Privacy Policy
Last updated: February 15, 2026
Data Controller
PDFlys, Kingdom of Saudi Arabia, is the data controller responsible for your personal data. For privacy inquiries, contact us at privacy@pdflys.com.
Our Core Promise
PDFlys is built on a simple principle: your files are yours. Every PDF you open in PDFlys is processed entirely in your web browser. Your files are never uploaded to our servers, and we have no ability to access, read, or store your documents.
Whether you're using our merge PDF, split PDF, compress PDF, or PDF editor tools — all processing happens locally in your browser for complete privacy.
What Data We Collect
Files You Edit
None. PDFlys operates 100% in your browser using JavaScript. Your PDF files never leave your device. We do not upload, transmit, store, or process your files on any server.
Account Information
When you sign in via Google, we store your display name and email address for authentication purposes. Your marketing email consent preference is stored in Firestore and can be changed at any time from your Settings page.
If you choose not to create an account, you can still use all PDF tools without limitation. Account creation is optional and only needed for features like saved signatures and workflows.
Analytics
We use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies and does not track you across sites. With your consent, we also use Google Analytics (GA4) and Google Ads conversion tracking to understand how visitors find and use PDFlys. These services may set cookies such as _ga and _ga_* to distinguish unique visitors. These scripts are only loaded after you explicitly accept cookies via the consent banner shown on your first visit.
Cookies & Tracking Technologies
PDFlys asks for your consent before setting any cookies. If you decline, no cookies are set and no tracking scripts are loaded. We store your cookie preference in your browser's local storage (not a cookie) so you are not asked again.
When you accept cookies, the following categories may be used:
- Analytics cookies — set by Google Analytics (GA4) to distinguish unique visitors and understand site usage.
- Advertising/conversion cookies — set by Google Ads to measure the effectiveness of our advertising campaigns and track conversion actions.
We do not use cross-site tracking cookies or any third-party cookies beyond the analytics and advertising services described above. No cookies are set without your explicit consent. For full details, see our Cookie Policy.
Lawful Basis for Processing
We process personal data under the following legal bases, in accordance with both the Saudi Personal Data Protection Law (PDPL) and the EU General Data Protection Regulation (GDPR):
- User authentication (name, email via Google Sign-In) — PDPL: Consent / Contractual necessity; GDPR: Contract performance (Art. 6(1)(b))
- Marketing emails (email address) — PDPL: Consent (opt-in); GDPR: Consent (Art. 6(1)(a))
- Google Analytics (IP, device, behavior) — PDPL: Consent (cookie banner); GDPR: Consent (Art. 6(1)(a))
- Google Ads tracking (conversion events) — PDPL: Consent (cookie banner); GDPR: Consent (Art. 6(1)(a))
- Plausible Analytics (anonymous page views) — PDPL: Legitimate interest (anonymous); GDPR: Legitimate interest (Art. 6(1)(f))
- Sentry error monitoring (error traces, device info) — PDPL: Legitimate interest; GDPR: Legitimate interest (Art. 6(1)(f))
- Cloudflare CDN/security (IP, request metadata) — PDPL: Legitimate interest (security); GDPR: Legitimate interest (Art. 6(1)(f))
How We Use Your Data
- To provide and maintain the Service (authentication, saving preferences)
- To send product updates and tips if you have opted in
- To understand how visitors use PDFlys and improve the Service (analytics)
- To measure the effectiveness of our advertising campaigns (conversion tracking)
- To detect and fix technical issues (error monitoring)
- To protect the Service from abuse and ensure security (CDN/DDoS protection)
Advertising & Conversion Tracking
With your consent, we use Google Ads conversion tracking to measure the performance of our advertising campaigns. When you interact with one of our ads and subsequently use a PDFlys tool, a conversion event may be recorded to help us understand which ads are effective.
Google Ads may set cookies and use device identifiers to attribute conversions. Third-party vendors, including Google, may use this information to show ads on sites across the internet based on your prior visits to PDFlys. No file data, document content, or personal documents are ever shared with any advertising service.
These advertising scripts are only loaded after you explicitly accept cookies via the consent banner. If you decline or have not yet responded to the consent prompt, no advertising cookies or scripts are loaded.
Sub-Processors & Third-Party Services
We use the following third-party service providers (sub-processors) to operate PDFlys. Each processes data in accordance with its own privacy policy and applicable data processing agreement:
| Service | Purpose | Data Processed | Location | Transfer Safeguard |
|---|---|---|---|---|
| Firebase Auth (Google) | Authentication | Name, email, UID | USA | EU-US DPF + SCCs |
| Firestore (Google) | User preferences | Email, settings | USA | EU-US DPF + SCCs |
| Plausible Analytics | Privacy-friendly analytics | Anonymous page views | EU (Estonia) | N/A (no PII) |
| Google Analytics (GA4) | Analytics (opt-in) | IP, device, behavior | USA | EU-US DPF + SCCs |
| Google Ads | Conversion tracking (opt-in) | Conversion events | USA | EU-US DPF + SCCs |
| Cloudflare | CDN, DDoS protection | IP, request metadata | USA/Global | EU SCCs |
| Sentry | Error monitoring | Error traces, device info | USA | EU SCCs |
None of these services have access to the PDF files you edit in PDFlys.
