Privacy
policy
Last updated: August 12, 2026.
1. Who we are
BestPDFInTheWorld is a PDF editing tool whose file processing runs entirely in your browser. The service is operated by BestPDFInTheWorld, based in Portugal. For any question about privacy or data protection, contact us at [email protected].
This policy applies to the bestpdfintheworld.com website, the app at app.html, and the account you can create to manage a Premium licence.
2. Two things this policy treats differently
One distinction needs to be clear from the start, because an earlier version of this page blurred it. On one hand, your PDF files: those never leave your computer, under any circumstance, and that has not changed. On the other hand, everything else about the service: the email you may use to create an account, a Premium licence key, the record of which tools you use, and the cookies on the marketing pages. This second part is real, and the sections below describe exactly what it is, why, and for how long.
3. Your PDF files
We do not store, transmit, or process your PDF files on our servers. All processing (merging, splitting, compressing, rotating, and every other tool) happens in your own browser, in memory, with libraries that run locally. When you close the tab, memory is released and the file is gone. This promise always holds, whether or not you have an account, are signed in, or have accepted cookies.
4. Your account
An account is created in one of two ways: by requesting a sign-in link by email at entrar-en.html, or automatically when you buy a Premium subscription, from the email you entered on the Stripe payment page. There is no password: you sign in with a magic link sent by email, valid for 15 minutes and usable once.
What we store: your email, whether it has been confirmed, the account type (regular user or administrator), the creation date, and the last sign-in date. Your session lives in a cookie that page JavaScript cannot read: an access token, valid 15 minutes, and a refresh token, valid 7 days. Neither is stored in the clear on our side, only the result of a hash function (SHA-256), so a copy of our database cannot be used to sign into any account. You can end your session at any time from within the app; that revokes the session on the server, not only in your browser.
Legal basis: performance of the contract for the service you requested.
5. Your Premium licence
When you activate a Premium licence key, it is validated on our server, not just stored on your device. The activation request sends the key and a random device identifier, generated in the browser and stored in localStorage; later requests, which confirm whether the licence is still active, use your session. None of these requests carry any file content.
This changed because until 2026-08-04 the licence key was the only credential: a key posted on a forum served anyone who copied it, with no limit at all. Today each key only activates on a limited number of devices (three, by default). The device identifier is never stored in the clear: we store only a hash with a secret applied to it (HMAC-SHA256), which cannot be used to reconstruct the original value. We also keep a small log of events (key activated, device limit reached, attempt with a revoked key), with that same device hash and a hash of the IP address, never the values in the clear; it exists to detect a key circulating outside the site. The only automatic block in the system is the device limit; any other signal produces an alert for human review, never an automatic revocation.
Linked to your licence we also keep the Stripe customer and subscription identifiers (to know which payment it corresponds to) and the renewal or end date.
Legal basis: performance of the contract (delivering what you bought) and legitimate interest in preventing the same key from being used by someone who did not buy it.
6. How often you use each tool
The free plan opens one tool, Sign PDF, with one signature a day. The remaining tools, OCR included, are part of the Premium subscription, which has no daily count. The exact numbers do not live in this policy because they change: they live in the product code, and the pricing page describes the mechanism.
This count lives in your browser (localStorage), and anyone can clear it with one line in the console: it is not a security barrier, it is an honest signal that there is a paid plan for people using the site seriously. If you are signed in, usage is also recorded on our server, only the tool id and nothing else (never the file name or the result), so we know which tools are actually used. For visitors without a session we send none of this, on purpose.
Also for signed-in users, the app tells our server when a task starts, when it finishes, when it fails, and when someone reaches a tool's free limit. These are operational signals (which tool, how long it took, what kind of error, on which plan), never the file, its name, or what is written inside it. When a purchase completes, it is our own server, notified by Stripe, that records that fact for measurement purposes; your browser is not involved in that request.
These signals are forwarded to Google Analytics, so we can understand conversion rates and product usage. Unlike the advertising cookies in the next section, this transfer does not run in your browser and does not use cookies: it is our server talking to Google on our behalf. It is still processing of personal data (Google Analytics is operated by Google Ireland Limited), based on our legitimate interest in understanding and improving the service; you can object by writing to the email in section 14.
7. Cookies and advertising on the site's pages
This section is about the site's marketing pages, like this one. The app at app.html, where your files are handled, loads none of these scripts and asks for none of this consent, on purpose: it has no third parties on board. Usage measurement for the app is described in section 6, is done by our own server, and uses no cookies.
On the marketing pages we set no measurement or advertising cookie without your permission. The fonts are self-hosted here, so not even they generate external requests.
On your first visit we show a consent message with two equally weighted choices, accept or refuse. The decision is stored on your device and applies to later visits. You can change it whenever you want, using the button further down.
