Privacy Policy

This Privacy Policy describes how Pdfstudio (“we,” “us,” or “our”) handles information in connection with the mobile application PDF To Image – Easy Extractor (“the App”).

Last Updated: 30 June 2026 Platforms: Android & iOS Category: Productivity

1. Introduction

Welcome to PDF To Image – Easy Extractor. We are committed to protecting your privacy and ensuring that your personal information and files are handled with the utmost care. This Privacy Policy explains our practices regarding information handling in connection with your use of the App on Android and iOS devices.

PDF To Image is an offline-first productivity application that converts PDF documents into high-quality images directly on your device. The App does not require user accounts, logins, registrations, subscriptions, or payments of any kind. It has been designed from the ground up to process your files locally, without transmitting them to any remote server, cloud service, or third-party processing platform.

By downloading, installing, or using the App, you agree to the terms described in this Privacy Policy. If you do not agree with the terms of this policy, please do not use the App. We encourage you to read this policy carefully and to contact us if you have any questions.

Key Principle: Your PDF files and generated images never leave your device. All processing happens locally, offline, and without any cloud involvement.

2. Information We Collect

We take a minimal and transparent approach to data handling. The following table provides a clear summary of what the App does and does not collect:

Data Category Collected? Details
Personal Information (name, email, phone, address) No The App does not collect any personally identifiable information.
PDF Files No PDF files are processed entirely on-device and are never uploaded, transmitted, or stored on any server.
Generated Images No Images are created and saved locally on your device only.
Device Identifiers No We do not collect device identifiers such as IMEI, advertising IDs, or serial numbers.
Location Data No The App does not access or collect any location information.
Photos or Media Files (beyond user-selected PDFs) No Only PDF files selected by the user for conversion are processed.
Payment Information No The App does not accept payments, subscriptions, or in-app purchases.
Anonymous Analytics Limited See Section 4 – Analytics for details on Firebase Analytics.

In summary, the App does not collect, store, transmit, or share any personal information or user files. The only data processing that involves any external service is the limited, anonymous analytics data described in Section 4 of this policy.

3. Offline-First Design

PDF To Image has been built with an offline-first architecture, which means that all core functionality operates entirely on your device without requiring an active internet connection. This design philosophy is central to our commitment to your privacy and data security.

3.1 How Offline-First Works

When you select a PDF file for conversion, the App reads and processes that file using on-device rendering engines. The PDF pages are converted into images at your chosen resolution (Low, Medium, High, or Ultra) and saved in your selected format (PNG, JPG, or WEBP) directly to your device’s local storage. This entire process — from file selection to image generation to saving — occurs without any data leaving your device.

3.2 What This Means for Your Data

  • Your PDF files remain on-device. They are never uploaded to any cloud server, remote endpoint, or third-party processing service. The file path or content is not transmitted externally during normal operation.
  • Generated images are created locally. All image output is rendered and saved on your device. No image data is sent to any external server.
  • Internet connectivity is not required for core functionality. The App performs PDF-to-image conversion entirely offline. An internet connection is only relevant if Firebase Analytics is active, as described in Section 4.
  • No cloud processing. There is no server-side component for PDF processing. All computational work is performed locally using your device’s resources.
  • No background uploads. The App does not upload, sync, or transmit files in the background at any time, whether the App is in the foreground or background state.
  • No AI or OCR processing. The App performs straightforward format conversion (PDF to image). It does not use any artificial intelligence, machine learning, or optical character recognition (OCR) technology to analyze the content of your documents.
Sharing: When you use the device share menu to share a generated image, the image is sent only to the app or service you explicitly choose (e.g., a messaging app, email, or cloud storage). We do not control or have access to that external sharing process.

4. Analytics – Firebase Analytics

The App uses Firebase Analytics, a service provided by Google, Inc. (“Google”), to collect limited, anonymous usage information. This section explains what Firebase Analytics is, what data it may collect, and how you can control it.

4.1 What Is Firebase Analytics?

Firebase Analytics is an app measurement solution that provides insight into how users interact with an application. It automatically captures certain events and user properties and sends this data to Google’s servers for analysis. Firebase Analytics helps developers understand app usage patterns, such as which features are used most frequently and how users navigate through the App.

