Privacy Policy
What we collect, what we deliberately do not collect, and how long anything is kept.
Most privacy policies are written to permit as much as possible. This one is written to describe what the software actually does — which is far less. Your documents are processed and deleted; what remains is a record that an operation happened, never a record of what was in it.
01The three rules this policy follows
- Your documents are not data we collect. They pass through, they are transformed, they are returned, and the working copy is deleted. They are never stored as a record about you.
- We record that an operation happened, not what was in it. The service keeps enough to enforce limits and keep itself running, and no more.
- Nothing is sold, and nothing is shared for advertising. There are no advertising trackers on this site and no third-party analytics profile of you.
Everything below is the detail behind those three sentences. Where a claim can be checked against how the software actually behaves, we have written it that way rather than in the broadest language a lawyer would allow.
02The files you upload
A number of tools never send your file anywhere. Rendering pages, generating thumbnails, and reading a PDF’s existing text layer all happen inside your browser, on your own machine. For those, the document never leaves your device at all.
Where a tool needs server processing — merging, splitting, compressing, applying edits, recognising text in a scan — the file is uploaded over an encrypted connection into an isolated temporary directory created for that single request. The tool runs, the result is returned, and the directory is deleted in the same request, whether the operation succeeded or failed.
The safety net behind that
If the process crashes before it can clean up after itself, a sweep runs every thirty minutes and removes any leftover working directory older than the retention window (one hour by default). This is a backstop for abnormal termination, not the normal path — under normal operation nothing survives the request that created it.
We do not keep a copy of your document. Not for backup, not for quality improvement, not for training any model. There is no archive of processed files to request, to search, or to leak.
03What we do keep
Three categories, and this is all of them.
Your email address, a hash of your password, your plan, and timestamps for account creation and last sign-in. The password itself is never stored — it is hashed with Argon2id, a deliberately slow, memory-hard algorithm, and that hash cannot be reversed back into your password.
For each tool run: which tool, whether it succeeded, the size in bytes of the input and output, the page count, how long it took, and a broad error category if it failed. No filename. No content. No text extracted from the document. This is what makes hourly limits and basic reliability monitoring possible.
A hash of your session token, the browser user-agent string, the IP address of the sign-in, and expiry. This exists so you can see and end your own sessions, and so an unfamiliar sign-in is visible rather than silent.
04If you never create an account
Guest use still has to be limited, or a single script would consume the whole service. We do it with two signals, neither of which identifies you:
- a random identifier stored in the
pm_anoncookie, which contains nothing but a randomly generated value with no meaning outside our rate counter; - a one-way SHA-256 hash of your IP address. The address itself is not written to the usage store; only the hash is, so two requests can be recognised as coming from the same place without that place being readable from the record.
Both signals are used together precisely so neither has to be strong. We use them for rate limiting and abuse prevention, and for nothing else.
05What we deliberately do not collect
Stating this positively is more useful than a long list of hedged permissions, so:
- No advertising or cross-site tracking cookies, and no ad network.
- No third-party analytics that builds a profile of you across sites.
- No filenames, document titles, or metadata from your files, kept as records.
- No text extracted by OCR — it is returned to your browser and not retained by us.
- No sale of personal information to anyone, under any definition of “sale”.
- No use of your documents to train machine-learning models.
06Why we are allowed to hold it
If you are in a place with a lawful-basis requirement, such as the UK or the EU under the GDPR, these are ours:
- Performance of a contract — processing your file, and running your account, are the service you asked for.
- Legitimate interests — rate limiting, abuse prevention, and keeping the service secure and working. We use the least identifying signal that achieves this, which is why IP addresses are hashed rather than stored.
- Legal obligation — where we must retain or produce something by law.
07How long anything lasts
Deleted at the end of the request that processed them. If a job crashes part-way, a clean-up sweep removes the leftover once it is an hour old; the sweep runs every half hour, so the worst case is about 90 minutes.
Retained while your account exists so that limits and usage history work. When you delete your account they are disassociated: the counts remain, but no longer point to you.
Expire 24 hours after sign-in, and immediately when you log out.
Roll forward on a one-hour window and are not built up into a history.