We will notify registered users via email if we add new sub-processors that process personal data.
International Data Transfers
PDFlys is based in the Kingdom of Saudi Arabia. Your personal data may be transferred to and processed in countries outside Saudi Arabia and the European Economic Area (EEA), including the United States, through our service providers.
Transfer Safeguards (PDPL): We ensure all cross-border transfers comply with the Saudi Personal Data Protection Law (PDPL) and do not conflict with the Kingdom's national interests. We use appropriate safeguards including Standard Contractual Clauses (SCCs) with all sub-processors.
Transfer Safeguards (GDPR): For transfers of EU/EEA personal data, our service providers maintain appropriate safeguards including the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs).
Data Retention
In accordance with the PDPL principle that personal data should not be retained longer than necessary for its purpose, we apply the following retention periods:
- PDF files: Not stored — processed in your browser only
- Account data (name, email): Until account deletion or 24 months of inactivity
- User preferences: Until account deletion or 24 months of inactivity
- Cookie consent records: 12 months (then re-consent required)
- Google Analytics data: 14 months (GA4 default)
- Sentry error data: 90 days
- Support/contact emails: 24 months after resolution
Your Data Protection Rights
Rights Under Saudi PDPL (All Users)
Under the Saudi Personal Data Protection Law (PDPL), you have the following rights:
- Right to Be Informed (Art. 8) — Know what data we collect, why, and who receives it
- Right of Access (Art. 10) — Request a copy of all personal data we hold about you
- Right to Rectification (Art. 10) — Correct inaccurate or incomplete personal data
- Right to Erasure (Art. 10) — Request deletion of your personal data
- Right to Data Portability (Art. 10) — Receive your data in a machine-readable format
- Right to Restrict Processing — Limit how we process your data in certain situations
- Right to Withdraw Consent (Art. 6) — Withdraw consent at any time without affecting prior processing
Additional Rights for EU/EEA Users (GDPR)
- Right to Object (Art. 21) — Object to processing based on legitimate interest
- Right Regarding Automated Decisions (Art. 22) — Not be subject to solely automated decision-making
Rights for California Residents (CCPA/CPRA)
California residents have the right to know what personal data we collect, request deletion, and opt out of the sale of personal data. PDFlys does not sell personal data.
Rights for Brazilian Users (LGPD)
Brazilian users have rights to access, correct, anonymize, delete, and port their personal data under the Lei Geral de Protecao de Dados.
To exercise any of these rights, contact us at privacy@pdflys.com. We will respond within 30 days (extendable by an additional 30 days for complex requests under PDPL, or 60 days under GDPR).
You can also exercise certain rights directly: use "Download My Data" in Settings for data portability, and "Delete Account" for erasure.
You have the right to lodge a complaint with the relevant supervisory authority:
- Saudi Arabia: Saudi Data & AI Authority (SDAIA) — sdaia.gov.sa
- European Union: Your national Data Protection Authority
- United Kingdom: Information Commissioner's Office (ICO)
Email Communications
If you create an account, you may opt in to receive product updates, tips, and feature announcements via email. This checkbox is unchecked by default at signup — we will never send you marketing emails unless you explicitly opt in.
You can change your email preference at any time from your Settings page or by emailing privacy@pdflys.com.
Your Choices & Opt-Out
You have full control over the data collected through PDFlys:
- Cookie consent: You can accept or decline cookies when you first visit PDFlys. If you decline, no analytics or advertising scripts are loaded and no cookies are set.
- Changing your cookie preference: You can change your cookie preference at any time from your Settings page, or by clearing site data for pdflys.com in your browser settings.
- Marketing emails: You can manage your email preferences from your Settings page or by emailing privacy@pdflys.com.
- Google Ads personalization: You can opt out of Google's use of cookies for ad personalization by visiting Google Ads Settings.
- General opt-out: You can opt out of third-party vendor cookies for advertising at aboutads.info or youronlinechoices.com.
- Browser controls: Most browsers allow you to block or delete cookies through their settings.
Because PDFlys processes all files locally in your browser, opting out of cookies does not affect any PDF editing functionality.
Children's Privacy
PDFlys is not intended for children under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly.
Changes to This Policy
If we make material changes to how we process your personal data, we will notify you via email (for registered users) and a prominent notice on our website at least 30 days before the changes take effect. For changes that require consent under the PDPL, GDPR, or other applicable law, we will obtain your explicit consent before applying the new processing activities.
For non-material changes (e.g., formatting, clarifications), we will update this page with a new "Last Updated" date.
Contact & Complaints
If you have questions about this Privacy Policy or wish to exercise your data protection rights, you can reach us at:
- Privacy inquiries: privacy@pdflys.com
- General inquiries: hello@pdflys.com
- Security inquiries: security@pdflys.com
If you are not satisfied with our response, you may lodge a complaint with:
- Saudi Arabia: Saudi Data & AI Authority (SDAIA) — sdaia.gov.sa
- European Union: Your national Data Protection Authority