing utilities, we collect and process three primary categories of information:
2.1 Account and Identity Information
When you register an account or interact with our authentication services, we collect:
- Direct Registration: Your full name, email address, and a cryptographically salted and hashed representation of your password (generated via the industry-standard bcrypt algorithm with high work factors). We never store your plaintext password.
- Social Identity Data: If you elect to register or sign in via Google, Facebook, or LinkedIn, we receive your public display name, verified primary email address, profile avatar URI, and unique provider identification token as authorized by your OAuth permissions.
- Account Preferences: Your selected interface theme (light/dark mode), compression level defaults, and conversion history flags.
2.2 Uploaded Document Files & Content Metadata
When you submit documents to our tools:
- File Binaries: The PDF, DOCX, XLSX, PPTX, HTML, or image files you drag-and-drop or select for conversion.
- Operational Metadata: File byte size, page count, filename, MIME type, and processing parameters (e.g. selected page ranges or watermark text).
- Processing Output: The resulting converted, merged, or compressed document generated by our serverless processing workers.
2.3 Automatically Collected Technical & Telemetry Data
When navigating our platform, our ingress load balancers automatically record standard network telemetry:
- Network Identifiers: Internet Protocol (IP) address (truncated and anonymized for telemetry), referring URLs, and geographical region (country level).
- Hardware & Browser Profiles: User-Agent header, browser vendor and version, device type, operating system build, screen resolution, and language headers.
- Performance Metrics: Upload transfer throughput, tool processing execution duration, memory allocation, and error status codes.
3The Document Lifecycle & 60-Minute Purge
Our document processing architecture is strictly ephemeral. To guarantee absolute confidentiality, we adhere to the following rigorous technical pipeline:
Secure Ingress Staging
Your document is received over TLS 1.3 encryption, assigned an unpredictable UUIDv4 token, and saved to a sandboxed RAM-backed or ephemeral disk volume isolated from other users.
Automated Execution Pipeline
Dedicated background processes (such as PDF engine decoders, OCR libraries, or LibreOffice headless instances) execute the conversion in an unprivileged container. No human ever inspects the file contents.
Secure Delivery & Stream
The generated output file is streamed back to your web browser with safe attachment headers, ensuring your local device receives the final artifact without intermediaries.
Permanent 60-Minute Purge & Scrub
Once processing is complete, immediate automated background tasks clean up local pointers. Any remaining files are purged automatically by our cron scrub daemon within sixty (60) minutes. File blocks are zeroed out and made irrecoverable.
4Non-Exploitation & No AI Training Guarantee
In the modern era of generative artificial intelligence and large language models (LLMs), many software providers silently crawl customer data to fine-tune their proprietary neural networks. GentlePDF maintains an absolute, binding guarantee never to use your documents or personal data for machine learning or AI training purposes.
Your contracts, medical records, financial spreadsheets, research manuscripts, tax documents, and personal portfolios remain your exclusive property. We do not extract text embeddings, semantic representations, or knowledge graphs from your uploaded materials.
5Third-Party Social Logins (Google, Facebook, LinkedIn)
To provide swift and friction-free onboarding, GentlePDF offers federated identity authentication via leading social identity providers. Here is exactly how each integration operates:
- Google Sign-In: Provided by Google LLC. We request the minimal scopes necessary:
email,profile, andopenid. We obtain your email address to establish your account identity, your public name for interface greeting, and your profile picture URL to display your account avatar. We do not access your Google Drive, Gmail, or Google Contacts. - Facebook Login: Provided by Meta Platforms, Inc. We utilize the Facebook OAuth dialog with the
public_profileandemailpermission scopes. We retrieve your verified email and name. We never post to your timeline, message your friends, or monitor your social graph. - LinkedIn Sign In: Provided by LinkedIn Ireland Unlimited Company / Microsoft Corporation. We authenticate your session using OpenID Connect (
openid,profile,email) to verify professional credentials and streamline team access.
You can revoke GentlePDF's authorization at any time by navigating to the connected apps or security settings within your Google, Facebook, or LinkedIn account dashboard.
6Purpose & Legal Bases for Processing (GDPR)
For individuals located within the European Economic Area (EEA), United Kingdom (UK), or Switzerland, our processing of your personal data is conducted exclusively under the recognized legal bases enumerated in Article 6 of the General Data Protection Regulation (GDPR):
Contractual Necessity (Art. 6(1)(b))
Processing your documents, creating your user profile, maintaining your login state, and delivering PDF output files as requested by you in fulfillment of our service agreement.
Legitimate Interests (Art. 6(1)(f))
Protecting our infrastructure against malicious denial-of-service (DDoS) barrages, preventing abusive automated scraping, maintaining server load balancing, and resolving crash bugs.
Legal Obligation (Art. 6(1)(c))
Retaining financial and subscription billing transaction records to comply with applicable tax, VAT, accounting, and fiscal auditing statutes.
User Consent (Art. 6(1)(a))
Sending optional marketing communications, product updates, or non-essential analytical cookies where you have explicitly opted in.
7Disclosure & Information Sharing
We do not sell, rent, or trade your personal information or document data to any third parties for monetary compensation or advertising targeting. We only share information with third parties in the limited circumstances described below:
- Infrastructure Sub-Processors: We partner with trusted cloud hosting and compute providers (such as Amazon Web Services, Google Cloud Platform, and Vercel Inc.) that provide physical datacenters, content delivery networks (CDNs), and encrypted object storage. These sub-processors are bound by strict Data Processing Agreements (DPAs) requiring adherence to rigorous confidentiality, ISO 27001, and SOC 2 Type II controls.