4.2 What Data May Firebase Analytics Collect?

Firebase Analytics may collect the following types of anonymous data:

  • Anonymous identifiers: A unique, anonymized identifier assigned to your device installation. This identifier does not contain any personally identifiable information and cannot be used to identify you individually.
  • Device information: General device characteristics such as device model, operating system version, screen resolution, and device language settings.
  • App usage data: Information about how you interact with the App, including which screens you visit, which features you use (e.g., PDF selection, conversion settings), and the frequency and duration of App sessions.
  • Performance data: App performance metrics such as crash reports, ANR (Application Not Responding) events, and startup times.

4.3 What Firebase Analytics Does NOT Collect

Critical: Firebase Analytics does NOT have access to, and does NOT collect, transmit, or process your PDF files or the images generated by the App. Firebase Analytics is a usage measurement tool only — it operates independently of the App’s file conversion functionality and has no capability to access or upload your personal documents.

4.4 How to Disable Analytics

You may opt out of Firebase Analytics through your device’s privacy settings:

  • Android: Navigate to Settings → Google → Ads → Delete advertising ID or Settings → Privacy → Ads (varies by device manufacturer and Android version). You may also opt out of Google Analytics for advertising personalization through Google’s Ads Settings. Additionally, you can disable ad personalization entirely in your Google Account settings at myaccount.google.com/activitycontrols.
  • iOS: Navigate to Settings → Privacy & Security → Tracking and disable the setting for “Allow Apps to Request to Track.” You may also manage advertising identifiers in Settings → Privacy & Security → Apple Advertising → Personalized Ads.

4.5 Google’s Privacy Policy

Firebase Analytics is operated by Google, and its data handling is governed by Google’s own privacy policies. We encourage you to review these policies to understand how Google processes analytics data:

5. Device Permissions

The App requests certain permissions from your device’s operating system in order to function properly. Each permission is described below, along with its purpose and scope.

5.1 Notification Permission

AttributeDetail
PermissionPost Notifications (Android 13+) / Notification Authorization (iOS)
PurposeUsed exclusively for sending user-facing notifications related to the App’s conversion functionality. This includes notifications about the completion status of PDF-to-image conversions, progress updates for batch processing, and important app functionality alerts (e.g., errors during conversion, storage availability warnings).
Data AccessedNo personal data is accessed through this permission. Notifications are generated locally and do not transmit information externally.
When RequestedPermission is requested at the point when the App first needs to display a notification, or when the user navigates to notification settings within the App.
Can Be Revoked?Yes. You can revoke this permission at any time through your device settings: Settings → Apps → PDF To Image → Notifications (Android) or Settings → Notifications → PDF To Image (iOS).

5.2 Storage / File Access Permission

AttributeDetail
PermissionRead/Write External Storage (Android) / Photo Library Access (iOS)
PurposeRequired to access PDF files you select for conversion and to save the generated images to your device’s storage. On Android, this uses the Storage Access Framework (SAF) or the MediaStore API, depending on the Android version. On iOS, the document picker is used to select files, and saved images are stored in your Photo Library or Files app, depending on your selection.
Data AccessedOnly the specific PDF file(s) you explicitly select for conversion. The App does not scan, index, or access any other files on your device.
Can Be Revoked?Yes. You can manage storage permissions through your device settings at any time. Revoking this permission will prevent the App from accessing files for conversion.

5.3 Permissions Are Never Used for Tracking

Important: None of the permissions requested by the App are used for tracking, surveillance, advertising profiling, or any purpose beyond the specific, limited functionality described above. The App does not access your contacts, microphone, camera, location, phone state, or any other hardware sensors or data sources not explicitly listed in this section.

6. How We Use Information

Given the App’s offline-first design, our use of information is extremely limited. Specifically:

  • App Improvement: We use anonymized Firebase Analytics data (as described in Section 4) to understand general usage patterns, identify bugs and crashes, and improve the App’s performance and user experience. This data does not identify you personally and does not include any content from your PDF files or generated images.
  • Core Functionality: PDF files you select are processed locally on your device for the sole purpose of generating images as you have requested. This processing does not involve any data collection, transmission, or external access.
  • No Personalized Advertising: We do not use any collected data to build user profiles, serve targeted advertisements, or make automated decisions affecting your rights.
  • No Data Sale: We do not sell, rent, trade, or otherwise monetize any user data. The App does not collect any personal data to sell in the first place.

