Legal
Privacy Policy
Last updated:
PDF AutoPilot is a document workspace built to keep your files close to you. Most of our tools run entirely in your browser — for those tools, your files are never uploaded and never reach our servers. Where a feature does need our servers (tools marked “Server”, AI features, Cloud Storage, eSign, your account), this policy explains exactly what we process, why, and for how long.
This policy covers everyone who interacts with PDF AutoPilot: visitors, account holders, developers using our API — and people who have been asked to sign a document through PDF AutoPilot eSign, even if they have never created an account. If someone sent you a signature request, the section “If someone asks you to sign a document” is written for you.
The short version
- Most tools run in your browser. Files you use with in-browser tools never leave your device and we never see them.
- Server tools delete your files immediately. Tools marked “Server” upload your file for processing and delete it as soon as processing completes — whether it succeeds or fails. We keep operational logs about the run, not your files.
- AI features send text to our AI provider only when you use them. We extract text from your document and send that text to Anthropic to generate the result you asked for. We do not use your content to train AI models.
- We do not sell personal information. There is no advertising and no analytics. PDF AutoPilot itself sets no cookies — if you use Google Sign-In or Stripe checkout, those providers may set their own cookies; see the Cookie Policy.
- If you were asked to sign a document, the sender gave us your name and email address. When you sign (or decline), we record your signature, IP address, and timestamps in an audit trail, and your name, email, IP address, and signing time appear on the completion certificate visible to the sender and other signers.
- You are in control. You can delete files, chats, and signature requests, revoke API keys at any time, and deleting your account permanently removes your files and content from our systems.
Who we are
PDF AutoPilot is operated by the operator of PDF AutoPilot (“PDF AutoPilot”, “we”, “us”). For the personal data described in this policy, we are the data controller.
Contact us at privacy@autopdfpilot.tech. This contact also serves as our Privacy Officer for Canada (PIPEDA), the person in charge of the protection of personal information for Quebec (Law 25), our data-protection contact (encarregado) for Brazil (LGPD), and our Grievance Officer for India (DPDP Act).
Where the law requires us to appoint a local representative (for example, an EU or UK representative), their details will be published in this section once appointed.
Your files and documents
Tools that run in your browser
Most PDF AutoPilot tools process files entirely on your device. The file is opened, transformed, and saved locally by your browser — it is never transmitted to us, and we have no record of its contents or its name.
Tools marked “Server”
Some operations (such as OCR and office-document conversions) need more processing power than a browser provides. These tools are clearly marked “Server” in the interface. When you use one:
- Your file is transmitted to our processing server over an encrypted (TLS) connection.
- The file is deleted immediately after processing completes or fails. We do not keep copies of the files or the results.
- We keep operational metadata about the run — which tool was used, timestamps, file sizes, processing duration, and success or failure. For document conversions, our logs also include a sanitized version of the file name.
We do not read, analyze, or profile the contents of your files except as necessary to perform the specific operation you request, and we do not use file contents to build profiles or infer anything about you.
Cloud Storage (“My Files”)
Cloud Storage is opt-in: nothing is stored unless you deliberately save a file to My Files. Files you save are kept until you delete them. Deleting a file moves it to your trash, where it remains (and still counts as stored data) until you empty the trash — trash is not emptied automatically today. Storage quotas apply, and your current usage is shown in My Files. Deleting your account permanently removes all stored files, including trash.
AI tools
When you use an AI feature (such as chat with a document, summarize, or translate), we extract the text of your document and send that text — not the file itself — to our AI model provider, Anthropic, which processes it on our behalf to generate the response. This happens only when you actively use an AI tool.
- Chat: if you are signed in, your chat history is stored with your account until you delete it or delete your account. It is not deleted automatically.
- Summarize and translate: results are returned to you and are not stored by us.
- We do not use your content to train AI models, and our provider processes it under contractual terms that do not permit it to be used for model training.
PDF AutoPilot eSign
If you send documents for signature
When you create a signature request, we store the PDF you upload, the names and email addresses of the signers you add, the request's status, and a complete audit trail of the signing process — including each signer's IP address, signature image, and timestamped audit events for the request (created, sent, signed, declined, completed). This is retained so that you have evidence of who signed what, and when. As the sender, you can see signer details, and the completion certificate showing each signer's name, email, signing time, and IP address is part of the completed document.
