Privacy Policy
Last updated: [REVIEW: effective date]
1. Overview
OxygenPDF ("we", "us", or the "Service") is a privacy-first PDF toolkit. This Privacy Policy explains what information we collect, why we collect it, and how we handle it across our website and our iOS app. Our guiding principle is simple: your documents are processed on your own device and are never uploaded to our servers.
The data controller responsible for your information is [REVIEW: legal entity name].
2. Information We Collect
We keep collection to the minimum needed to run the Service. Specifically:
- Account information (email address and user ID): When you create an account or sign in, our authentication provider (Convex) stores your email address and a unique user identifier. This is used to operate core account features such as signing you in, associating your plan and settings with your account, and keeping your session secure. This data is linked to your identity and is used for app functionality, not for advertising or cross-app tracking.
- Product-interaction and usage analytics: We use PostHog to understand how the Service is used — for example which tools are opened, which features are used, and general usage patterns — so we can fix problems and improve the product. This analytics data is linked to your account and user identifier. It is used only for our own product analytics and is never used to track you across other companies' apps or websites.
- Local device settings: Preferences such as your interface settings are stored on your device (for example in browser storage, or in the iOS app's local preferences). These stay on your device and are used only to remember your choices.
3. Your Documents Never Leave Your Device
PDF processing in OxygenPDF happens entirely on your device, in your browser or in the app. We do not upload, store, transmit, or retain your documents or their contents. Because the files are processed locally, we have no access to them and never see what is inside them.
[REVIEW: if any optional cloud or AI-assisted feature can transmit document data off-device, describe that feature and its handling here accurately, or state that no such feature exists in the shipping product.]
4. How We Use Your Information
We use the information described above to:
- Provide, maintain, and secure your account and the Service.
- Associate your plan, entitlements, and settings with your account.
- Understand product usage and diagnose issues so we can improve the Service.
- Respond to your support requests and communicate with you about the Service.
5. Third-Party Services
We rely on a small number of trusted providers to run the Service:
- Convex — provides authentication and backend infrastructure and stores your account email and user ID.
- PostHog — provides product analytics for the usage data described above.
- [REVIEW: payment processor] — processes purchases if you buy a paid plan. Payment card details are handled by the payment processor; OxygenPDF does not collect or store your full payment card information.
These providers process data on our behalf under their own terms. We do not sell your personal information.
6. No Tracking or Advertising
OxygenPDF does not track you across other companies' apps or websites, and does not use your data for third-party advertising. On iOS, we do not use the Advertising Identifier (IDFA) and we do not present the App Tracking Transparency (ATT) prompt, because we do not perform this kind of tracking.
7. Data Retention
We retain your account information for as long as your account is active. Analytics data is retained for as long as it is useful for understanding and improving the Service. You can ask us to delete your account and associated data as described below.
8. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, export, or delete the personal information associated with your account. To make a request, or to delete your account, contact us at support@oxygenpdf.com.
9. Children's Privacy
The Service is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.
10. International Users and Governing Law
This Privacy Policy is governed by the laws of [REVIEW: governing law / jurisdiction], without regard to its conflict of law provisions. If you access the Service from outside that jurisdiction, you understand your information may be processed where we and our providers operate.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Your continued use of the Service after a change takes effect means you accept the updated policy.
12. The browser extension
The extension fetches the PDF you are looking at using your own browser session, hands it to a new OxygenPDF tab, and stops. The file never reaches a server, ours or anyone else’s.
- What it reads: The address of the tab you used it on, and the PDF at that address — including a PDF on your own machine, if you turn on your browser’s file-access switch. Nothing else on the page, and nothing until you ask.
- Where the file goes: Into your browser’s own storage for the seconds it takes to reach the OxygenPDF tab, then it is deleted. Anything a handover leaves behind is cleared within ten minutes.
- What we collect: Nothing. No analytics, no counters, no account, no error reporting. The extension makes no request to us at any point.
- What it remembers: The tools you pin in the popup, stored on this machine. Not synced, not sent anywhere, and gone if you remove the extension.
- What it never does: It does not run on pages you have not used it on, and it never reads what you are browsing.
What it asks for, and why
- activeTab: Read the address of the tab you used it on, so it knows which PDF you mean.
- contextMenus: Add one item to the tab’s right-click menu.
- scripting: Look for a PDF on the page you used it on, and show the result there.
- storage: Hold the PDF for the few seconds it takes to reach the OxygenPDF tab.
- alarms: Delete anything left behind if a handover never completes.
- offscreen (Chrome only): Download the file somewhere the browser will not interrupt part way through.
- Access to the site you are on: A PDF that only exists for your signed-in session has to be read from that site. The extension asks the first time it needs to, and names the site it is asking about. Turning it down leaves everything as it was.
- Access to local files: Opening a PDF that is already on your machine needs your browser’s own file-access switch, which is off by default and can only be turned on by you. The extension points you at it and reads nothing on disk until you do. Files you open this way are handled exactly like any other: held for seconds, then deleted.
13. Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us at support@oxygenpdf.com.