PFree PDF Tools
Local-first

Effective August 30, 2026 · Version 19

Privacy Policy.

Free PDF Conversion & Tools minimizes collection: ordinary document tools run locally, while encrypted sharing, optional payment, and limited operational records use disclosed providers.

Operator and Privacy Officer

Operator: Nicholas Ekman, carrying on business as AKELASENTERPRISES, a registered Ontario sole proprietorship. The sole proprietorship is not a corporation or separate legal person. Designated Privacy Officer: Nicholas Ekman. General, privacy, legal, security, and support contact: AkelasEnterprises@hotmail.com. Begin the subject with [PRIVACY], [LEGAL], [SECURITY], or [SUPPORT] as appropriate. Requests and complaints can also be filed through the Privacy Rights Centre. The monitored email is the published public service contact; no residential address is displayed. Any additional address or transaction notice that applicable law requires will be supplied through the legally required channel. Independent Ontario legal review of the current launch position and Quebec exclusion was completed on August 30, 2026.

Data, purposes, and authority

Local PDF bytes are used only in browser memory to perform the selected tool and are not intentionally sent to our server. Encrypted links store ciphertext, random identifiers, encryption parameters, expiry and access settings to perform requested sharing. Contact details and request text are used to answer privacy or security requests. Pseudonymous IP-derived hashes, route categories, counters, timestamps and generic error codes support delivery, fraud prevention, security and reliability. Signature records contain consent events, pseudonymous actor hashes, timestamps and document hashes to provide requested evidence. If you buy a Day Pass, Stripe collects the checkout identity, contact, billing, payment, tax-location, device, network, fraud-prevention, and transaction information needed to process and support that purchase. Our application stores a random pass-token hash, pseudonymous visitor hash, Stripe session and payment references, purchase and expiry times, status, and allowance use; it does not receive or store a full card number or card security code. Processing is based, as applicable, on your request or contract, meaningful consent, legitimate service-security purposes, and legal obligations.

Coverage of all thirty-one tools

Form filling; compression; PDF-to-Word, TXT, JPG, and PNG conversion; JPG/PNG/HEIC/SVG/TIFF-to-PDF conversion; TXT/Markdown-to-PDF conversion; merging; splitting; editing; rearranging; reversing; odd/even extraction; page duplication; blank-page insertion; rotation; typed signing; redaction assistance; fillable-field generation and flattening; watermarking; page numbering and deletion; common metadata clearing; and structural rebuilding operate in local browser memory. The form filler does not intentionally transmit the PDF or entered field values to the application server and does not save an autofill profile. Image, text, and Markdown source files used by local converters are not intentionally sent to the application server. HEIC and TIFF decoding occurs in the browser; SVG files are stripped of active and external content and rasterized locally. Secure links and signature-request links encrypt document bytes and filename metadata in the browser before temporary upload. The server receives ciphertext and restricted link controls but not the decryption key, plaintext PDF, plaintext filename, signature text, or locally detected PDF text.

Do not submit personal or regulated information

The service is not marketed or configured for healthcare providers, health information custodians or their agents, regulated professionals, financial institutions, governments, or other regulated organizations. Do not select or submit personal information, personal health information, medical, legal, financial, government, child-related, privileged, classified, or similarly regulated records. Local processing and encryption reduce exposure but do not make prohibited use compliant or authorized.

Processors and cross-border handling

Cloudflare provides the production domain, edge execution, static delivery, D1 structured storage, R2 encrypted-object storage, and security services. Cloudflare Worker Logs persist application-emitted route categories and generic status codes for reliability; full invocation logs and traces are disabled in the application configuration, and the application never writes filenames, document contents, PDF text, passwords, secure-link identifiers or fragments, decryption keys, signature text, or form contents to those logs. Cloudflare may still process ordinary network and request metadata as the hosting and security provider. OpenAI Sites provides a separate development or preview environment while that preview remains in use; it is not the intended production payment host. Stripe Managed Payments hosts optional Day Pass checkout and provides payment, tax calculation and handling, fraud prevention, dispute and refund handling, receipts, and transaction-level support. Google ownership verification uses public metadata and ads.txt. Advertising scripts remain disabled pending approval and consent testing; any later activation is limited to eligible, non-sensitive content routes for advertising delivery, fraud prevention, frequency controls, and aggregate reporting. These providers may use affiliated entities and documented subprocessors. Processing may occur in Canada, the United States, and other jurisdictions where providers operate, and information may be accessible to courts, law enforcement or national-security authorities under local law. We remain accountable where applicable for information transferred for processing and require contractual and security safeguards. No independent analytics provider is intentionally enabled.

Public search discovery

Public pages may be crawled and indexed by search engines. When a release is submitted through the IndexNow protocol, Microsoft Bing and participating search services receive only the public page URLs listed in our sitemap and a public verification key. We do not send document content, filenames, secure-link identifiers, link fragments or decryption keys, form values, payment information, privacy-request text, or private routes through IndexNow. Search providers can receive ordinary request information when they crawl a public page under their own terms and privacy practices.

