Privacy Policy
Effective: 2026-09-04 · Last updated: 2026-09-04
pdfmill is operated by SHK Tech Consulting LLC, a limited liability company organized under the laws of Wisconsin, doing business as Zenaptic Labs, 6580 Monona Drive #1029, Monona, WI 53716, United States (“we”, “us”, “our”).
Privacy and support contact: support@pdfmill.dev. A person answers.
pdfmill is an API and dashboard that turn a template plus your data into a PDF or PNG. It is offered to businesses, not to consumers. This policy describes what the product does today. It is not a statement of intent.
In short
- We do not store the documents you render, or the data you send us to render them.
- We do not log the contents of render requests.
- We hold your email address, workspace, templates, hashed API keys, render counts, and billing identifiers from Stripe.
- Everything we hold is stored in the United States.
- We use no analytics, no advertising cookies, and no tracking cookies.
- We do not sell or share personal data, and we do not use your content to train any model.
1. What we collect
What you give us
- Email address — required to create an account. Sign-in is by a link we email you; there is no password.
- Workspace name — you can rename it at any time.
- Templates — the HTML templates and variable definitions you create and save in pdfmill, including their saved versions.
- Sample data saved with a template — optional; see §2.
- Support correspondence — anything you send to support@pdfmill.dev.
What the service creates as you use it
- API keys — stored only as a SHA-256 hash. The key is shown once, at creation. Neither you nor we can recover it afterwards; you can revoke it and create another.
- Render counts — one integer per workspace per month, used to enforce your plan limit and to bill honestly. It is a count, not a record of what you rendered.
- Sign-in records — session and one-time sign-in-link records, so that a link works once and expires after 15 minutes.
- Operational logs — for each API request we record exactly: a request id, which API key was used, the template name, the output format, the page count, the byte size, the duration, and the outcome. Nothing from the request body.
What we receive from Stripe if you subscribe
- Customer and subscription identifiers, the plan you are on, the current period end, and whether the most recent payment failed. We also keep a ledger of Stripe webhook event ids and types, so a duplicate delivery is never processed twice.
- We never receive or store your card number. Stripe handles payment details directly.
2. What we deliberately do not collect
This describes how the product is built, not an aspiration.
- We do not store the documents you generate. They are rendered in memory and streamed back to you in the HTTP response. Nothing is written to disk or to object storage.
- We do not store the data you send to the render API. Invoice line items, customer names, and any other values you merge into a template exist only for the life of that request.
- We do not log payload contents. Our logs record size, timing and outcome — never the data.
- We do not use your content to train any model, and we do not sell or share it.
- We do not collect location data, biometric data, or any special category of personal data as defined by GDPR Article 9. Please do not place such data in templates or saved sample data.
The one exception, which you control: sample data saved with a template. If you save example values alongside a template so you can preview it in the dashboard, those values are stored with that template version until it is deleted. Do not put real personal data there unless you intend it to be stored.
One diagnostic capability, disclosed for completeness. The render engine contains an off-by-default mode that can write a failed render's merged HTML to the server's temporary directory, purged after 24 hours and never served to anyone. It is not enabled in production.
3. Why we use it, and our legal basis
| What | Why | GDPR legal basis |
|---|---|---|
| Email address | Create your account and sign you in | Performance of a contract |
| Workspace, templates, saved sample data | Provide the service | Performance of a contract |
| Render counts | Enforce plan limits; bill accurately | Performance of a contract |
| API key hashes | Authenticate API requests | Performance of a contract |
| Operational logs | Keep the service working, diagnose failures, prevent abuse | Legitimate interests |
| Billing identifiers from Stripe | Take payment and manage your subscription | Performance of a contract; legal obligation for tax records |
| Service email (sign-in links, account notices) | Operate your account | Performance of a contract |
We send no marketing email. If that ever changes, we will ask for your consent first.
We use no analytics of any kind today — no product analytics, no session recording, no error tracking service. We will update this policy before any analytics is introduced.
4. Sub-processors
| Sub-processor | What it does | Where it processes data |
|---|---|---|
| Render | Application and API hosting | United States (Ohio) |
| Supabase | Postgres database | United States (AWS us-east-2, Ohio) |
| Stripe | Payments and subscriptions | United States and other countries in which Stripe operates |
| Resend | Sends sign-in links and account email | United States |
| Forward Email | Receives mail sent to support@pdfmill.dev | See note below |
Forward Email handles only the messages you choose to send to our support address — no account, template, render or billing data passes through it. We have not independently confirmed the countries in which it processes that mail, so we do not claim one here.
