Privacy at a glance
- Active free-audit document files delete after 30 days; unresolved paid-review files are protected until acceptance or completed refund, then active copies delete 30 days later.
- Encrypted disaster-recovery backups may retain document copies for up to 35 additional days, isolated from normal product access.
- Customer documents are used only to provide the requested service, never to train AI models.
- You can run the free audit without creating an account.
- Custom analytics events do not send document content or raw filenames.
Information we handle
Documents and results
When you upload a PDF, we handle the file, its displayed filename, page count, document structure, audit findings, improvement instructions, generated files, and Accessibility Improvement Reports. These records are needed to run the service and let you review the result.
Account and order information
If you sign in with Google, we store your Google account identifier, email address, and a PDF Hound user identifier. If you optionally ask us to email an audit or repair update, we associate that address with the order for service messages, not marketing. Guest purchases use a random claim code stored in your browser. We also keep order status, credit balance, credit movements, and Stripe transaction references. PDF Hound does not receive or store your full payment card number.
Credit-return feedback
When you ask to return a repair credit, we collect a required reason category and any optional details you provide. Both are stored with the order so we can complete the return, respond to support questions, and understand where the repair or review experience needs improvement. The category is also recorded in our operational decision log and may be included in product analytics; the optional details are not sent to product analytics or copied into the operational decision log. Do not include passwords or sensitive personal information in the optional details.
Technical and analytics information
We use an IP address or signed-in user identifier to apply rate limits and prevent abuse. When analytics is enabled, PostHog may receive page and interaction data, browser and device details, a pseudonymous identifier, and the signed-in account identifier. Document text, filenames, element attributes, and session playback are masked or disabled. Review, admin, and guest-payment capability values are removed from recorded URL properties.
How we use information
We use the information described above to:
- audit, remediate, validate, and deliver the PDF you submit;
- show document status, preserve account balances, and process purchases or credit refunds;
- process credit-return requests and improve repairs and review tools using the feedback submitted with those requests;
- secure the service, limit abuse, troubleshoot failures, and provide support; and
- understand aggregate product usage and improve the workflow.
Relevant document content may be processed by the Google Gemini API to classify layouts, describe meaningful images, recover reading order, or independently verify semantic evidence. When Gemini vision is the selected OCR provider, it may also transcribe scan-like pages and independently verify that transcription. PDF Hound enables this document processing only with an operator-attested paid Gemini service configuration under which submitted content is not used to improve Google products. When Google Cloud Document AI OCR is selected, scanned or image-based pages may instead be sent to its Enterprise OCR processor for transcription; Gemini may still process relevant page content for the semantic tasks described above when enabled. OCR evidence can include recognized text, location, language, confidence, and verification results needed for review. PDF Hound does not use customer files to train AI models.
Service providers
Depending on which features are configured or used, information may be processed by:
- Google for cloud storage, paid-service Gemini semantic processing and optional vision OCR, optional Google Cloud Document AI OCR using its Enterprise OCR processor, and optional Google Sign-In;
- Stripe for checkout and payment processing;
- Cloudflare Turnstile for automated abuse prevention;
- PostHog for product analytics; and
- our application hosting and email providers for service delivery and notifications.
These providers process information under their own terms and privacy notices. We disclose information only as needed to operate the requested feature, comply with law, or protect the service and its users.
Retention and deletion
Active document files: free-audit PDFs and generated files are automatically removed from the active service after 30 days. Paid repair files remain active while review or a credit return is unresolved; acceptance or completed refund starts a fresh 30-day retention period. Accepted results remain downloadable during that period; refunded results do not. Active-file deletion is enforced by storage lifecycle controls and the scheduled local retention sweep.
Disaster-recovery copies: encrypted, access-restricted backups may retain a document copy for up to 35 additional days after it leaves the active service. Backup copies are not available through PDF Hound and are used only to recover from data loss. Any restored data is retention-swept before the service can expose it again. Backup schedules and storage lifecycle rules enforce the 35-day maximum; backups are not locked or versioned beyond it.
Service records: some structured audit, remediation, order, and job records may remain after the underlying files are deleted for reliability and operational evidence. These records do not keep the uploaded or generated file available.
Longer-lived records: account records, credit balances, credit transaction history, payment references, transactional email delivery logs, support leads, cost records, and operational decision logs are not included in the active-file deletion policy. They are retained to preserve balances, delivery idempotency, transaction integrity, security, support, and business records, subject to applicable legal requirements.
Credit-return feedback: the reason category and optional details are part of the associated order record, and the category may also remain in operational decision logs and product analytics. These records are not covered by the 30-day document-file deletion policy and do not currently have a fixed automatic deletion period. You may request deletion as described below; we may retain limited transaction, security, or legal records where permitted or required.
Browser storage: PDF Hound stores session details, guest claim codes, recent document names, and workflow status in your browser so you can resume work. These remain until you remove an item, sign out where applicable, clear site data, or the browser removes them.
Security
Document files are encrypted during transfer and at rest. Access to review results uses signed-in ownership or hard-to-guess capability links and tokens. We also use request limits and optional bot checks to reduce abuse. No internet service can guarantee absolute security, so keep a source copy of every document you upload.
Your choices and requests
You may use the free audit without an account, remove locally listed items from My PDFs, clear PDF Hound site data in your browser, or sign out to end the local session. Depending on where you live, you may also have rights to access, correct, delete, or receive a copy of personal information.
Send a privacy request to hello@pdfhound.com. We may need to verify that you control the relevant account, email address, claim code, or review link. Some transaction and security records may need to be retained where law permits or requires it.
Changes to this policy
We may update this policy as the service changes. The date at the top will change when we publish a material revision.
Questions
Contact hello@pdfhound.com with questions about data handling or this policy.