Privacy Policy

Last updated: 16 July 2026 · Effective: 16 July 2026

This Privacy Policy explains what information NotAnotherPDF ("the App") collects, how we use it, who we share it with, and the rights you have. We built the App to do its job without hoarding your data. NotAnotherPDF is available worldwide, and this policy applies to everyone who uses the App, wherever they are.

The short version

Who we are (Data Controller)

The App is provided by Enfoa Cybersecurity LLC ("we", "us"), a company registered in the United States.

Enfoa Cybersecurity LLC
10900 Research Blvd, Ste 160C, Austin, TX 78759, United States
Email: [email protected]

For the purposes of the EU/UK GDPR, we are the data controller for the personal data described here.

Information we collect

CategoryWhat it includesWhy
AccountA randomly generated account identifier created on first launch, your credit balance, subscription (Pro) status, and a per-account purchase token. If you use Sign in with Apple, we also store the unique identifier Apple assigns (not your name or email).To create your account, keep your credits, and link your purchases.
Document contentThe images/pages you scan or import, and the text extracted from them.To perform text recognition (OCR) and return the result to you. Processed transiently; see below.
PurchasesApple transaction identifiers and subscription status received from Apple.To grant credits/Pro and verify purchases. We never see your card details.
Usage & diagnosticsIP address, approximate country, device model, OS version, app version, language, screens viewed, number of scans completed/failed, and crash/performance diagnostics.To run the service securely, prevent abuse, fix bugs, and understand how the App is used.
Fraud preventionA one-time device token from Apple's DeviceCheck service, generated when your account is created or attached. Apple stores two small per-device flags for us that record whether this device has already received free credits; these flags live at Apple, not on our servers.To grant the free credit allowance once per device and prevent abuse. The token does not identify you or your device to us and cannot be used to track you across apps.

We do not request your name, and we do not store an email address. We use no advertising SDKs and no cross-app tracking. Usage data goes to our own backend; purchase events are also shared with RevenueCat, our subscription-analytics provider (see Service providers).

Your documents and AI processing

When you scan or import a document, the page images are sent over an encrypted connection to our backend (hosted on Cloudflare) and to OpenAI, which performs the AI text recognition. The recognized text is returned to your device.

Please note: documents you scan may contain sensitive information (for example IDs, medical, or financial details). Only scan documents you are comfortable processing through a cloud AI service, and avoid uploading content you are not authorized to share.

How and why we use your data (legal bases)

PurposeLegal basis (GDPR)
Provide the App, recognize text, sign and export documentsPerformance of a contract (Art. 6(1)(b))
Process purchases and manage credits/subscriptionsPerformance of a contract (Art. 6(1)(b))
Keep the service secure and prevent fraud/abuse (incl. IP for rate-limiting)Legitimate interests (Art. 6(1)(f))
Diagnostics, crash reporting, and product analyticsLegitimate interests (Art. 6(1)(f))
Comply with legal obligationsLegal obligation (Art. 6(1)(c))

Service providers (sub-processors)

We share the minimum data needed with trusted providers who process it on our behalf under data-protection agreements:

ProviderPurposeMore info
Apple Inc.Sign in with Apple, App Store, in-app purchases, DeviceCheck fraud prevention, crash diagnosticsApple Privacy
Cloudflare, Inc.Backend hosting, edge network, database and temporary storageCloudflare Privacy
RevenueCat, Inc.Purchase and subscription analytics (receives purchase events and an anonymous app identifier; no advertising, no cross-app tracking)RevenueCat Privacy
OpenAIAI text recognition (OCR) of scanned documentsOpenAI Policies

We do not sell your personal data or share it for advertising.

We may access, preserve, or disclose your information if we reasonably believe it is necessary to: comply with a law, regulation, legal process, or enforceable government request; enforce our Terms, including investigating potential violations; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of our users, the public, or us, as permitted by applicable law. Where the law allows, we limit any such disclosure to what is necessary.

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy, and we will notify you before your information becomes subject to a materially different policy.

International data transfers

We are based in the United States, and our providers process data in the United States and other countries. Where personal data of users in the EU/EEA, UK, or Switzerland is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the providers' certification under the EU-US Data Privacy Framework. You may request a copy of the relevant safeguards by contacting us.

How long we keep data

Delete your account and data

You can delete your account and associated personal data at any time:

When you delete your account, we permanently remove your credits and subscription state, any documents and scan data, your session(s), your device attestation keys, and your purchase-reconciliation records, and you are signed out.

To keep the service secure and prevent abuse (for example, blocking repeated free-credit farming and detecting fraud), we retain a limited set of security and usage metrics (which can include your account identifier, IP address, approximate country, device and app details, and aggregate scan counts) under our legitimate interests (GDPR Art. 6(1)(f)). Apple, as the seller of record, keeps purchase and tax records under its own policies. This retained data is never used to advertise to you or to reconstruct your documents. To ask about the data kept after deletion, contact [email protected].

Your rights: EU/EEA, UK & Switzerland (GDPR)

If you are in the EU/EEA, UK, or Switzerland, you have the right to: access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent at any time (without affecting prior processing). To exercise any right, contact [email protected]. When you exercise the right to erasure, we may retain the limited security and fraud-prevention data described under Delete your account where our legitimate interests or legal obligations allow.

You also have the right to lodge a complaint with your local data protection authority. If you are unhappy with our response, you may contact your national supervisory authority.

EU & UK Representative (Art. 27). We have appointed a representative you can contact on any matter relating to our processing of personal data of individuals in the EU/EEA and the UK:

Sibel Inceleme
Alsdorf, Germany
Email: [email protected]

Your rights: California (CCPA/CPRA) & other US states

If you are a California resident, you have the right to know what personal information we collect and how it is used, to access and delete it, to correct inaccuracies, and to opt out of the sale or sharing of personal information.

We do not sell or share your personal information as those terms are defined under California law, and we do not use it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights. To make a request, email [email protected]. Residents of other US states with similar laws may exercise comparable rights the same way.

Your rights in other regions

NotAnotherPDF is used around the world, and this policy applies wherever you are. Depending on where you live, you may have additional rights under your local data protection laws, and we honor them. These include, among others:

To exercise any of these rights, email [email protected]. We apply the same core protections to every user regardless of location: no document storage, no selling of data, and no advertising trackers. Because we and our service providers operate globally, your data may be processed in the United States and other countries under the safeguards described in International data transfers.

Children's privacy

The App is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

Security

We protect your data using industry-standard measures, including encryption in transit, device-based app attestation, hashed session tokens, and access controls, and we delete your documents from our servers right after processing.

However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. To the maximum extent permitted by law, we are not responsible for any unauthorized access to, disclosure, alteration, or loss of your data caused by events beyond our reasonable control, including the acts of third parties. You also help keep your data safe: secure your device and Apple ID, and keep your own backups of important documents. If a data breach ever affects your personal data, we will notify you and the relevant authorities as required by law.

Changes to this policy

We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide notice in the App or on this page.

Contact us

Questions or requests about privacy? Email [email protected] or write to Enfoa Cybersecurity LLC, 10900 Research Blvd, Ste 160C, Austin, TX 78759, United States.