PDFAutoPilot

Legal

Cookie Policy

Last updated:

This policy explains how PDF AutoPilot uses cookies and similar technologies — including browser localStorage — on autopdfpilot.tech. It is short, because there is not much to tell: as of the date above, PDF AutoPilot itself sets no cookies.

We do keep a small amount of data in your browser's localStorage so the product works — your sign-in session, your interface preferences, and a history of your own tool runs that never leaves your device. Privacy laws such as the EU ePrivacy rules treat this kind of on-device storage like cookies, so we describe all of it here, along with exactly what will change if we launch advertising and analytics in the future.

The short version

  • PDF AutoPilot itself sets no cookies today. Not for advertising, not for analytics, not even for signing in. Your session is kept in localStorage, not a cookie.
  • No advertising, analytics, or cross-site trackers run today. There is no Google Analytics, no ad code, and no tracking pixels on the site.
  • We use four localStorage keys, all functional: your sign-in session, interface preferences, a device-only history of your tool runs, and your light/dark theme choice.
  • Google may set its own cookies on sign-in pages. When a page or dialog showing the “Sign in with Google” button loads, your browser loads Google's sign-in script — see below.
  • Stripe sets its own cookies on its checkout pages (checkout.stripe.com) when you buy credits.
  • If we launch advertising or analytics, they will run only behind a consent manager where the law requires consent, and we will update this policy first.

What cookies and similar technologies are

Cookies are small text files a website asks your browser to store and send back on later visits. Similar technologies include localStorage and IndexedDB, which let a site save data on your device without automatically sending it anywhere. The rules that govern cookies apply to these technologies too, which is why this policy covers them.

What we store today

PDF AutoPilot stores four items in your browser's localStorage. None of them track you across other websites and none are shared with third parties, which is why they qualify as strictly necessary or user-requested functional storage and do not require a consent banner.

  • folio-auth — your sign-in session: a bearer token plus a cached copy of your profile and credit balance. The token accompanies your requests to our API so we know it is you; that is what keeps you signed in. Created when you sign in; cleared when you sign out (the token and cached profile are removed — the empty entry may remain until you clear site data).
  • folio-ui — interface preferences you have chosen, such as whether the sidebar is collapsed and when you last opened notifications. Stays on your device.
  • folio-activity — a local history of your own tool runs (up to 60 entries: tool name, file sizes, page counts, timestamps — never your files themselves). This history is stored only on your device and is never transmitted to us. You can clear it any time in Settings → Privacy & data.
  • theme — your light/dark mode preference. Stays on your device.

These items persist until you clear them or delete the site's data in your browser; signing out clears the contents of folio-auth. If we introduce a consent manager (see below), it will also store your consent choices on your device — storage that exists purely to remember what you said no to, and is itself exempt from consent.

Third-party services that may set cookies

  • Google Identity Services — when a page or dialog showing the “Sign in with Google” button loads, your browser loads Google's sign-in script from accounts.google.com, and Google may set its own cookies as part of providing that button. This happens only on sign-in surfaces — not across the rest of the site — and is required to offer Google sign-in. See Google's Privacy Policy.
  • Stripe — credit purchases happen on Stripe's own checkout pages (checkout.stripe.com), where Stripe sets cookies for payment processing and fraud prevention. Those pages are governed by Stripe's privacy policy.

What will change when advertising and analytics launch

We plan to introduce advertising and analytics in the future. None of the following is active today. Before any of it goes live, we will update this policy and the date at the top, and — where the law requires it — ask for your consent first.

  • Analytics cookies — Google Analytics 4 (not currently in use; will activate only with your consent where consent is required): cookies such as _ga that measure how the site is used. We will cap analytics data retention at 14 months, link how Google uses information from sites that use its services, and you will be able to opt out via the consent manager or the GA opt-out browser add-on.
  • Advertising cookies — third-party vendors, including Google (not currently in use; will activate only with your consent where consent is required): cookies used to serve ads based on your prior visits to this and other websites. You will be able to opt out of personalized advertising at Google Ads Settings and aboutads.info/choices (in the EEA, youronlinechoices.eu). Current cookie details will be available on Google's cookie page.

How consent will work:

  • EEA, UK, Switzerland, and Quebec: nothing non-essential will run before you affirmatively consent, collected through a Google-certified consent manager integrated with the IAB Transparency & Consent Framework. Rejecting will be as easy as accepting — you will be able to refuse and keep using PDF AutoPilot — and a persistent “Cookie settings” link will let you change or withdraw your consent at any time. The full list of vendors and their purposes will be available in the consent manager's preference panel. We will run Google Consent Mode in basic mode: no Google advertising or analytics tags load at all until the consent signals (ad_storage, ad_user_data, ad_personalization, analytics_storage) are granted.
  • Japan: cookie and analytics identifiers will be shared with advertising or analytics providers only with your consent or where they cannot be linked to you as an identified individual.
  • United States: today we do not sell or share personal information as defined by the CCPA and we set no cookies, so opt-out preference signals such as Global Privacy Control currently have no effect on our processing. If we launch advertising that involves sharing personal information, we will add a “Your Privacy Choices / Do Not Sell or Share My Personal Information” control and honor Global Privacy Control signals as required by law.

Your choices

Today:

  • Clear your activity history in Settings → Privacy & data inside PDF AutoPilot.
  • Sign out to clear your session — the token and cached profile are removed from folio-auth (the empty entry may remain until you clear site data).
  • Clear all site data in your browser's settings: Chrome, Safari, Firefox, Edge. Note that clearing site data signs you out and erases your local activity history and preferences.

Once advertising or analytics launch, the consent manager banner and the persistent “Cookie settings” link will let you accept, reject, or change your choices at any time, with withdrawal as easy as consent.

Changes to this policy

We will update this page and the date above whenever our use of cookies or similar technologies changes. For material changes — such as the launch of advertising or analytics — we will give notice in the product before the change takes effect.

Contact

Questions about this policy: privacy@autopdfpilot.tech.