You are responsible for the documents you send: you must have the right to process their contents and to send them to the signers you designate, and the signer contact details you provide must be accurate. PDF AutoPilot processes the documents on your instructions to provide the signature service. Signature requests, documents, and audit trails are not deleted automatically — they are kept until you delete them or delete your account. Signing links do expire (30 days by default, up to 365 days), after which a pending request can no longer be signed.
We use signer email addresses solely to deliver the invitation and complete the signature workflow. They are never added to any marketing list.
If someone asks you to sign a document
This section is our privacy notice to you as a signer. You do not need a PDF AutoPilot account to sign, and this notice applies even though you have no other relationship with us.
- Where your data came from: the person who sent you the signature request (the sender) provided us with your name and email address so we could deliver their document to you.
- What we process: your name and email address, the contents of the document you are asked to sign, and — when you act on the request — your signature image and timestamped audit events recorded when you sign or decline (together with your IP address).
- What others can see: your name, email address, signing time, and IP address are printed on the completion certificate attached to the signed document, which the sender and the other signers can see.
- Why we process it: we have a legitimate interest in operating the signature workflow the sender requested and in maintaining a tamper-evident audit trail as evidence of the signature (including for the establishment, exercise, or defense of legal claims).
- The signing link sent to you is a private, unique token. Do not forward it — anyone with the link can view the document. The signing link expires (30 days by default), after which the request can no longer be signed through it.
- You can decline directly on the signing page. If you decline, that fact (and any reason you provide, together with your IP address) is recorded in the audit trail and visible to the sender.
- How long we keep it: the request, document, and audit trail are retained until the sender deletes them or deletes their account.
- Your rights: you have the rights described in Your rights and controls below. For questions about the document itself, contact the sender; for questions about our processing, contact privacy@autopdfpilot.tech.
Account information
You sign in to PDF AutoPilot with Google Sign-In — we do not operate our own passwords. When you sign in, Google provides us with exactly these details from your Google account: your account identifier, email address, name, and profile picture. We use them to create and operate your account and to send you service messages about your account and activity (for example, signature-request notifications). We do not currently send marketing email.
Payments
Credit purchases are handled by Stripe Checkout. Your card details are entered directly with Stripe — we never see or store your card number. We keep records of your purchases: what you bought, the amount, the time of purchase, and Stripe's transaction identifiers. We keep these records to deliver your credits, maintain your credit ledger, prevent fraud, and meet tax and accounting obligations — which is why purchase records are retained even if you later delete your account.
Developer API
If you create API keys, we store them hashed — we cannot see or recover your key after it is shown to you once. For each API request we record usage metering data: the endpoint called, response status, request size, and processing duration. We do not record your IP address in API usage rows. Usage rows are kept for billing, quota, and abuse-prevention purposes; see How long we keep things for what happens to them when you delete your account.
Data stored on your device
PDF AutoPilot stores a small amount of data in your browser's local storage (this is not a cookie and is never sent to third parties):
folio-auth— your sign-in session: an authentication token, your basic profile (name, email, picture), your credit balance, and sign-in status. Required for staying signed in.folio-ui— interface preferences you set: sidebar collapsed state and the time you last opened notifications.folio-activity— your local activity history: up to 60 recent tool runs (tool name, a summary such as “Merged 3 PDFs”, file sizes, page counts, timestamp, success/failure, and whether the server was used). This history exists only on your device and is never transmitted to us. Clear it anytime in Settings → Privacy & data → Clear history.theme— your light/dark appearance preference.
All of this storage exists solely to provide features you use. You can remove it at any time through your browser's site-data settings; signing out clears your session.
How we use information, and our legal bases
Where laws such as the EU/UK GDPR apply, we rely on the following legal bases:
- Performance of our contract with you: operating your account, in-browser and server tools, Cloud Storage, AI features you invoke, eSign requests you send, credit purchases, the developer API, and service messages.
- Legitimate interests: keeping the service secure and available — including per-IP rate limiting, abuse and fraud prevention, and security logging (network and information security); operating the signature workflow and audit trail requested by an eSign sender (this covers signer data); and defending legal claims.
- Legal obligation: retaining purchase and transaction records for tax and accounting law.
- Consent: none of our current processing relies on consent. If we ever introduce advertising, analytics, or marketing email, those will run on consent, which you could withdraw at any time without affecting other processing.
