Draft — pending legal reviewThis document reflects how the service actually operates, but has not yet been reviewed by a lawyer. It is not yet binding.

Privacy Policy

Version 2026-09-10

1. The two kinds of data here

This distinction matters more than anything else in this document.

Your account data — your name, email, company, plan and usage. We decide how this is handled, so we are the controller of it.

The content you send us to render— the HTML of your invoices, contracts or statements, which frequently contains your own customers' personal data. We only process this to produce the document you asked for. You remain the controller; we act as your processor and do nothing else with it.

2. What we collect, and why

DataWhy
Email, name, companyTo create and identify your account
Password (hashed, never stored in plain text)To sign you in
Acceptance of these documents — version, time, IP, browserTo evidence consent, as the law requires
API keys (hashed)To authenticate your requests
Usage records — timestamps, sizes, durations, statusTo meter credits, bill correctly and answer support questions
The submitted HTML and the produced PDFTo render the document and to make it retrievable from your dashboard
Payment recordsLegally required accounting records

We do not sell your data, we do not use your documents to train models, and we do not read the content you render except where you explicitly ask us to investigate a specific problem.

3. How long we keep it

Rendered documents and the submitted HTMLare deleted on your plan's retention window — 7 days on Free, 30 on Base and Startup, 90 on Boost, 180 on Growth, 365 on Enterprise. If you use your own storage bucket, the document is written there and your retention rules apply, not ours.

Account data is kept while your account is open. After closure it is recoverable for 30 days, then erased or anonymised.

Billing records and consent records outlive the account: the first because accounting law requires it, the second because a record proving consent that deletes itself along with the account cannot answer the question it exists for.

4. Who else processes it

These are our subprocessors. Each one holds only what its purpose requires.

ProviderPurposeLocation
Oracle CloudRuns the rendering serviceMumbai, India
SupabaseDatabase — accounts, keys, usageMumbai, India
UpstashRate-limit and quota countersMumbai, India
Cloudflare R2Stores rendered documentsAsia-Pacific
ResendSends verification and account emailUnited States
RazorpayProcesses paymentsIndia
VercelServes the dashboardGlobal edge network

We will give notice before adding a subprocessor that handles rendered content.

5. How it is protected

Everything travels over TLS. Passwords are hashed with bcrypt and API keys are stored as hashes, so neither can be read back from our database. If you connect your own storage bucket, those credentials are encrypted at rest with a key held only in our production environment. Access to production data is limited to people who need it.

6. Your rights

You can ask for a copy of your data, correct it, delete it, or object to how we use it. Account closure and erasure are available from the dashboard without asking us. For anything else, write to privacy@pdfspectrum.com and we will respond within 30 days.

Where the content you rendered contains someone else's personal data, requests from that person should go to you — you are the controller of it, and we will assist you in answering them.

7. Cookies

The dashboard stores a session token so you stay signed in, and a small number of preferences in your browser. We do not use advertising or cross-site tracking cookies.

8. Changes

The version in force is shown at the top of this page. For material changes we will email the address on your account before they take effect.

9. Contact

privacy@pdfspectrum.com