7. Data Retention

Since the App does not collect, store, or transmit personal information or user files to our servers, there is no data retention period applicable to personal data under our direct control. The App itself does not maintain any database, log file, or cache of your documents, images, or personal information beyond what is necessary for the immediate conversion task on your device.

Regarding Firebase Analytics data, retention is governed by Google’s data retention policies. Firebase Analytics data is retained for a configurable period (typically up to 14 months by default), after which it is automatically deleted. For more information, please refer to Google’s documentation on data retention for Analytics.

On your device, PDF files and generated images are stored according to your device’s file management system. These files remain on your device until you choose to delete them through your device’s file manager or the App’s interface. We have no access to, or control over, files stored on your device.

8. Data Sharing & Disclosure

We do not share, sell, rent, or disclose any personal information to third parties because the App does not collect personal information in the first place. The limited, anonymous analytics data collected through Firebase Analytics is processed by Google in accordance with Google’s privacy policies, as detailed in Section 4.

We may disclose information only in the following limited circumstances:

  • Legal Requirements: If required by applicable law, regulation, legal process, or governmental request. Given that we do not possess personal data or user files, the scope of any such disclosure would be extremely limited to any analytics metadata that may exist within Firebase.
  • Protection of Rights: To protect the rights, property, or safety of Pdfstudio, our users, or the public, to the extent permitted by law. Again, because we do not collect personal data, the practical impact of any such disclosure would be minimal.

We do not participate in any data broker arrangements, do not share data for marketing purposes, and do not engage in cross-device tracking or user profiling of any kind.

9. Third-Party Services

9.1 Firebase Analytics (Google, Inc.)

The App integrates Firebase Analytics, a product of Google, Inc., for the purpose of collecting limited, anonymous usage data as described in Section 4. Firebase Analytics is governed by Google’s own privacy policy, terms of service, and data processing agreements. The App sends only anonymized, non-personal usage events to Firebase Analytics. No PDF content, image content, or personally identifiable information is transmitted to Firebase.

9.2 Mobile Platform Privacy Policies

The App operates within the ecosystems of Google (Android) and Apple (iOS), each of which has its own privacy practices and policies that may apply to your use of the App:

  • Google Play Services: When installed on an Android device, the App may interact with Google Play Services for analytics and other basic platform functions. Google’s privacy policy applies to data processed by Google Play Services: https://policies.google.com/privacy.
  • Apple iOS: When installed on an iOS device, the App operates within Apple’s ecosystem. Apple’s privacy policy applies to data processed by Apple’s platform services: https://www.apple.com/legal/privacy/en-ww/.

We do not control and are not responsible for the privacy practices of Google, Apple, or any other third-party service provider. We encourage you to review their respective privacy policies.

10. Security

We take the security of your information seriously and have implemented the following measures and architectural decisions to protect your data:

  • Local Processing: All PDF-to-image conversion is performed entirely on your device. Because files are never transmitted over the internet during normal App operation, there is no risk of interception, man-in-the-middle attacks, or data breaches involving your documents.
  • Files Remain On-Device: Your PDF files and generated images are stored only in your device’s local file system. We do not have access to these files, and they are never uploaded to any remote server or cloud storage service operated by us.
  • No Cloud Storage: The App does not use any cloud storage services for user files. There is no cloud-based backup, sync, or storage feature. All data resides exclusively on your device.
  • No Remote Servers: The App does not communicate with any backend servers operated by Pdfstudio for the purpose of file processing, storage, or retrieval. The only external communication is the limited Firebase Analytics data described in Section 4, which is transmitted over encrypted HTTPS connections.
  • Reasonable Safeguards: While no system can guarantee absolute security, we employ industry-standard practices to protect the App and its functionality. This includes using secure communication protocols (HTTPS/TLS) for any external data transmission, following platform security guidelines for Android and iOS, and testing the App for common security vulnerabilities.
  • Platform Protections: The App benefits from the built-in security features of the Android and iOS operating systems, including application sandboxing, file system access controls, and platform-level encryption of device storage.
Note: The security of your files also depends on the physical security of your device and the security settings you have configured on your operating system. We recommend using device encryption, screen lock, and keeping your operating system up to date.