Providing personal data: you are never under a statutory obligation to provide us personal data. Where data is needed to create your account or deliver a feature you request, providing it is a contractual requirement — we cannot provide that feature without it.
Sensitive information: we do not intentionally collect sensitive personal information (such as health data, precise geolocation, government identifiers, or biometric data) and ask that you not submit it to us other than as content of files you control.
Automated decision-making: PDF AutoPilot makes no decisions producing legal or similarly significant effects about you based solely on automated processing. AI tools run only at your explicit request and produce documents, not decisions. Rate limiting is an automated security measure that only throttles request volume.
Who receives your data
We share personal data only with the categories of service providers needed to run PDF AutoPilot, each processing data on our instructions:
- Hosting and infrastructure providers (servers, storage, databases, content delivery) for everything stored or processed server-side.
- Google, when you choose Google Sign-In.
- Stripe, our payment processor, when you buy credits.
- Anthropic, our AI model provider — it receives the extracted text of your document only when you use an AI tool.
- Email delivery provider, to send service messages and eSign invitations.
- eSign participants: when you send or sign a document, the other parties to that request see the document and completion certificate as described above.
- Advertising partners (future, conditional): only if advertising launches, and in the EEA/UK/Switzerland and similar regions only with your consent.
We do not sell personal information. We may also disclose data where required by law, to protect our rights or users' safety, or as part of a corporate transaction (with notice to you).
International transfers
We and our service providers operate internationally, so your information may be processed in countries other than your own, including the United States, whose laws may differ from those of your country. Where data protected by EU, UK, or Swiss law is transferred to such countries, we rely on an adequacy decision where one exists, and otherwise on the EU Standard Contractual Clauses (supplemented where needed), the UK International Data Transfer Addendum, or safeguards recognized by Swiss law. You can request a copy of the relevant safeguards at privacy@autopdfpilot.tech.
How long we keep things
We keep personal data only as long as needed for the purposes above. In practice, honestly stated:
- Server-tool uploads: deleted immediately after processing completes or fails; only operational metadata (including a sanitized file name for conversions) remains in logs.
- Cloud Storage files: until you delete them; trashed files until you empty the trash (no automatic emptying today).
- eSign requests, documents, and audit trails: until the sender deletes them or deletes their account — they are not deleted automatically, though pending signing links expire (30 days by default, up to 365 days).
- AI chat history: until you delete it or delete your account (no automatic expiry today).
- Operational and security logs (including server-tool run metadata): kept only as long as needed for security, troubleshooting, and abuse prevention, then deleted or aggregated.
- Rate-limit counters: kept per IP address for short rolling windows — currently one minute — and expire automatically.
- API usage rows: retained for billing and abuse prevention; see account deletion below.
- Purchase records: retained as long as tax and accounting law requires.
When you delete your account: your files (including trash), eSign requests, documents and audit trails, and AI chats are permanently deleted, and your user record is anonymized so it no longer identifies you. Your API keys are permanently revoked and can never be used again; we retain the hashed key records and their usage rows, which no longer identify you once your account record is anonymized. We also retain purchase records (for tax and accounting law) and detached credit-ledger rows that are no longer linked to your identity.
Your rights and controls
Start with the built-in controls — they are the fastest way to exercise most rights: delete files and empty trash in My Files, delete chats, delete or void signature requests, revoke API keys, clear local activity history (Settings → Privacy & data), and delete your account entirely in Settings.
Beyond that, we extend a baseline of privacy rights to all users, wherever you live: the right to know what personal data we hold about you and get a copy of it, to receive it in a portable machine-readable format, to correct it, to delete it, to object to or restrict certain processing, and to withdraw any consent. Send requests to privacy@autopdfpilot.tech; we will verify your identity (normally by confirming control of your account email) and respond within the time required by applicable law. If we refuse a request, we will explain why, and you may appeal by replying to our decision. We will never discriminate against you for exercising your rights. Availability and scope of specific rights may vary by jurisdiction, and requests are subject to legal retention needs (for example, purchase records we must keep).
European Economic Area and United Kingdom
You have the rights of access, rectification, erasure, restriction, data portability, and the right to object — including to any processing based on our legitimate interests (such as security logging or the eSign audit trail, subject to compelling grounds) and, unconditionally, to any direct marketing (we currently send none). Where processing rests on consent, you may withdraw it at any time without affecting prior processing. You may lodge a complaint with the supervisory authority in your EU member state, or in the UK with the Information Commissioner's Office (ico.org.uk).