Retention and deletion

Encrypted links and associated pseudonymous signature events expire after about 15 minutes, and one-view objects are deleted after successful decryption confirmation. Cleanup normally runs every five minutes; an independent storage lifecycle remains as a deletion fail-safe. Usage, authorization, and rate-limit records are kept about 2 days; operational events, payment-event deduplication records, and deletion evidence about 30 days. Pending or abandoned pass records are removed after about 2 days. Minimal expired, refunded, or disputed Day Pass entitlement records and payment-revocation markers are retained up to about 180 days for purchase recovery, fraud, refunds, and disputes, unless a legal hold or longer legal requirement applies. Stripe retains transaction and tax records under its legal, financial, fraud, and service schedules. Privacy requests are retained 24 months after completion; every safeguards-breach record at least 24 months after determination; government-request and vendor-assessment records seven years. Backups and provider logs may persist for controlled rotation periods. Deletion jobs verify object absence and record the result.

Your rights and complaints

You may request access, correction, deletion, consent withdrawal, or complain. Depending on where you live, you may also have rights to portability, restriction, objection, opt out of sale, sharing, targeted advertising or certain profiling, and appeal a denied request. We do not discriminate for exercising a privacy right. Authorized-agent requests are verified as required. We acknowledge requests, verify identity proportionately, search relevant systems, record decisions, and target a response within 30 days, subject to the shorter or longer lawful deadline that applies. Most document contents cannot be retrieved because they never leave your browser. You may complain to the Office of the Privacy Commissioner of Canada, an EEA supervisory authority, the UK Information Commissioner, the California Privacy Protection Agency, an applicable US state attorney general, the Office of the Australian Information Commissioner, or another regulator with jurisdiction.

EEA, United Kingdom, and Switzerland

Where European data-protection law applies, the operator acts as controller for limited service records and relies on contract or requested steps, consent for optional advertising storage, legitimate interests in proportionate security and abuse prevention, and legal obligation as applicable. You may object to or request restriction of legitimate-interest processing and may withdraw consent without affecting earlier lawful processing. Advertising requiring consent will remain disabled unless a certified consent platform records a valid choice. Required international-transfer safeguards and provider transfer assessments must be completed before targeted launch.

United States

We do not sell personal information, share it for cross-context behavioural advertising, or use document data for targeted advertising. We honour applicable opt-out rights and recognized legally required browser preference signals after advertising activation. We do not knowingly process minors’ data. State-specific request, appeal, authorized-agent, and regulator processes are handled through the Privacy Rights Centre. This section does not claim that every state law applies to the operator; it explains the controls used where a law does apply.

Australia, Asia-Pacific, Latin America, Africa, and other regions

Where the Australian Privacy Act and Australian Privacy Principles apply, this Policy is intended to describe identity, collection, purposes, disclosure, overseas handling, access, correction, and complaints. A complaint may be submitted to the Privacy Officer and then to the Office of the Australian Information Commissioner where eligible. For users elsewhere, we apply the same data-minimization, access, correction, deletion, complaint, security, and limited-retention baseline, while honouring any stronger mandatory local right that applies. Availability does not mean every privacy law applies to the operator or that the service is certified under local law.

Breaches and government requests

Every suspected safeguards breach is entered in a breach register. Automated triage assesses sensitivity and probability of misuse, creates draft regulator and affected-person notification tasks where a potential real risk of significant harm is indicated, and requires Privacy Officer and legal approval before sending. We report and notify as required, keep breach records for at least 24 months, preserve evidence, and document decisions. Government demands are validated for jurisdiction, authority, scope and necessity; we challenge overbroad demands, disclose only what is legally required, record the response, and notify affected people unless prohibited.

Contextual advertising only

We do not ask visitors to identify a business, professional, or personal use category for advertising. We do not provide advertisers with document data, tool inputs, filenames, secure-link information, or locally processed content. Advertising may use the public page topic and the limited provider data described below, subject to applicable consent choices.

Advertising and sponsored access

Google ownership verification remains present, but advertising scripts and ad delivery are disabled pending Google approval and consent testing. Any later advertising activation excludes encrypted recipient and other protected pages. Before advertising is activated for visitors requiring prior consent, Google’s certified consent message must be configured and tested. Google may receive ordinary request information such as IP address, user agent, page URL, ad events, consent signals, and fraud-prevention data; it must not receive document bytes, filenames, PDF text, secure-link fragments or keys, passwords, signatures, or form contents. A clearly labelled, user-selected rewarded advertisement may be considered only if Google makes a compliant format available to this account. The reward would be a native digital site feature only and have no cash value. Ads must not appear unexpectedly during a tool action, delay completed downloads, imitate controls, auto-refresh, reward clicks, or receive document information. We do not encourage VPNs, repeated viewing, automated viewing, self-clicking or anything intended to manufacture impressions.

Territorial availability

The service is intended to be available worldwide by default where lawful and technically supported. Following legal review, it is not offered to residents of Quebec. A future Quebec launch would require a complete French service, French contractual and support capability, and renewed Quebec-specific legal review. Service or advertising may also be unavailable where sanctions, export controls, provider rules, court orders, local restrictions, or technical conditions prohibit or prevent delivery. Users must not evade a geographic or sanctions restriction. See the Availability page for the current approach.

Children, security, and changes

The service is for adults aged 18 or older and is not directed to minors. Security measures include local-first processing, encryption, short retention, access controls, rate limits and verified deletion. No Internet service is risk-free. Material policy changes receive a new version and renewed acknowledgement where appropriate.