Privacy Policy
Last updated July 29, 2026
Penstead is a PDF toolkit that runs primarily in your web browser. This policy explains exactly what happens to your files, what data we collect, and the choices you have. Plain language, no dark patterns.
The short version
- Viewing, editing, annotating, signing yourself, OCR, compressing and redacting happen on your device. Those files never reach us.
- Converting a file, sharing a link and sending something for signature do upload it, because a server has to do the work.
- Converted files are deleted within the hour. Share links go after 14 days on the free plan, or when you delete them on a paid one.
- Signature requests are kept indefinitely, including after you close your account — a completed signature is a record the other signatories depend on.
- An account stores your email address, your sign-in sessions and a hashed version of your network address. We never see your card.
- Analytics loads only if you agree, and nothing about the product changes if you decline. You can export or delete your data at any time.
What happens entirely in your browser
The following never upload your document — they run on your own device and the file never touches our servers:
- Viewing, reading, and searching PDFs
- Editing text, annotating, signing yourself, and adding watermarks
- Organizing, cropping, rotating, numbering, compressing, and redacting
- Filling PDF forms
- Text recognition (OCR)
- Converting images and plain text to PDF
A ZIP file is unpacked in your browser too, but every file inside it is then handled by its own rule: images, plain text, and PDFs stay local, while any Word, Excel, PowerPoint, OpenDocument, HTML or EPUB file inside the ZIP goes to our conversion service exactly as a loose one would. So a ZIP is only fully local if everything in it is.
Features that use a server
Three things send your document off your device:
- Converting Office/HTML files (Word, Excel, PowerPoint, OpenDocument, RTF, HWP, HTML, EPUB), including ones found inside a ZIP. The file is sent to our conversion service, converted, and discarded immediately. It is not stored or logged. An EPUB is unpacked in your browser first, and it is the assembled text that is sent.
- Share link. Your PDF is stored in private cloud storage and reachable only through a long, unguessable link. It is automatically deleted after 14 days, and you can delete it sooner from the share dialog. Anyone with the link can view and download the file until then, so only share it with people you trust.
- Request signatures.When you send a document out for others to sign, the document, the recipients’ names and email addresses, everything they type into the fields, and an audit trail are stored so the signing process can complete and so the signed copy can be produced later.
We never sell your documents, never use them to train models, and never access their contents except as required to perform the action you asked for.
Accounts
You do not need an account. Every tool works signed out, and signing in does not unlock any tool — it raises the limits on the few things our servers do for you, and gives you one place to find documents you have sent.
If you do sign in, we store:
- Your email address. There are no passwords. We email you a single-use link that expires in 15 minutes, and that link is stored only as a one-way hash — we cannot read it back out.
- A session.A cookie holding a random token, stored on our side as a one-way hash, alongside your browser’s user-agent string and a salted hash of your IP address, so you can see and revoke where you are signed in. We do not store the address itself.
- Rate-limit counters keyed to your account, so limits follow you rather than your network.
If you subscribe, Stripe handles the payment. Your card details go to Stripe and never reach our servers; we keep the Stripe customer and subscription identifiers, your plan, and when the current period ends. If you email us or we email you, we keep a record of what was sent and whether it arrived — see below.
What we log
Signing is the one place where we record data about people other than you, so it is worth stating plainly. Each time a signature request is viewed, signed, downloaded, or declined, we store an audit entry with the time, the action, and the IP address and browser user-agent of whoever performed it. That trail is what makes an e-signature defensible, so it is also printed onto the Certificate of Completion pageattached to the finished PDF — meaning every signer’s IP address and browser are visible to everyone who receives the signed document, and to the sender in their management view.
If you send someone a signature request, please tell them this. Under GDPR an IP address is personal data, and they are agreeing to it through you rather than through us. If you send us a message through the contact form, we store your message, the email address you optionally give us, and your IP address, to handle abuse reports and rate-limit the form.