- Payment Processors: For paid subscriptions, credit card and payment processing is handled through PCI-DSS Level 1 compliant gateways (such as Stripe). GentlePDF does not retain or store raw credit card numbers or security CVVs on our servers.
- Legal Requirements & Compulsory Process: We may disclose information if we have a good faith belief that disclosure is required by applicable law, regulation, valid subpoena, court order, or governmental warrant. In such instances, we rigorously scrutinize each request to ensure lawful jurisdiction and notify the affected user where legally permissible.
- Corporate Reorganization: In the event of a merger, acquisition, corporate reorganization, asset sale, or bankruptcy, user accounts may be transferred to the acquiring entity subject to the identical protective terms of this Privacy Policy.
8International Cross-Border Data Transfers
GentlePDF operates globally, with cloud compute clusters situated in the United States, the European Union, and the Asia-Pacific region. When you access our services, your information may be routed to or processed in a jurisdiction outside your country of residence where data protection laws may differ from those of your local jurisdiction.
For data transfers originating from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognized as providing an adequate level of data protection by the European Commission, GentlePDF relies on standard contractual clauses (SCCs) approved by the European Commission, supplemented by technical safeguards such as end-to-end transport encryption and ephemeral storage to ensure your data receives an equivalent level of protection.
9Technical & Cryptographic Safeguards
GentlePDF implements comprehensive technical, administrative, and physical security measures designed to safeguard data against unauthorized access, destruction, loss, alteration, or disclosure:
- Encryption in Transit: 100% of data traffic between your web browser and our platform is encrypted via TLS 1.3 with Perfect Forward Secrecy (PFS) and HTTP Strict Transport Security (HSTS) enforced.
- Encryption at Rest: All temporary file directories and databases utilize Advanced Encryption Standard (AES-256) disk encryption.
- Network Segmentation & Sandboxing: Conversion processes run within unprivileged Linux containers with read-only root filesystems and restricted networking to prevent inter-process snooping.
- Password Hashing: User passwords are encrypted using multi-round bcrypt hashing, rendering them immune to rainbow table lookups.
- Vulnerability Management: Continuous automated security scanning, dependency dependency audits, and proactive vulnerability patching.
10Your Rights under GDPR & European Law
If you are a resident of the European Union, European Economic Area, or United Kingdom, you hold comprehensive rights regarding your personal data:
To exercise any of these rights, email our Data Protection team at privacy@gentlepdf.com. We respond to all verified statutory requests within thirty (30) days without charge.
11California Privacy Disclosures (CCPA / CPRA)
Under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA/CPRA"), California residents are entitled to specific disclosures regarding our collection, use, and disclosure of Personal Information:
- No Sale or Sharing of Personal Information: GentlePDF does not sell your Personal Information to data brokers or third parties, nor do we "share" your Personal Information for cross-context behavioral advertising.
- Right to Know & Delete: You have the right to request disclosure of the categories and specific pieces of Personal Information collected about you over the prior 12 months, as well as the right to demand deletion.
- Non-Discrimination Guarantee: We will never discriminate against you, deny you services, charge you different rates, or degrade service quality because you exercised any of your rights under California law.
12Children's Privacy Compliance
GentlePDF is designed for general audiences, professionals, students, and businesses. Our platform is not directed to children under the age of sixteen (16). We do not knowingly collect, solicit, or maintain personal information from individuals under sixteen years of age. If we learn that we have unintentionally received personal information from a minor without verifiable parental consent, we will promptly delete that information from our datastores. Parents or guardians who believe their child has provided personal information to GentlePDF should contact us at privacy@gentlepdf.com.
13Cookies, Local Storage & Preferences
We use strictly necessary cookies and browser local storage (localStorage) to deliver core web features:
- Session Token Storage: We store your JSON Web Token (JWT) locally to keep you authenticated across page refreshes and browser tabs without forcing repetitive logins.
- Interface Preferences: We record your selected UI theme (Dark/Light mode) and recent tool parameters to provide a tailored user experience.
- No Third-Party Advertising Trackers: GentlePDF does not deploy intrusive third-party cross-site advertising beacons, tracking pixels, or data broker cookies.
You can configure your browser to reject cookies or purge local storage at any time through your browser's settings menu. Please note that clearing local storage will log you out of your GentlePDF session.
14Revisions to This Privacy Policy
We may periodically update, refine, or expand this Privacy Policy to reflect enhancements to our toolset, newly supported conversion engines, evolving data privacy statutes, or operational advancements. When revisions occur, we will update the "Effective Date" at the top of this document.
For material modifications that significantly affect your privacy rights or how your personal information is processed, we will provide prominent notice—such as an announcement banner on the GentlePDF home page or a direct notification to your registered email address. We encourage you to review this page periodically to remain informed about how we safeguard your information.
15Data Protection Officer (DPO) & Contact Information
GentlePDF Inc. has appointed a dedicated Data Protection Officer to supervise regulatory compliance, respond to statutory inquiries, and enforce privacy protections across all development squads. If you have questions, concerns, comments, or requests regarding this Privacy Policy or our data processing practices, please contact us:
GentlePDF Privacy Office & Data Protection Officer
Email: privacy@gentlepdf.com
Corporate Address: GentlePDF Inc., Attn: Privacy Office, 1209 Orange Street, Wilmington, DE 19801, USA
General Legal Inquiries: legal@gentlepdf.com