We disclose data to law enforcement only where legally compelled, and we will tell you unless we are prohibited from doing so. We do not sell personal data and we do not share it for cross-context behavioural advertising.
5. Where your data is stored, and what that means outside the US
pdfmill's application servers and database are in the United States. We do not offer EU, UK or other regional data residency.
If your business is in the EU, EEA, UK or Switzerland, using pdfmill means the account data described in §1 is transferred to and stored in the United States. Because we do not store rendered documents or render payloads, the personal data that crosses that border is limited to account, template, usage and billing records.
If your organisation requires a data processing agreement, standard contractual clauses, or other documented transfer safeguards before you send us personal data, email support@pdfmill.dev and we will deal with it before you rely on the service.
6. Cookies
pdfmill sets strictly necessary cookies only: a session cookie, a CSRF-protection cookie, and a sign-in callback cookie. They exist so that signing in works and stays secure.
There are no advertising cookies, no third-party tracking cookies, and no analytics cookies. That is why you do not see a consent banner. If we ever add a cookie that is not strictly necessary, we will update this policy and ask for consent where the law requires it.
7. How long we keep things
We do not run automatic expiry on account data. Stated honestly:
| Data | How long |
|---|---|
| Account, workspace, templates and their versions, saved sample data | Until you delete your account or ask us to delete it |
| Deleted templates | Deleting a template hides it from the dashboard; its stored versions, including any saved sample data, are retained until the account is deleted. Ask us and we will remove them outright |
| API key hashes | Until you revoke the key or delete the account |
| Render counts | Kept with the workspace as billing history, until account deletion |
| Operational logs | Retained by our hosting provider under its own log retention; we keep no separate archive |
| Sign-in link records | Single use; void 15 minutes after issue. Expired rows may remain in the database until the account is deleted or you ask us to clear them |
| Billing records | Held by Stripe under its retention and applicable tax law; we keep only identifiers and webhook event ids while your account exists |
Deleting your account removes your workspace, API keys, templates and usage records. Two minimal traces are not removed automatically: Stripe webhook event ids and types, and expired sign-in link rows keyed to your email address. Email us and we will delete those too.
8. Your rights and how to use them
You may ask us to:
- See what we hold about you;
- Correct anything inaccurate;
- Delete your account and its data;
- Export your templates and account data in a portable format;
- Object to or restrict processing we base on legitimate interests.
Email support@pdfmill.dev to exercise any of these. Access, export and deletion are carried out by hand, by a person, on emailed request — there is no self-service delete or export button in the dashboard, and we would rather say so than imply otherwise. We aim to respond within 30 days.
If you are in the EU, EEA, UK or Switzerland, you may also complain to your national data protection authority. If you are in California, you have rights of access, deletion, correction and to opt out of sale or sharing — we do not sell or share personal data, so there is nothing to opt out of.
9. Security
- All traffic is served over TLS.
- API keys are stored as SHA-256 hashes and are never recoverable in plaintext by anyone, including us. They are revocable at any time.
- Sign-in links are single-use and expire 15 minutes after they are issued.
- The database is managed by Supabase, with encryption at rest.
- The render engine blocks requests to internal and private network addresses, to prevent server-side request forgery.
- Access to production systems is limited to the operator of the service.
- Rendered output and render payloads are never persisted, so there is no document store to breach.
No system is perfectly secure. If we discover a breach affecting personal data, we will notify affected customers and any regulator we are required to notify, without undue delay and within the deadlines the law sets.
10. Children
pdfmill is a business tool, sold to businesses. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, write to support@pdfmill.dev and we will delete it.
11. Data you render through pdfmill
If your documents contain other people's personal data — invoices with customer names, certificates with student names — you are the controller of that data and we act as your processor. You are responsible for having a lawful basis for that processing, for what your templates contain, and for what you place in saved sample data.
We process that data only to produce the output you asked for, on your instructions, and we retain none of it (§2). If you need a data processing agreement for this relationship, email support@pdfmill.dev.
12. Changes to this policy
If we make a material change, we will email account holders and update the date at the top of this page at least 30 days before it takes effect. Continuing to use pdfmill after that date means you accept the change. Introducing analytics, a new data category, or a non-essential cookie counts as a material change.
13. Contact
Email: support@pdfmill.dev
Post: SHK Tech Consulting LLC (dba Zenaptic Labs), 6580 Monona Drive #1029, Monona, WI 53716, United States
See also the Terms of Service.