Privacy Policy
Last updated 2026-08-24
PDFCheetah does its work inside your browser. This policy explains the narrow set of cases where any information reaches us at all, and what happens to it when it does.
The short version
- Your documents are processed on your device. They are not uploaded to us.
- You can use every tool without an account.
- We run no third-party analytics, no advertising, and no third-party trackers.
- We count how often each tool is opened, run, succeeds or fails, and how often a document will not open at all, so we can tell what is broken. It carries no cookie, writes nothing to your device, and uses no identifier that outlives the tab you are in or that can be linked to another visit.
- We do not sell or share your personal information.
Who we are, and how to reach us
PDFCheetah is operated by an individual rather than a company, trading as PDFCheetah. Where this policy says "we", that is who it means, and we are the controller of the small amount of personal information described below.
Email privacy@pdfcheetah.com about anything on this page, including a request to see, correct or delete what we hold. The contact page reaches the same person if you would rather use a form.
Your documents
Opening, previewing, editing and saving a PDF all happen locally in your browser. The file is read from your device, worked on there, and written back there. It is not sent to us, and there is no copy of it on our side to lose, read, or hand over.
This is enforced rather than promised. The application's Content Security Policy blocks unexpected network destinations, and an automated test suite watches every network request the application makes while a document is open. It permits exactly two: fetching one of our own versioned files, such as a stylesheet or a piece of the tool's engine, and sending the usage record described below. Both are checked against the document's contents, its filename and its exact bytes, and the test fails if either ever carries them.
While a job runs, working data may be written to a private storage area your browser reserves for this site. Your own file is removed from that area as soon as the job has produced a finished result and we have checked that the result opens. It is also removed when you start another job, when you leave the tool or cancel, and when you use the Delete local files control. If you then change something and export again, your file is read in from your device again rather than kept waiting in storage. The finished result stays until you leave the tool, because it is what you are about to download. Anything still there from an earlier session, including one where you closed the tab, is cleared the next time you open the app, once it is more than fifteen minutes old, so that an interrupted job can be picked up rather than lost.
One honest limit: this describes what our application does. It is not a claim about your device. A compromised computer, a malicious browser extension, or another person with access to your machine sits outside anything we can control.
When information does reach us
There are five cases. Two of them only happen if you choose them, and neither is needed to use any tool.
- Serving the site. Like any website, our host records the request: your IP address, browser user-agent, the page requested, and the time. This is needed to deliver the site and to protect it from abuse.
- Visiting a page. We record which kind of page you viewed — a tool, the tool list, a marketing page, a legal page such as this one, an account page, or anything else — and nothing else about the visit. Not the address of the page, and not what you typed into a search engine to find it. It carries no cookie, writes nothing to your device, and uses no identifier that outlives the tab you are in or that can be linked to another visit.
- Using a tool. We record which tool you opened, roughly how you arrived at it, how many files you chose as a range rather than an exact number, what your browser is capable of, whether a job started, whether it succeeded or failed, roughly how long it took, whether you downloaded the result, and an error code if the job failed or your document could not be opened at all. It carries no cookie, writes nothing to your device, and uses no identifier that outlives the tab you are in or that can be linked to another visit.
- Using the contact form. We receive the name, email address, subject and message you type into it.
- Asking to hear about Pro. If you give us your email address on the pricing page, we store that address so we can tell you once when Pro is ready. Nothing else is stored with it.
Why we are allowed to hold it
Data protection law asks us to name a reason for each of the five cases above. Ours are:
- Serving the site, the page-view record and the usage record — our legitimate interests. We need to deliver the site and defend it from abuse, and we need to know which kinds of page people reach, which tools they open, and which of them break. The record is deliberately built so that interest costs you as little as possible: no cookie, nothing written to your device, and no identifier that survives the tab. Because it stores nothing on your device and reads nothing from it, it needs no consent banner, which is also why you have not been asked to dismiss one.