Some requests to Google do happen before you decide, and we want to be clear about it. The site loads three Google files at startup: the AdSense script (it is what lets Google confirm this site belongs to us, and it is where the consent platform required by European advertising rules lives) and the Google Analytics and Google Tag Manager scripts, in denied mode (Consent Mode). In those requests your IP address is visible to Google, as it is to any server your browser asks something from. What does not happen at that moment, and we verified it by measurement: no measurement or advertising cookie is created, neither from googlesyndication.com nor from doubleclick.net. The only cookie present before you decide is the one storing your own decision.
- If you refuse, or do not answer: no measurement or advertising cookie is created. Google measurement only receives anonymous signals, with no cookies and no identifiers, which cannot follow you across pages or across visits. The site works exactly the same way, with every tool available.
- If you accept: we load Google Analytics 4 (audience measurement), Google Tag Manager (tag manager) and Google AdSense (advertising). These services set their own cookies and receive your IP address and site usage data. They belong to Google Ireland Limited, and Google may transfer that data outside the European Economic Area under the European Commission's standard contractual clauses.
You can change your mind at any time:
None of this changes the essential point: your PDF files still never leave your computer, whether you accept or not. Processing is always local, and there is no way for the content of your documents to reach us or any third party.
8. Payments (Stripe)
Premium subscription payments are processed through Stripe, an online payment platform. When you subscribe, you are redirected to the Stripe checkout page, which collects and processes your payment data independently. BestPDFInTheWorld does not receive, see, store, or process your credit card details, PayPal account, or any other payment information; that relationship is solely between you and Stripe. We recommend reading the Stripe privacy policy.
Once payment is confirmed, we receive from Stripe the email you entered on the payment form (to create or find your account and send you the licence key) and the subscription identifiers (to know that your account corresponds to a real payment, and for how long). We never receive your card number or equivalent data.
9. Data retention
We keep each category of data only as long as it serves the purpose it was collected for:
- Email sign-in link: deleted as soon as it expires (15 minutes) or one day after it is used.
- Signed-in session: deleted when it expires (7 days) or one day after it is ended.
- Tool usage log: deleted after 90 days.
- Record of processed Stripe events: kept for 90 days, then deleted automatically. While it is there it does two jobs: it stops a Stripe redelivery from creating the same licence twice, and it lets the admin panel add up real revenue over the last 30 days. When handling an event fails, the row is deleted at once so the next attempt can run.
- Account, licence, and activated devices: kept for as long as the account exists, because they are what makes the subscription possible. They do not currently have an automatic time-based deletion; deletion happens on request, as described in section 11. This is flagged for the product owner to decide, not a silent choice made in this policy.
10. Security
There are no passwords in the system, so there are no passwords to leak. The sign-in link and the session token are never stored in the clear, only the result of a hash function (SHA-256); the same principle applies to the device identifier (section 5, with a secret applied) and to the IP address used for the daily limit of visitors without a session and for anomaly detection on licences. Traffic with our server always runs over HTTPS.
11. Your rights under the GDPR
With actual data being processed, these rights are real and can be exercised, always through the email in section 14:
- Access: you can ask us for a copy of your account data, including the licence and the device and usage logs linked to it.
- Rectification: you can ask us to correct your email; there is no self-service form on the site for this today.
- Erasure: you can ask for your account to be deleted. That removes the email, the licence, and the linked devices; the usage log loses its link to the account instead of being deleted immediately, because it still serves aggregate statistics that identify no one. There is no delete-account button in the app today, on purpose: it is a request handled by a person, so an irreversible write does not happen without review.
- Portability: you can request your data in a structured format.
- Objection: you can object to processing based on our legitimate interest (sections 5 and 6, mainly usage measurement). The service itself (section 4) rests on a contractual basis and is not affected by an objection, unless you no longer want to use the service.
- Complaint: you may file a complaint with the Portuguese Data Protection Authority (CNPD) or the supervisory authority in your country.
12. Minors
We do not ask for or verify age, and the tool can be used by anyone with a browser. Creating an account only requires an email, with no other identifying data. If you are a parent or guardian and believe a minor in your care created an account without your knowledge, contact us at the email in section 14 and we will handle the deletion request as a priority.
13. Changes to this policy
This policy may be updated. The date of the last update appears at the top of the page. Significant changes are communicated by email to anyone with an account; without an account, we recommend checking this page periodically.
14. Contact
For any question about this policy or about how your data is handled at BestPDFInTheWorld:
Email: [email protected]
Summary: Your PDF files never leave your browser, always. If you create an account, we keep your email, your licence, and signals of how the service is used, never files or their content, for the time described in section 9. The marketing pages only use measurement and advertising cookies with your permission. Payments are processed by Stripe, not by us.