Privacy Policy
Last updated: Sep 1, 2026
This Privacy Policy explains what information PDFCraft ("we", "us") collects when you use https://snapdfhub.com (the "Service"), why we collect it, and the choices you have. It is written to match how the Service actually works. If you operate your own copy of PDFCraft, edit this document to reflect your deployment.
Summary
- Most tools process your documents entirely inside your browser. Those files are never transmitted to our servers.
- Tools that require server processing (for example compression, OCR and Office conversions) transfer your file over an encrypted connection, process it, and delete it automatically after 120 minutes at the latest.
- We do not sell personal data, we do not use your documents for advertising, and we do not use your documents to train machine-learning models.
Files you process
Browser-side tools. Merging, splitting, rotating, page organisation, image-to-PDF, text-to-PDF, the PDF editor and signing run in your browser using JavaScript. The document stays on your device; only the finished result you choose to download is written to your disk.
Server-side tools. Some operations need software that cannot run in a browser. When you use one of these tools, the file is uploaded to our processing servers over TLS, stored in a private location that is not publicly accessible, processed in an isolated environment, and made available to you for download. Uploaded files and generated results receive an expiry time when they are created and are deleted by an automatic cleanup job when that time is reached — by default 120 minutes after creation. You can delete a file earlier from your dashboard, and deleting your account removes all of your files immediately.
We never open, read or review the contents of your documents unless you explicitly ask us to in a support request and provide the file yourself.
Information we collect
Account information. If you create an account we store your name, email address and a salted hash of your password (never the password itself). Sign-in sessions are stored server-side and identified by a random token in a cookie.
Usage records. For server-side tools we keep a technical record of each processing job: the tool used, file sizes, timestamps, the outcome and, for signed-in users, the account it belongs to. Anonymous usage is attributed to a random guest identifier stored in a cookie. These records let you see your history, let us enforce plan limits, and help us diagnose failures. They do not include document contents.
Technical logs. Our servers write structured logs containing IP addresses, browser user-agent strings, requested URLs and error details. Passwords, session tokens and document contents are excluded from logs by design.
Contact messages. When you use the contact form we store your name, email address, subject and message, together with the IP address and user agent of the request, so that we can reply and prevent abuse.
Billing. Paid plans are processed by Stripe. Card numbers are entered directly on Stripe's pages and are never sent to or stored by our servers. We store your Stripe customer identifier, subscription status and invoice references so we can show your billing history.
How we use information
We use the information above to operate the Service, keep your account secure, provide the plan you subscribed to, respond to your messages, prevent abuse (including rate limiting and spam protection), and improve reliability. Legal bases under the GDPR are performance of a contract (providing the Service), our legitimate interests (security, abuse prevention, service improvement) and, where required, your consent.
Cookies
The Service uses only cookies that are necessary for it to work: a session cookie for signed-in users, a guest identifier for anonymous processing, and a language preference. Details are in our Cookie Policy.
Sharing
We share personal data only with the service providers needed to run the Service — hosting and storage providers, our email delivery provider (for verification, password reset and contact notifications), Stripe for payments, and, if enabled by the operator, a CAPTCHA provider used to protect forms. Each provider processes data on our behalf and under its own privacy commitments. We also disclose information when required by law or to protect the rights and safety of users and the public.
Retention
- Uploaded files and generated results: deleted automatically after at most 120 minutes.
- Job history: kept while your account exists; anonymous job records are removed together with their files.
- Account data: kept until you delete your account, after which it is removed immediately (invoices may be retained by Stripe as required by accounting law).
- Server logs: rotated and deleted on a short schedule set by the operator.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. You can update your profile and delete your account from the Account page at any time. For any other request, contact us at privacy@pdfcraft.app.
Security
We protect the Service with TLS encryption, hashed passwords, server-side sessions, strict file validation, isolated processing environments, rate limiting and security headers. No system is perfectly secure, and we encourage you not to upload documents you cannot afford to share with a third-party service if that is a concern — the browser-side tools are always available.
Children
The Service is not directed at children under 16 and we do not knowingly collect personal data from them.
Changes
We may update this policy from time to time. The date at the top of the page shows when it was last changed. Significant changes will be announced on the Service.
Contact
Questions about privacy can be sent to privacy@pdfcraft.app or through the contact form.