Privacy Policy
Last updated: April 25, 2026
1. Information We Collect
We collect the following information:
- Account information: email address, full name, and password (hashed)
- Usage data: API call counts, PDF generation counts, and timestamps
- Content: HTML templates and data you submit for PDF generation
- Payment information: processed by Lemon Squeezy (our Merchant of Record); we do not store card numbers
- Technical data: IP address, browser type, and request metadata for API calls
2. How We Use Your Information
- To provide and maintain the Service (PDF generation, template storage)
- To process payments and manage subscriptions
- To enforce rate limits and usage quotas
- To send transactional emails (password resets, billing notifications)
- To improve the Service and fix bugs
3. Data Storage & Security
Your data is stored on Supabase (PostgreSQL) with row-level security enabled. Generated PDFs are stored in Supabase Storage. All data is encrypted in transit (TLS) and at rest. API keys are stored as SHA-256 hashes.
4. Third-Party Services
We use the following third-party services:
- Supabase: authentication, database, and file storage
- Lemon Squeezy: payment processing (Merchant of Record)
- Anthropic (Claude): AI template generation and data mapping
Each third-party service has its own privacy policy. We only share the minimum data required for each service to function.
5. Cookies
We use essential cookies for authentication (Supabase session tokens). We do not use tracking cookies or third-party analytics cookies.
6. Your Rights
You have the right to:
- Access your personal data stored in the Service
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your templates and generated documents
- Withdraw consent for data processing
7. Data Retention
Generated PDFs are retained for 90 days after creation. Templates are retained until you delete them or your account is terminated. Usage logs are retained for 12 months. Account data is deleted within 30 days of account termination.
8. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this privacy policy periodically. Material changes will be communicated via email. Continued use of the Service after changes constitutes acceptance.
Contact
For privacy-related questions, contact us at privacy@pdfgen.ai.