Analytics and cookies
Nothing measures you until you say yes. We ask once, in a bar at the bottom of the page, and Google Analytics is not loaded at all unless you allow it — not loaded and told to be quiet, not present and inert. Decline and no request is ever made to Google from your browser. Everything on the site works identically either way.
If you do allow it, Analytics records standard usage data — pages viewed, approximate region, device and browser type — and sets its own cookies. It never receives the contents of your files, and never your email address. Google is an advertising company, so while we run no ads, sell no data and embed no ad-network pixel, we cannot claim this data is untouched by advertising infrastructure.
You can change your mind at any time with the Cookieslink in the footer, and any content blocker or “do not track” setting will stop it regardless. Your answer is kept in your browser’s local storage rather than a cookie — a cookie recording that you refused cookies would be an odd thing to set.
Separately from Analytics, we keep our own count of a few product events so we can tell whether the free plan is the right size. Those are described under Data retention below, they are first-party, and they never contain file names or contents.
Data retention
How long each thing lasts, and why:
- Files edited locally: never stored by us at all.
- Files sent for conversion: held only for the moments the conversion takes, then deleted. A file whose conversion is abandoned is swept within the hour.
- Shared documents: on the free plan, deleted automatically after 14 days. On a paid plan the link lasts until you delete it. Either way you can delete it yourself at any time.
- Signature requests: retained indefinitely. Voiding a request stops anyone opening the link, but it does not erase the document, the recipients, the field values, or the audit trail — the record has to survive so a completed signature can be proven later, and the other signatories rely on that as much as you do. If you want one erased outright, ask us.
- Sign-in links: unusable after 15 minutes or one use, and the rows are deleted within a day.
- Sessions: expire after 30 days, sooner if you sign out, and are removed a week later.
- Email records:which messages we sent you and whether they were delivered, kept as long as the account, because “did they get it?” is the question a signature request most often turns on. Addresses that hard-bounce or report us as spam are kept on a suppression list so we never mail them again.
- Rate-limit counters: hours to a day.
- Product measurement: 12 months. We record when someone signs up, first uses a server-side feature, hits a plan limit, or subscribes — so we can tell whether the free allowance is the right size. These records carry the event, your account if you have one, and a salted hash of your network address if you do not. They never contain file names or file contents.
- Account records: until you close the account. Payment records are kept by Stripe for as long as tax and accounting rules require, independently of us.
Closing your account does not delete documents you have already sent. Share links and signature requests keep working, because other people hold those links and, in the case of a signed document, have a legal record that depends on it. If you want those removed as well, delete the share links first, and ask usabout signature requests.
Sub-processors
These are every third party that can touch your data, and what each one is for. We do not sell data to any of them, and none of them receives your documents except where noted.
- Vercel — hosting. Sees requests to the site.
- Supabase — database and private file storage. Holds shared documents, signature requests, accounts and sessions.
- Google Cloud Run — the document-conversion service. Office, HTML and EPUB files pass through it and are not retained.
- Stripe — payments. Receives your card details directly and your email address; we never see the card.
- Resend — email delivery. Receives the recipient address and the message we send.
- Google Analytics — usage measurement. Never receives your files or your email address.
Your rights
Depending on where you live (for example the EU/UK under GDPR, or California under CCPA), you may have the right to access, correct, export, or delete your data, or to object to processing. You do not have to ask us for most of it:
- Export. “Download my data” on your account page returns everything we hold about you as one JSON file, including what we deliberately leave out and why.
- Deletion.“Close my account” on the same page removes your account and signs you out everywhere. Read the note on retention above first: documents you have already sent are not removed by it.
- Shared documents. Delete the link from the share dialog, at any time, with no account.
For anything else — a signature request erased outright, or a request from someone who signed a document rather than sent it — contact us and we will handle it.
Children
Penstead is not directed to children under 13 and we do not knowingly collect their data.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above.
Contact
Questions, data requests, or abuse reports: get in touch.