11. GDPR & UK GDPR Compliance

The General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK General Data Protection Regulation as incorporated into UK law by the European Union (Withdrawal) Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (“UK GDPR”) provide comprehensive data protection rights to individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland.

11.1 Lawful Basis for Processing

Under GDPR and UK GDPR, the App processes limited data as follows:

  • Firebase Analytics Data: Processed on the basis of Legitimate Interest (Article 6(1)(f) GDPR), specifically our legitimate interest in understanding general app usage patterns, improving app performance, and fixing bugs. This processing involves only anonymous, aggregated data and does not infringe on your rights and freedoms because the data cannot be used to identify you personally. Where consent is required by Google’s own processing, Google obtains such consent through its own mechanisms.
  • Local File Processing: The processing of PDF files and generation of images on your device does not constitute “processing” under GDPR as it occurs entirely locally without any transmission to us or any third party. We do not act as a data controller or processor for your locally processed files.

11.2 Your Rights Under GDPR / UK GDPR

If you are a resident of the EEA, UK, or Switzerland, you have the following rights under GDPR and UK GDPR:

  • Right of Access (Article 15): You have the right to obtain confirmation of whether personal data concerning you is being processed, and if so, to access that data and certain supplementary information. Given that the App does not collect personal data, any such access request would yield no personal data under our control.
  • Right to Rectification (Article 16): You have the right to have inaccurate personal data corrected and incomplete personal data completed. Since we do not maintain personal data, there is no data to rectify.
  • Right to Erasure / Right to Be Forgotten (Article 17): You have the right to have personal data concerning you erased without undue delay. As we do not collect or store personal data, there is no personal data to erase. Any analytics data held by Google is subject to Google’s own retention and deletion policies.
  • Right to Restriction of Processing (Article 18): You have the right to restrict the processing of your personal data in certain circumstances. You may exercise this right by disabling Firebase Analytics through your device settings as described in Section 4.4.
  • Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Since we do not collect personal data, there is no data to port. Your PDF files and generated images are already stored in standard formats on your device.
  • Right to Object (Article 21): You have the right to object to processing based on legitimate interests. You may exercise this right by disabling Firebase Analytics through your device settings.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you have the right to withdraw consent at any time. You may withdraw consent for analytics tracking by adjusting your device privacy settings.
  • Rights Related to Automated Decision-Making (Article 22): The App does not engage in automated decision-making, including profiling, that produces legal effects or similarly significant effects concerning you.
  • Right to Lodge a Complaint (Article 77): You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe that the processing of your personal data violates GDPR or UK GDPR. In the EU, you may contact your national data protection authority. In the UK, you may contact the Information Commissioner’s Office (ICO) at https://ico.org.uk.

11.3 Data Protection Officer

The App does not currently require the appointment of a Data Protection Officer under Article 37 of GDPR, as our processing activities do not meet the threshold for mandatory appointment (we do not carry out large-scale systematic monitoring or large-scale processing of special categories of data). If you have any data protection inquiries, please contact us directly at the email address provided in Section 25.

12. CCPA / CPRA Compliance

The California Consumer Privacy Act of 2018 (“CCPA”), as amended by the California Privacy Rights Act of 2020 (“CPRA”), provides California residents with specific rights regarding the collection, use, and sale of their personal information.

12.1 Categories of Personal Information

For the past 12 months, we have collected the following categories of personal information (all through Firebase Analytics only):

CategoryCollected?Examples
IdentifiersNoReal name, email address, etc. — not collected.
Customer RecordsNoAddress, phone number, payment info — not collected.
Protected ClassificationsNoAge, race, religion — not collected.
Commercial InformationNoPurchase history — not applicable.
Internet / Network ActivityLimitedAnonymous app interaction events via Firebase Analytics.
Geolocation DataNoNot collected.
Sensory DataNoAudio, images (from camera) — not collected.
Professional / Employment InfoNoNot collected.
Non-Public Education InfoNoNot collected.
InferencesNoWe do not create inferences or profiles about you.
Sensitive Personal InformationNoAccount credentials, precise geolocation, race, etc. — not collected.

12.2 Your Rights Under CCPA / CPRA

  • Right to Know / Right to Access: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the purposes for which we use it, and the third parties with whom it has been shared. To submit a verifiable consumer request, please contact us at ronik2599@gmail.com.
  • Right to Delete: You have the right to request the deletion of your personal information. Given that we do not collect personal information directly, there is no personal data in our possession to delete. Any analytics data held by Google is subject to Google’s own deletion mechanisms.
  • Right to Correct: You have the right to correct inaccurate personal information that we maintain about you. As we do not maintain personal data, there is nothing to correct.
  • Right to Opt-Out of Sale / Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary, but you may disable analytics as described in Section 4.4.
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information. No action is required on your part.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

12.3 No Sale of Personal Information

We have not sold and do not sell personal information in the preceding 12 months, nor do we intend to sell personal information in the future. Furthermore, we do not share personal information for cross-context behavioral advertising.

13. US State Privacy Laws

In addition to the CCPA/CPRA, several US states have enacted comprehensive consumer privacy legislation. We respect these laws and are committed to complying with their requirements. The following states have enacted privacy laws that may apply:

  • Virginia Consumer Data Protection Act (VCDPA): Effective January 1, 2023. Grants Virginia residents the right to access, correct, delete, and obtain a copy of personal data, as well as the right to opt out of processing for purposes of targeted advertising, sale of personal data, or profiling. We do not engage in targeted advertising, sale of data, or profiling.
  • Colorado Privacy Act (CPA): Effective July 1, 2023. Provides Colorado residents with rights similar to the VCDPA, including access, correction, deletion, data portability, and the right to opt out. We do not process personal data for targeted advertising, sale, or profiling.
  • Connecticut Data Privacy Act (CTDPA): Effective July 1, 2023. Grants Connecticut residents rights to access, correct, delete, and port their personal data, and the right to opt out of targeted advertising and the sale of personal data.
  • Utah Consumer Privacy Act (UCPA): Effective December 31, 2023. Provides Utah residents rights to access, delete, and correct personal data, and the right to opt out of targeted advertising and the sale of personal data.
  • Iowa Consumer Data Protection Act: Effective January 1, 2025. Grants Iowa residents rights to access, correct, delete, and obtain a copy of personal data, and the right to opt out of targeted advertising, sale, and profiling.
  • Indiana Consumer Data Protection Act: Effective January 1, 2026. Similar consumer rights framework for Indiana residents.
  • Montana Consumer Data Privacy Act: Effective October 1, 2024. Provides Montana residents with data access, correction, deletion, and opt-out rights.
  • Tennessee Information Protection Act (TIPA): Effective July 1, 2025. Grants Tennessee residents comprehensive data privacy rights.
  • Oregon Consumer Privacy Act: Effective July 1, 2024. Provides Oregon residents with data protection rights including access, deletion, correction, and opt-out.
  • Texas Data Privacy and Security Act (TDPSA): Effective July 1, 2024. Grants Texas residents data privacy rights including access, correction, deletion, and opt-out.
  • Delaware Personal Data Privacy Act: Effective January 1, 2025. Provides Delaware residents with comprehensive data privacy protections.
  • New Hampshire Consumer Privacy Act: Effective January 1, 2025. Grants New Hampshire residents data privacy rights.
  • New Jersey Data Privacy Act: Effective January 15, 2025. Provides New Jersey residents with consumer data protection rights.
  • Maryland Online Data Privacy Act: Effective October 1, 2025. Grants Maryland residents data privacy rights.
  • Minnesota Consumer Data Privacy Act: Effective January 1, 2026. Provides Minnesota residents with comprehensive privacy rights.
  • Nebraska Data Privacy Act: Effective January 1, 2026. Grants Nebraska residents data protection rights.
  • Additional States: Other US states may enact or have enacted similar privacy legislation. This policy is designed to comply broadly with comprehensive US state consumer privacy laws. As new laws become effective, we will update our practices and this policy as needed.

For all US state privacy laws, the practical effect is the same: since the App does not collect personal information, there is no personal data to access, correct, delete, or port under our direct control. If you wish to exercise any of these rights, please contact us at ronik2599@gmail.com. We will respond within the timeframes required by the applicable state law.

14. PIPEDA Compliance (Canada)

The Personal Information Protection and Electronic Documents Act (“PIPEDA”) is Canada’s federal private-sector privacy law. PIPEDA sets out ground rules for how private-sector organizations collect, use, and disclose personal information in the course of commercial activity.

14.1 The Ten Principles of PIPEDA

Our practices align with the ten fair information principles set out in the Canadian Standards Association’s Model Code for the Protection of Personal Information, which forms Schedule 1 of PIPEDA:

  1. Accountability: Pdfstudio is responsible for personal information under its control. Although we do not collect personal information directly through the App, we are accountable for any data practices that may involve third-party services like Firebase Analytics.
  2. Identifying Purposes: The purposes for which any information is collected (namely, anonymous analytics) are identified in this Privacy Policy.
  3. Consent: Knowledge and consent are required for the collection, use, or disclosure of personal information. Firebase Analytics consent is managed through Google’s own consent mechanisms and device-level privacy settings.
  4. Limiting Collection: Our collection of information is limited to what is necessary for the purposes identified in this policy. We collect no personal information.
  5. Limiting Use, Disclosure, and Retention: Personal information is not used or disclosed for purposes other than those for which it was collected, except with consent or as required by law. No personal data is retained by us.
  6. Accuracy: Personal information shall be as accurate, complete, and up-to-date as necessary for the purposes for which it is used. Since we do not maintain personal data records, this principle is inherently satisfied.
  7. Safeguards: Security safeguards appropriate to the sensitivity of the information are implemented. As described in Section 10, the App’s offline-first architecture provides strong inherent safeguards.
  8. Openness: This Privacy Policy is readily available to users and describes our information handling practices transparently.
  9. Individual Access: Upon request, individuals have the right to access their personal information and challenge its accuracy. As we do not collect personal information, there is no data to access. You may contact us to verify this.
  10. Challenging Compliance: Individuals may challenge our compliance with the above principles by contacting us. You may also file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.

15. Australian Privacy Act

The Privacy Act 1988 (Cth) (“Privacy Act”) is the principal Australian legislation governing the handling of personal information by federal government agencies and certain private sector organizations. While the App may not meet the threshold of an “organization” with an annual turnover of more than AUD 3 million, we voluntarily comply with the Australian Privacy Principles (“APPs”) as a matter of best practice.

15.1 Application of the APPs

  • APP 1 – Open and Transparent Management of Personal Information: This Privacy Policy serves as our APP privacy policy, clearly describing how we handle (or, in this case, do not handle) personal information.
  • APP 3 – Collection of Solicited Personal Information: We do not solicit or collect personal information through the App. The only data processing involves anonymous analytics through Firebase Analytics, which does not constitute collection of personal information under the Privacy Act.
  • APP 6 – Use or Disclosure of Personal Information: We do not use or disclose personal information. We do not disclose personal information to overseas recipients beyond what may occur through Firebase Analytics (which processes only anonymous, non-personal data).
  • APP 11 – Security of Personal Information: As described in Section 10, the App’s offline-first design ensures strong security for user files. We take reasonable steps to protect any information from misuse, interference, loss, unauthorized access, modification, or disclosure.
  • APP 12 – Access to Personal Information: If you believe we hold any personal information about you, you may request access by contacting us. Given that the App does not collect personal information, such a request would yield no personal data.

If you wish to make a privacy complaint, you may contact us directly or lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.

16. LGPD Compliance (Brazil)

Lei Geral de Proteção de Dados Pessoais (“LGPD”, Law No. 13,709/2018) is Brazil’s comprehensive data protection law. LGPD applies to the processing of personal data of individuals in Brazil, regardless of where the processing takes place.

16.1 Legal Bases for Processing

Under LGPD (Article 7), any processing of personal data requires a valid legal basis. The App does not collect personal data. To the extent that Firebase Analytics processes any data, it does so under the legal basis of legitimate interest (Article 7, IX, LGPD) for app improvement and analytics purposes, and/or through consent mechanisms provided by Google.