- The contact form — our legitimate interests, in replying to a message you chose to send us. We use what you wrote to answer it, and for nothing else.
- Asking to hear about Pro — your consent, given by typing your address and pressing the button. You can withdraw it at any time by asking us to remove the address, and we will.
Where we rely on legitimate interests you can object, on grounds particular to your situation, and we will stop unless we have a reason that overrides them. The one thing we do on consent is the Pro email, and there you do not need to object at all — just ask us to remove the address. The section on your rights below says how to do either.
What we do not collect
- Nothing from inside the documents you open: not their contents, names, sizes, page counts, or anything read out of them. We do record which tool ran, whether it worked, and how many files you chose as a range rather than an exact number — facts about the job you started rather than about the files themselves.
- No advertising networks, social media pixels, or third-party tracking scripts.
- No profiling, and no automated decision-making about you.
- No document contents, filenames, passwords or document metadata in any diagnostic or error report.
What is stored on your device
We use no advertising or tracking cookies. The site stores two things locally, both of them functional:
- Temporary working data for a job in progress, described above.
- A cache of the application's own files, so tools keep working when you go offline.
Who else handles this information
We keep this list short deliberately, and it is complete:
- Cloudflare, which hosts and delivers the site, and stores the tool usage records described above.
- Supabase, which stores contact form messages and Pro interest email addresses.
- Hostinger, which handles email for pdfcheetah.com, so anything you send to the address above passes through them on the way to us.
Where in the world it is
Your documents are not part of this at all. They stay on your device, so there is nothing of them to move anywhere.
The three companies above are international, and the small amount of information they hold for us — the request records, the usage counts, contact messages and Pro email addresses — may be stored or processed outside the United Kingdom. Each of them publishes data protection terms that include the transfer safeguards UK law recognises, and those terms are part of our agreement with them. If you want to see the current version for any one of them, email us and we will point you at it.
How long we keep it
- Server request records: kept by our host for a short period, for delivery and security. We take no copy of our own. Where a form is rate-limited, your address itself is still never written down — it is turned into a scrambled fingerprint that cannot be turned back, and only that is stored, next to a count of how many times that form has been submitted. The scrambling key changes every hour, and each old key is deleted together with the counts it was used for: usually within minutes, and at the latest by the following night, when a scheduled clear-out runs. Once a key is gone the link cannot be rebuilt, even by us. Two honest limits: while an hour is running, someone holding both the key and the counts could work out which addresses they came from — so treat this as a short-lived stand-in for your address rather than as anonymous — and on a quiet night an old key can sit unused until that clear-out reaches it.
- Tool usage records: 28 days, after which they are deleted automatically. The same applies to the page-view records described above, which are kept in the same place and expire on the same schedule. What remains is daily totals — how many times a tool ran and how many succeeded — which are not about any one visit and cannot be traced back to one.
- Contact form messages: for as long as needed to deal with what you wrote about.
- An email address you gave us for Pro: until Pro launches and we have written to you, or until you ask us to remove it.
- Working data on your device: your own file, until the job has produced a finished result we have checked opens — then it is deleted. The result itself, until you start another job, leave the tool, or delete it yourself. Anything older than fifteen minutes is cleared the next time you open the app.
Your rights
Under UK data protection law you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use of it, object to our using it, and ask for it in a portable form. Email privacy@pdfcheetah.com and we will respond within one month. The contact page reaches the same person, but email is the faster route for a request about your own data.
If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.
Children
PDFCheetah is not aimed at children. There are no accounts, and the only information a child could give us is a message on the contact page or an email address on the pricing page. If you believe a child has given us either, contact us and we will delete it.
Changes to this policy
If this policy changes we will update this page and the date at the top of it. Where a change materially affects how we handle information you have already given us, we will say so rather than rely on you noticing a new date.
Contact
Questions about this page, or a request about your information, go to privacy@pdfcheetah.com, or through the contact page.