Privacy Policy
Last updated: March 9, 2026
Table of Contents
The Short Version
- 18 of our 36 tools process files entirely in your browser. Your files never leave your device.
- Server-processed files (like AI tools) are encrypted in transit, held in memory for the request, and we keep no copy.
- The one exception is our MCP API, which stores each output file so your integration can download it. The link expires after an hour, and an automatic cleanup removes stored files older than 24 hours.
- Usage logs are anonymized and contain no personally identifiable data.
- We do not sell your personal data. Payment processing is handled securely by Stripe.
1. Introduction
LittlePDF (operated by Renvia Code, "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit littlepdf.com and use our services. By using LittlePDF, you agree to the collection and use of information in accordance with this policy.
2. Client-Side Processing & File Privacy
LittlePDF is designed with a privacy-first architecture. Most of our PDF tools, including merge, split, compress, rotate, watermark and page reordering, run entirely in your web browser using client-side JavaScript. This means:
- Your files are never uploaded to our servers for these operations.
- Processing happens locally on your device using technologies such as pdf-lib and the Web Crypto API.
- We have no ability to access, read, or store the content of files processed client-side.
- Once you close the browser tab, all file data is released from memory.
18 of our 36 tools process files entirely in your browser. We never see your documents.
3. AI-Powered Tools & Server-Side Processing
Certain advanced features transmit your files to our processing servers. That covers AI-powered OCR, document summarization, and the format conversions that need server-side rendering. When it happens:
- Files are encrypted in transit using TLS 1.3.
- On the website, the file is held in memory for the length of the request and we keep no copy of it. None of the website API routes write an uploaded file to disk or to a storage bucket.
- We do not retain, log, or use your file contents for model training or any purpose beyond fulfilling your request.
- AI processing is powered by third-party APIs (such as Google Gemini for OCR). These providers process data under strict data processing agreements and do not retain your files.
- Some conversions run through a document engine (LibreOffice or Chromium) that has to write the file inside its own container to open it. That working copy belongs to the conversion process and is not something we read, index, or hold on to.
Each tool page clearly indicates whether processing happens in your browser or on our servers, so you always know before you upload.
Our MCP API works differently, and you should know how. An MCP client is a program, not a browser, so it cannot receive a file as a download. Every file an MCP tool produces is therefore written to a private storage bucket under your account id, and the tool answers with a signed link to it. That link stops working after one hour, and an automatic cleanup continuously removes stored objects older than 24 hours. This applies only to the MCP API, not to the website or the browser extension.
4. Information We Collect
We collect the following categories of information:
a. Account Information
When you create an account, we collect your name, email address, and authentication credentials. If you sign in via a third-party provider (Google, GitHub), we receive the profile information you authorize.
b. Payment Information
Payment processing is handled entirely by Stripe. We never receive, store, or have access to your full credit card number. Stripe provides us with a tokenized reference, your billing address, and the last four digits of your card for receipt purposes.
c. Usage Analytics
We collect anonymized usage data to improve our service, including pages visited, tools used, feature interactions, device type, browser version, and approximate geographic region. We do not track individual user behavior across sessions in a personally identifiable way.
d. Technical Data
Our servers automatically log IP addresses, request timestamps, and HTTP headers for security monitoring and abuse prevention. These logs are retained for 30 days and then permanently deleted.
5. How We Use Your Information
- To provide, operate, and maintain our services.
- To process transactions and send related billing information.
- To send service-related notices, including security alerts and account notifications.
- To analyze usage patterns and improve our tools and user experience.
- To detect, prevent, and address technical issues, fraud, or abuse.
- To comply with legal obligations and enforce our Terms of Service.
6. Third-Party Services
We use the following third-party services to operate LittlePDF:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication & database | Account data, session tokens |
| Stripe | Payment processing | Billing details (tokenized) |
| Google (Gemini AI) | OCR & document intelligence | File content (ephemeral, not retained) |
| Vercel | Hosting & edge delivery | HTTP request data, logs |
Each provider operates under their own privacy policies and data processing agreements. We select providers that meet or exceed industry standards for data protection.
8. Data Retention
We retain your account information for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law (e.g., tax records for payment transactions, which are retained for up to 7 years). Server logs are retained for 30 days. Analytics data is aggregated and anonymized and may be retained indefinitely.
Files are a separate matter. Website tools keep nothing: the browser tools never upload, and the server routes hold the file only for the length of the request. Files produced through the MCP API are the exception described in section 3: they sit in storage under your account id, the download link expires after an hour, and the object is removed automatically once it is 24 hours old. To have one removed sooner, email privacy@littlepdf.com.
9. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing of your data for certain purposes.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Opt Out of Sale (CCPA): We do not sell personal information. No opt-out is necessary.
10. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS 1.3), encryption at rest for stored data, and access controls based on the principle of least privilege. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
LittlePDF is not directed at children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting a notice on our website and updating the "Last updated" date above. We encourage you to review this page periodically. Your continued use of LittlePDF after changes are posted constitutes your acceptance of the revised policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: