Privacy Policy
Last updated
1. Who we are
pdf.xyz is operated by BENEERA LLC, a limited liability company registered in Wyoming, United States (“we”, “us”).
30 N Gould St # 44190Sheridan, WY 82801United StatesFor anything in this policy, including requests about your data, write to [email protected]. It is a monitored address, not a formality.
Where this policy uses terms from the UK and EU General Data Protection Regulation, BENEERA LLC is the controller for the limited personal data described below.
2. Your files
This is the part most people are asking about, so it comes first.
Tools that run in your browser (29 of 50). The file is opened and processed by code running on your own device. It is not sent to us, and we could not read it if we wanted to. Closing the tab discards it. Nothing about the file's contents, name, or size reaches our servers.
Tools that use a processing worker (21 of 50). Some work cannot be done in a browser — optical character recognition, office-format conversion, and anything using an AI model. For these, your file is uploaded over an encrypted connection to storage we control, scanned for malware, processed, and then removed on this timetable:
Counted here, but browser-first (1 of 21). This group — Compress PDF — runs in your browser first and uploads only when the local attempt cannot finish the job. Because an upload can happen, it is counted with the worker tools above rather than with the 29 that never upload. That is why a count of tools with an in-browser mode is larger than the count that never send anything — same catalogue, two different questions.
- The uploaded file is actively deleted as soon as the job reaches an end — success or failure — and in any case within 60 minutes. If a job hits a temporary error and is retried, the file is kept for that retry rather than re-uploaded.
- The result stops being downloadable after 60 minutes. After that the link returns an error and nobody can retrieve it, including us. The stored copy is then erased by a storage rule that runs on a daily cycle, so the bytes typically survive a few hours longer than the link does. We would rather say that than round it to a number that sounds better.
- A record of the job — including your file's name — is kept for about 24 hours so the system can report status, avoid duplicating work, and retry safely. It does not contain your document's contents.
- Nothing here is used to train any model — not ours, and not a provider's.
We do not read your documents, and no person at pdf.xyz opens them in the ordinary course of running the service.
One case worth naming. If you use the tools that add or remove a PDF password, the password you type is part of the instruction sent to the worker, and it sits in that job record for the same ~24 hours. It is never written to a log, an error message, a filename, or a result. Still: if a password is one you use elsewhere, change it, or use it only for the document.
Every tool page states which of these two applies before you choose a file, and the status page lists them all.
3. Tools that use an AI model
Our AI tools — summarising, translating, answering questions about a document, and structured extraction — work from the text of your PDF. The worker extracts that text and sends it to a third-party AI provider to produce the answer. The PDF file itself is not sent to the provider.
Two details we would rather state than have you discover. Only text the PDF already contains as text is sent — we do not run character recognition to manufacture text from a scan, and a scanned document is refused rather than silently half-processed. And for Chat with PDF, the document's text is sent again with every question — the worker keeps nothing between them. The provider holds it in a short-lived cache, which lowers the cost of processing the repeat rather than avoiding it; that cache lasts minutes, not days.
We use providers under agreements that prohibit training on data sent through the API. We cannot control what a provider does beyond those terms, so if a document is sensitive enough that this matters, use one of the in-browser tools instead, or do not use the AI tools for it.
4. What else we collect
Beyond file processing, the data we handle is deliberately small.
- Ordinary server logs. Our hosting and storage providers record the technical details every web request produces — IP address, time, the page or endpoint requested, browser user-agent. These are used to operate and secure the service, including to detect abuse, and are retained for a short period by those providers.
- A job identifier. Worker tools create a job with a random identifier so your browser can poll for the result. It is not linked to you.
- No product analytics leave your device. The site counts things like which tools get used, and that counting goes nowhere: in the shipped build it is wired to a sink that discards it. There is no analytics vendor, no advertising pixel, and no error-tracking SDK anywhere in the site. The whole dependency list is ten packages, none of them a tracker.
- One thing you can choose to send us. Some tools in our catalogue are not built yet. If you press “Notify me” on one, that tells us which tool you wanted — the tool's name, and nothing else. No identifier, no time, nothing about you or your device. We add one to a count so we know what to build next. Pressing nothing sends nothing.
- Page-performance and error reports, only if we switch them on. There is one optional channel for load-speed measurements and crash reports. It is off unless a reporting destination is configured, and when it is off the code that would send anything is not loaded at all. When on, values are stripped before sending — filenames, file links, and query strings are removed rather than trusted to be harmless.
- What you send us. If you email us, we keep that correspondence so we can reply.
There are no accounts. We do not ask for a name, an email address, or a password to use the tools, so we hold no profile of you to lose.
6. Why we are allowed to do this
Under UK and EU data protection law we rely on two lawful bases:
- Performance of a contract — processing the file you asked us to process is the service you requested.
- Legitimate interests — keeping the service available, secure, and free of abuse, and understanding aggregate performance. We have considered your rights in reaching that balance, which is why these signals carry no identifiers and no document contents.
8. Where data goes
BENEERA LLC is established in the United States, and our providers operate internationally. If you are in the UK or the EEA, using this service means your data is processed outside your country — that is not a corner case here, it is the normal path.
Where personal data leaves the UK or EEA, we rely on the safeguards our providers offer, typically the UK International Data Transfer Agreement or the EU Standard Contractual Clauses. The practical reduction in exposure is the same one that runs through this whole policy: for most of our tools nothing is transferred at all, because the file never leaves your device.
9. Security
Traffic to and from this site is encrypted in transit. Uploaded files are stored on infrastructure we control and are scanned for malware before any processor touches them — a deployment with no scanner refuses to start, so this is not a setting that can quietly lapse. The site sets a strict Content Security Policy and related protections against common web attacks. We remove uploads and results on the timetable in section 2 rather than keeping them.
No service can promise perfect security, and we do not. What we can say is that the largest single reduction in risk is the design itself: for the majority of our tools there is nothing on our servers to breach, because the file never left your device.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and — in California — to know what is collected and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of.
To exercise any right, email [email protected]. We will not treat you differently for asking.
Please be aware of a practical limit: because we hold no accounts and delete files within an hour, a request about a document you processed is usually a request about data that no longer exists. We are also often unable to connect a request to a specific past request without information that would identify you more than we currently do — we will not create a record of you in order to answer.
If you are in the UK or EEA and you think we have handled your data badly, you may complain to your national supervisory authority. In the UK that is the Information Commissioner's Office.
11. Children
This service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes to this policy
If we change how we handle data, we will update this page and the “last updated” date above. Where a change materially reduces the protections described here, we will say so prominently rather than quietly editing the text.