← All tools
DAMNPDFS / INFORMATION

Your files stay close.

What we process, what we retain, and how you can clear it.

Document processing

Browser tools process your files on your device. The processing badge identifies the location before you run an operation. Temporary cloud processing uploads the selected files to a private Google Cloud Storage bucket and uses short-lived worker folders.

Cloud copies are deleted when the completed job is acknowledged or cancelled, or when their one-hour expiry is reached. Cleanup runs independently of document workers. Cloud documents are separate from sponsorship and payment records.

Local storage and downloads

Your latest workspace may be saved in this browser’s IndexedDB, up to 100 MB, for at most four hours. Re-saving does not extend a file’s deadline. Invoice drafts have the same four-hour limit. Expired copies are removed while the app is open; when the browser is closed, they are removed before restoration on your next visit.

Use Privacy & local data to clear document copies immediately. Downloads you save yourself are under your control. Theme, favourites and reusable workflow presets stay on your device until you clear them or browser storage.

Tool engines, fonts and local AI/OCR model downloads can be cached separately from documents. Use Clear offline cache in Privacy & local data to remove stored offline copies without deleting your document workspace.

AI providers

You choose the provider, model and API key for external AI features. Your key stays in tab memory for the session and is excluded from document metadata, payment records and application logs. A transient relay is used when the provider cannot be called directly from the browser.

Selected document content is sent to your chosen provider when you run an external AI operation. The provider’s terms and retention rules apply to that processing. Local OCR and built-in models do not require an external API key. Forget the key in AI settings whenever you finish.

Sharing and feedback

Peer-to-peer file transfers use WebRTC encryption, recipient acceptance and an integrity check. Room signaling, chat and whiteboard updates use temporary server coordination. Rooms expire after one hour. Reviews you choose to submit are public; avoid including personal or document information.

Sponsors and payment records

Sponsor names, logos and destination links are public while their advertisements are active. Contact details, subscription identifiers, paid coverage, refunds and private management access are retained separately in our payment database. These business records are not deleted by the temporary-document expiry.

Razorpay processes checkout and recurring payments. Card details and payment authentication are handled by Razorpay; our application verifies payment identifiers and signed notifications.

Usage and operational data

Vercel Web Analytics measures anonymous page visits and traffic sources; Speed Insights measures page performance. Our first-party analytics records public page/tool IDs, tool starts and outcomes, coarse click locations, navigation/control categories, coarse device size, approved campaign labels and time spent on visible pages. Agent activity is counted separately from human tool runs. We do not record document contents, filenames, typed values, AI keys or payment credentials. Private document previews, drawings and form content are excluded from click capture. URL query strings and fragments are removed from analytics URLs.

Usage analytics starts automatically without a permission banner. First-party measurement uses a random session identifier in tab memory and a random browser identifier in local storage for at most 90 days. If local storage is unavailable, measurement uses the session identifier only. It helps estimate active browsers across days; it does not identify a person. Active-browser counts use anonymous aggregate sketches, with approximately 3.25% relative estimation error. Raw events contain no browser/session identifier, expire after 90 days and are kept in the private DamnPDFs Firestore database; daily aggregates expire after 400 days. These records are separate from temporary documents and payment records.

Do Not Track and Global Privacy Control signals take priority. You can remove the random browser identifier by clearing this site’s browser storage. Ad blockers, browser privacy signals and offline visits can reduce measured totals. Historical aggregate sketches cannot be linked back to, or individually removed for, a browser.

The earlier successful-use counter contains no stable visitor identifier and expires after thirty days; duplicate-event markers expire after two days. Operational request logs omit query strings, credentials and document bodies. Admin analytics requires private server authorization; it is not exposed through the public tool catalog.

Questions or record requests

Use the contact page for privacy questions, corrections or requests concerning sponsorship and feedback records.