California and other US states
Depending on your state, you may have rights to know/access, correct, delete, and port your data, to opt out of “sale,” “sharing,” and targeted advertising, to limit use of sensitive personal information, to non-discrimination, and to appeal a refusal. What we collect, in state-law categories: identifiers (name, email, Google account ID — sources: you and Google; disclosed to our infrastructure, email, and payment providers), commercial information (purchase records — from Stripe and you; disclosed to Stripe), internet/electronic activity (operational logs, API usage — from your use of the service; disclosed to infrastructure providers), and user-provided content (files, documents, signatures, chat text — from you or an eSign sender; disclosed to infrastructure providers and, for AI features only, Anthropic). We collect no sensitive personal information as a category requiring a “Limit” link, and we do not sell or share personal information as defined by these laws — for any category. We will respond to verified requests within 45 days, extendable once by a further 45 days where reasonably necessary (we will tell you if we need the extension). Because we do not sell or share, opt-out preference signals such as Global Privacy Control currently have no effect on our processing; if we introduce advertising that involves sharing, we will honor them as required by law and update this policy first.
Brazil (LGPD)
You have the rights to confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about sharing, revocation of consent, review of solely automated decisions (we make none), and to petition the ANPD. International transfers use safeguards permitted under the LGPD.
Canada (including Quebec)
Our Privacy Officer is reachable at privacy@autopdfpilot.tech; you may access and correct your personal information and complain to the Office of the Privacy Commissioner of Canada. Quebec residents: the person in charge of the protection of personal information can be reached at the same address; your personal information may be communicated to and stored outside Quebec, including in the United States; you have rights of access, rectification, cessation of dissemination/de-indexing, and portability, and may complain to the Commission d'accès à l'information.
Australia
This policy describes what we collect, why, and how to access and correct it. Your information may be disclosed to overseas recipients, including in the United States and other countries where our service providers operate. We do not make computer-based decisions that significantly affect your rights or interests. Complaints: contact us first at privacy@autopdfpilot.tech; if unresolved, you may complain to the OAIC.
India
You may access, correct, and erase your personal data, nominate another person to exercise your rights, and seek grievance redressal from our Grievance Officer at privacy@autopdfpilot.tech, who will respond within the period required by law. You may escalate to the Data Protection Board of India.
Japan, South Korea, Switzerland, Nigeria, and elsewhere
Japan: our purposes of use are stated in this policy; personal data is stored and processed in foreign countries, including the United States, whose protections may differ; you may request disclosure, correction, and cessation of use via privacy@autopdfpilot.tech. South Korea: you may request access, correction or deletion, and suspension of processing; retention and destruction follow How long we keep things. Switzerland: this policy identifies the controller, purposes, and recipient categories; data is transferred to the United States and other countries where our providers operate, using safeguards recognized by Swiss law; you have rights of access, rectification, and deletion. Nigeria: you have rights of access, correction, erasure, and objection, and may complain to the Nigeria Data Protection Commission. PDF AutoPilot is not directed at, and not intended for use by, individuals located in mainland China.
Security
We protect your data with TLS encryption for all data in transit and hashed storage of API keys, and we design the service so that every account-scoped request is authenticated and each user can only reach their own files, requests, and chats. Server-tool files are deleted immediately after processing completes or fails, which limits what an incident could ever expose. No online service can guarantee absolute security, and we make no such claim — but we design so that the most sensitive path, your everyday files, never reaches us at all.
Children
PDF AutoPilot is not directed at children. You must be at least 13 to use PDF AutoPilot — or, in the EEA and UK, at least the age at which you can validly consent to the processing of your personal data in your country (between 13 and 16) — and under 18 you need a parent or guardian's permission. We do not knowingly collect personal information from children under 13; if you believe a child has provided us personal information, contact privacy@autopdfpilot.tech and we will delete it.
Changes to this policy
We may update this policy as PDF AutoPilot evolves — in particular, before any launch of advertising or analytics. For material changes we will give you advance notice by email or a prominent in-product notice before they take effect, and we will not apply materially new practices to previously collected data without the notice or consent the law requires. The date at the top always tells you when the current version took effect.
Contact
Privacy questions and rights requests: privacy@autopdfpilot.tech Legal notices: legal@autopdfpilot.tech
If we appoint an EU or UK representative, their contact details will be published in Who we are.