Privacy Policy
Last updated: December 2025
Introduction
AllPDFMagic ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our PDF tools and services. This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.
Data Controller
AllPDFMagic is the data controller responsible for your personal data.
- Contact Email: support@allpdfmagic.com
- Website: https://www.allpdfmagic.com
Information We Collect
We collect the following types of information:
- Account Information: Email address and password when you create an account.
- Usage Data: Information about how you use our services, including tool usage and timestamps.
- Files: PDF files you upload for processing. These are automatically deleted after processing.
- Device Information: Browser type, IP address (anonymized), and device type for analytics.
- Cookies: Small text files stored on your device. See our Cookie Policy for details.
Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our PDF tools and services you requested.
- Legitimate Interests: Analytics to improve our services, security measures, and fraud prevention.
- Consent: For non-essential cookies (analytics, marketing) and optional communications.
- Legal Obligation: When required by applicable law or regulation.
How We Use Your Information
- To provide and improve our PDF tools and services
- To process your documents as requested
- To communicate with you about your account or our services
- To enforce our terms and prevent abuse
- To analyze usage patterns and improve user experience (with consent)
Third-Party Services
We use the following third-party services to operate our platform:
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, Authentication | United States |
| Vercel | Website Hosting | United States |
| Google Analytics | Analytics (with consent) | United States |
| Stripe | Payment Processing | United States |
International Data Transfers
Your data may be transferred to and processed in the United States where our service providers operate. These transfers are protected by appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission. We ensure that any international transfer of personal data is subject to appropriate security measures.
Data Processing Agreements (DPAs)
We have Data Processing Agreements in place with all our third-party service providers to ensure your data is protected in accordance with GDPR and other applicable data protection laws.
| Service Provider | DPA Status | Compliance |
|---|---|---|
| Supabase | ✅ DPA Signed | SOC 2 Type II, GDPR, HIPAA |
| Vercel | ✅ DPA Signed | SOC 2 Type II, GDPR, ISO 27001 |
| Google (Analytics) | ✅ DPA via Terms | GDPR, ISO 27001, SOC 2/3 |
| Dodo Payments | ✅ DPA Signed | PCI DSS, GDPR |
| Railway (API Hosting) | ✅ DPA Signed | SOC 2 Type II, GDPR |
For copies of our Data Processing Agreements or additional compliance documentation, please contact us at support@allpdfmagic.com.
File Security
Your files are encrypted during transfer using SSL/TLS. Files are processed in memory and automatically deleted from our servers after processing. We do not access, view, or share the contents of your files.
Data Retention
- Uploaded Files: Automatically deleted within 1 hour of processing.
- Account Data: Retained until you delete your account.
- Usage Logs: Retained for 90 days for security and analytics.
- Payment Records: Retained as required by law (typically 7 years).
Your Rights Under GDPR
If you are in the European Economic Area (EEA), you have the following rights:
- Right of Access (Art. 15): Request a copy of your personal data.
- Right to Rectification (Art. 16): Correct inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data.
- Right to Restriction (Art. 18): Limit how we process your data.
- Right to Data Portability (Art. 20): Receive your data in a portable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing.
To exercise these rights, contact us at support@allpdfmagic.com. You also have the right to lodge a complaint with your local data protection supervisory authority.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to Know: What personal information we collect and how it's used.
- Right to Delete: Request deletion of your personal information.
- Right to Opt-Out: Opt out of the sale of personal information.
- Right to Non-Discrimination: Equal service regardless of privacy choices.
📢 We Do Not Sell Your Personal Information. AllPDFMagic does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration.
Automated Decision-Making
We use AI and automated processes to provide PDF tools (e.g., OCR, translation, summarization). These are technical operations to deliver the services you request and do not make decisions that produce legal effects or significantly affect you. You can always contact us for human review.
Cookies and Tracking
We use cookies to provide essential functionality and, with your consent, for analytics. You can manage your cookie preferences at any time using the cookie settings in the footer of our website. For more details, see our Cookie Policy.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at support@allpdfmagic.com