Privacy
Your document is not our product.
PDFBright handles documents that may contain sensitive information. This page describes what the current product actually does, including local document processing, optional account authentication, billing, and limited product analytics.
Processing policy last updated: 2026-09-13
Current document processing
Supported PDF analysis, cleanup, OCR, preview generation, and file optimization currently run in your browser. PDFBright does not intentionally upload the PDF you select to a document-processing server.
Your browser still makes ordinary network requests to load PDFBright and may download OCR/runtime assets. Those requests are separate from sending your document contents for processing.
File lifecycle
The selected PDF and generated output are held by the browser for the active workflow. PDFBright does not currently provide cloud document storage, document history, or a document library.
When you replace the file, clean another PDF, reload, or close the page, PDFBright releases the application references it created. Files you explicitly download are then controlled by your browser, operating system, and device storage settings.
Accounts and sign-in
The initial cleanup workflow can be used without an account. If you choose to sign in, PDFBright uses Supabase for authentication and account storage. Account data can include an internal user identifier, email address, authentication provider information, and a PDFBright profile record containing plan or entitlement state.
Google and Facebook sign-in are optional identity-provider paths. When you use one, that provider and Supabase process the information required to authenticate you, such as your basic profile and email address. PDFBright does not request access to Gmail, Google Drive, Facebook posts, friends, advertising data, or other unrelated account content for sign-in.
What PDFBright currently collects
For signed-in users, PDFBright stores the account data needed for access, plan status, billing/entitlement linkage, and future usage allowances. PDFBright application code does not intentionally send document contents, filenames, OCR text, extracted text, or page images to analytics.
PDFBright uses PostHog for limited product analytics and error/performance monitoring. The events are designed around product actions such as landing, upload start, analysis, cleanup, download, checkout, and subscription state. Custom PDFBright properties are limited to non-content metadata such as entry path, coarse file-size bucket, processing mode, and plan/billing state where relevant.
Like ordinary web infrastructure, the analytics service can also receive standard browser and network metadata associated with those requests, including requested/current URL, referrer, browser and operating-system information, device or viewport characteristics, IP-derived approximate location, and timing/performance information. Signed-in analytics can be associated with PDFBright's internal user identifier so product events can be attributed to the same account.
Analytics safeguards
PDFBright disables PostHog autocapture, automatic pageview/pageleave capture, and session recording. PDFBright sends deliberate product events instead of recording page contents or user sessions. Exception reporting is sanitized before application-defined error details are sent.
Analytics is not used to upload, inspect, or reconstruct the PDF being processed. The document-processing workflow remains local even when a product analytics event is sent.
Payments and subscriptions
PDFBright uses Paddle as the billing and merchant-of-record provider for paid plans. Paddle handles checkout, payment details, applicable billing information, taxes, receipts, and subscription payment processing. PDFBright does not store full card details.
To provide and manage Pro access, PDFBright receives and stores the billing linkage needed for the account, such as Paddle customer, transaction, and subscription identifiers, subscription status, selected plan, and billing-period information. This billing metadata is separate from the contents of PDFs you process.
Current safety limits
The current anonymous workflow accepts PDFs up to 25 MB and up to 25 pages. Local OCR also has a smaller scanned-page limit based on browser performance testing. These limits reduce memory and denial-of-service risk; later Free/Pro allowances may differ while hard safety controls remain in place.
Cookies and local storage
Authentication may use browser storage or cookies needed to maintain a secure signed-in session. PDFBright does not currently use advertising cookies. PostHog analytics uses browser local storage to maintain its analytics identifier/state under the current configuration; session recording and broad interaction autocapture are disabled.
Account deletion
You can request deletion of your PDFBright account data by following the instructions on our Data Deletion page. Deleting a PDFBright account does not delete your Google, Facebook, or other identity-provider account.
Future server-assisted processing
Heavy server-assisted OCR is a future architecture path, not a feature that is silently active today. Before any future operation sends a document or derived page data to a processing server, PDFBright will disclose that in the interface before processing and publish the actual retention/deletion behavior.
Contact and policy changes
Questions about privacy can be sent to support@pdfbright.app. This policy will change as PDFBright changes accounts, billing, analytics, or processing architecture, and material changes should be reflected here before the corresponding behavior is made available.