Held until you delete the account.
09Your privacy rights
What we collect, and whyYour account email, usage counts, and your files only while a job runs.
- Account email and name — to sign you in, and to send the confirmation and password-reset messages you ask for.
- Sign-in details — the browser type and IP address of each sign-in, kept with that session so it can be secured.
- Uploaded files — held only while the tool that needs them is running. They are never kept as a record about you.
- Usage records — which tool ran, when, whether it worked, and file sizes. Never a file name or anything inside a file. These enforce fair-use limits and keep the service running.
- A browser id and a scrambled network address for visitors without an account, so the free allowance counts per browser rather than per person.
No advertising trackers, no third-party analytics profile, and nothing is sold.
How long we keep itFiles go when the job ends. Your account stays until you delete it.
- Uploaded files — deleted as the request that processed them finishes. If a job crashes part-way, a clean-up sweep removes the leftover within about 90 minutes.
- SmartShrink works in several steps, so it holds your file between them — and deletes it as soon as the shrunk file is made, or after 30 minutes if you leave part-way.
- Account data — kept until you delete your account, then removed. Your past usage records are kept only as anonymous counts that no longer point to you.
- Sign-in sessions — end 24 hours after you sign in, or straight away when you log out.
Your rights under GDPR (EU, EEA and UK)Access, correction, deletion, portability and objection.
- Access — ask what we hold about you and get a copy.
- Correction — have anything inaccurate fixed.
- Deletion — delete your account yourself (below), or ask us to.
- Portability — receive your data in a common, machine-readable format.
- Objection and restriction — object to, or ask us to limit, how your data is used.
You may also complain to your national data protection authority. We would rather you came to us first, but you do not have to.
Your rights under CCPA (California)Know, delete, and opt out of sale — and we do not sell personal data.
- Right to know what personal information we collect, use and disclose.
- Right to delete personal information we hold about you.
- Right to opt out of sale or sharing. We do not sell personal information and do not share it for cross-context advertising, so there is nothing to opt out of — but you may still ask us to confirm that.
- No discrimination for using any of these rights.
Your rights elsewhereBrazil, Canada, India, Australia, Japan and South Korea.
The rights above are not limited to Europe and California. Wherever you are, you can ask what we hold, have it corrected, have it deleted, and take a copy with you:
- Brazil — LGPD (Lei Geral de Proteção de Dados).
- Canada — PIPEDA.
- India — the Digital Personal Data Protection Act.
- Australia — the Privacy Act and the Australian Privacy Principles.
- Japan — APPI.
- South Korea — PIPA.
We extend the same rights to everyone, whichever of these applies to you.
Delete your dataDo it yourself in a click, or ask us.
With an account: go to your dashboard and choose Delete my account. It is removed immediately and cannot be undone.
Without an account: delete the anonymous data kept against this browser.
For anything else — a copy of your data, a correction, or a question — write to support@kovapdf.com. We aim to reply within 30 days.
We follow GDPR and CCPA data protection principles
In practice: encrypted connections (TLS) for every upload, files deleted as soon as the job finishes, no sale of personal data, and every right above available to everyone.
10Using your rights
Depending on where you live you may have rights to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent. We extend the substance of these to everyone rather than checking your location first.
The Privacy Settings page is where each of these is actually exercised — it lists the control, what it does, and how to reach it. Anything not available as a self-service control can be requested at support@kovapdf.com, and we aim to respond within 30 days.
If you are in the EEA or the UK and think we have handled your data badly, you may complain to your national data protection authority. We would rather you came to us first, but you are not obliged to.
11International transfers
Our servers may be located in a different country from you, so using the service involves transferring data across borders. Where that means moving personal data out of the EEA or the UK, we rely on the appropriate safeguards for that transfer, such as the European Commission’s standard contractual clauses. Your uploaded documents are not part of any long-term transfer — they exist on the processing server only for the length of the request.
12Children
KovaPDF is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has created an account, write to support@kovapdf.com and we will remove it.
13Changes and contact
If we change how your data is handled in a way that matters, we will say so on the site before it takes effect rather than leaving you to notice.
Privacy questions and requests: support@kovapdf.com