Privacy Policy
Last updated: August 28, 2026
The short version
The core promise of PDFNinja is simple: your PDFs never leave your device. Every PDF tool (merge, split, compress, redact, convert, sign annotations, OCR, and all the rest) runs entirely in your browser using JavaScript and WebAssembly. No account, no upload, no tracking, no ads.
The only features that send data to a server are the optional AI tools and the eSignature workflow — described honestly below.
What happens to your files
For the local tools, your file is read into your browser's memory, processed on your device, and the result is offered back to you as a download. We never receive, transmit, or store the file. This includes Ghostscript compression, which runs a 15 MB Ghostscript engine inside your browser via WebAssembly.
We collect no analytics, no usage logs, and no telemetry. We do not use cookies for advertising, and we do not fingerprint your device.
AI features (Chat with PDF, Summarize, Transcribe, Text-to-Speech)
These tools use your own API key (bring-your-own-key). Your key is stored only in your browser's local storage and sent to the AI provider you choose (such as OpenAI) when you run a request. We never see or store your key.
When you run an AI tool, the extracted document text (for chat/summary) or your audio file (for transcription) is sent to the AI provider through our server simply as a relay. This text or audio is passed on to the provider you've configured, and we do not store it. Text is capped at 200,000 characters and audio at 24 MB per request.
Before using AI features with sensitive documents, check the privacy policy of the AI provider you choose. AI features are optional and are never enabled without your own key.
eSignature (Send & Sign)
The eSignature workflow intentionally uses a backend so signers can open and sign a document from any device. When you create an envelope, the following are stored securely in our Supabase database and storage:
- The PDF document you upload
- The signer's name and email address
- The signature, date, and text you place on the document
- Signing events (opened, signed, declined) and timestamps
Access is protected by unguessable, per-envelope tokens and database row-level security — no login or shared password is involved. Documents are retained so signers can access them, and you can request deletion at any time using the contact details below.
Local storage & cookies
We use a small amount of local storage for functionality only: your sidebar preference, an optional AI API key, and an authentication session if you use eSignature. None of this is used for advertising. You can clear it at any time through your browser settings.
Third parties
- Vercel — hosts the website and API routes.
- Supabase — hosts the database and file storage used by the eSignature workflow.
- AI providers (OpenAI or the base URL you configure) — receive document text or audio only when you run an AI tool with your own key.
- Ghostscript (WebAssembly) — runs locally in your browser; no data leaves your device.
Your rights & contact
You can request deletion of any eSignature documents or data at any time. For privacy questions, data requests, or deletions, email privacy@pdfninja.app.
Children & changes
PDFNinja is not directed at children under 13, and we do not knowingly collect their personal information. We may update this policy from time to time; changes will be posted on this page with a new "Last updated" date.
