Back to home

Privacy and local storage

Technical notice about local files, account data and purchases.

Last updated: 2026-10-10

Notice status

Development draft; not ready for a paid launch. The controller, contact details, active suppliers and final retention periods have not been configured. These must be published and verified before purchases are enabled. No contact address is invented.

Files on your device

Documents, filenames, text, certificates and invoice data are processed in your browser. The product has no document upload interface. Do not place these details in support requests, URLs or messages.

Files normally remain in memory. Closing or losing a tab may require selecting them again. Releasing memory references does not guarantee forensic erasure.

Buying or restoring Single Export sends the selected file’s SHA-256 digest, associated with the order and a hash of the browser purchase credential. Legacy account purchases remain account-linked. No filename, document bytes, certificates or invoice fields are sent. A digest can link identical copies and is not anonymous data. Free preview sends no digest; Pro checkout needs no digest. Retention must be finalized before sales.

Optional temporary recovery

Before sign-in or payment you may choose to store input files in this browser’s IndexedDB. Recovery eligibility lasts 15 minutes. Quota limits, private browsing and cleared site data may prevent recovery.

Expired records are cleared on startup, returning to the foreground and before recovery, with best-effort cleanup while active. A closed browser cannot guarantee a deletion timer. Browser site settings can remove local data. Record deletion does not guarantee physical disk erasure.

Accounts, transactions and network data

Single Export does not require registration. The payment provider still processes necessary billing, payment and transaction data. Pro uses a verified account. Registration, sign-in and email verification separately involve account data; network requests may include IP addresses and browser information.

When enabled, Single Export uses an embedded Stripe form in the purchase dialog; Pro uses hosted Stripe checkout. Stripe provides the payment form, and this site does not receive card details. Some verification methods may redirect to a bank. Stripe scripts load only after a purchase action; documents are not sent. Necessary account email uses the operator’s configured provider.

Technical storage

  • Authentication session and language cookies.
  • Guest purchases use an HttpOnly browser credential cookie for up to 365 days; the server stores only its hash. During confirmation, an order number, document digest and start time may remain locally for up to 10 minutes, without documents or payment-form secrets.
  • You may download a purchase recovery code. It grants access to purchased file rights and must be kept private. Clearing cookies requires that code or a still-valid local license.
  • Theme preferences, a logical browser identifier and a verifiable local Pro license. The license lasts at most 24 hours and never beyond plan expiry; it is not an authentication credential.
  • Public app resources in Cache Storage for later offline opening. Account, API and payment responses must not be cached.
  • A local interrupted-task marker without file details.

This release includes no advertising, third-party analytics, session replay or chat scripts. Storage is described by its purpose rather than its API name.

Retention, rights and contact

The initial security-log target is 7 days without document contents. Infrastructure enforcement remains to be verified; automatic deletion is not yet guaranteed. Account and transaction retention must be set against applicable obligations and provider agreements.

Before launch, the operator must publish processing grounds, recipients, transfers and applicable rights procedures. Contact details are not configured yet; see Support. Do not send sensitive documents.

Terms of service