16.2 Your Rights Under LGPD

As a data subject under LGPD, you have the following rights, which can be exercised by contacting us or Google (for analytics data):

  • Right of Confirmation and Access (Article 18, I-II): The right to confirm the existence of processing and access personal data. We do not hold personal data.
  • Right of Correction (Article 18, III): The right to correct incomplete, inaccurate, or out-of-date personal data. No personal data is maintained by us.
  • Right of Anonymization, Blocking, or Deletion (Article 18, IV): The right to request anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant personal data. Since we do not hold personal data, there is nothing to delete.
  • Right to Data Portability (Article 18, V): The right to request the portability of data to another service or product provider. Your PDF files and images are already in standard formats stored on your device.
  • Right to Information About Sharing (Article 18, VI): The right to information about public and private entities with which data is shared. We do not share personal data with any entity.
  • Right to Consent Revocation (Article 18, VIII): The right to revoke consent at any time. You may disable Firebase Analytics through device settings.
  • Right to Lodge a Complaint (Article 18, IX): The right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD), Brazil’s data protection authority, and with consumer protection bodies.
  • Right to Opposition (Article 18, X): The right to oppose processing carried out based on the legitimate interest of the controller. You may exercise this by disabling analytics.

17. POPIA Compliance (South Africa)

The Protection of Personal Information Act 4 of 2013 (“POPIA”) is South Africa’s comprehensive data protection legislation. POPIA aims to give effect to the constitutional right to privacy by safeguarding personal information when processed by responsible parties.

17.1 Conditions for Lawful Processing

POPIA sets out eight conditions for the lawful processing of personal information. Our practices align with these conditions as follows:

  • Accountability: Pdfstudio ensures compliance with these conditions. Although we process minimal (if any) personal data, we remain accountable for our data practices.
  • Processing Limitation: Personal information must be processed lawfully, in a reasonable manner, and in a manner that does not infringe the privacy of the data subject. We process no personal data through the App.
  • Purpose Specification: The purpose of any processing is specified in this Privacy Policy. The sole external processing (Firebase Analytics) is limited to anonymous usage analytics.
  • Further Processing Limitation: Further processing is compatible with the original purpose. No further processing of personal data occurs.
  • Information Quality: We take reasonable steps to ensure that personal information is complete, accurate, and up to date. Since we do not maintain personal data, this condition is inherently met.
  • Openness: This Privacy Policy is publicly available and describes our practices transparently.
  • Security Safeguards: As described in Section 10, appropriate technical and organizational measures are in place to secure information.
  • Data Subject Participation: Data subjects have the right to request access to, correction of, or deletion of their personal information. Since we hold no personal data, there is no data to provide. You may contact us to verify.

If you wish to lodge a complaint, you may contact the Information Regulator (South Africa) at https://www.inforegulator.org.za.

18. Singapore PDPA

The Personal Data Protection Act 2012 (“PDPA”) is Singapore’s principal data protection legislation, administered by the Personal Data Protection Commission (PDPC). The PDPA governs the collection, use, disclosure, and care of personal data in Singapore.

18.1 Key Obligations

Our practices are consistent with the key obligations under the PDPA:

  • Consent Obligation: Personal data may only be collected, used, or disclosed with the individual’s consent or under another legitimate basis. The App does not collect personal data. Firebase Analytics consent is managed through Google’s mechanisms.
  • Purpose Limitation Obligation: Personal data may only be collected, used, or disclosed for purposes that a reasonable person would consider appropriate. We have no purposes requiring the collection of personal data.
  • Notification Obligation: Organizations must notify individuals of the purposes for which personal data is collected, used, or disclosed. This Privacy Policy fulfills that obligation, and the notification here is that no personal data is collected.
  • Access and Correction Obligation: Individuals may request access to their personal data and request corrections. We do not hold personal data, so there is no data to access or correct. Please contact us if you have questions.
  • Protection Obligation: Organizations must make reasonable security arrangements to protect personal data. The App’s offline-first architecture, as described in Section 10, provides strong inherent protection.
  • Retention Limitation Obligation: Personal data should not be retained longer than necessary. We do not retain personal data. Analytics data retention is governed by Google’s policies.
  • Transfer Limitation Obligation: Personal data may only be transferred to other jurisdictions with comparable data protection standards or with the individual’s consent. Any analytics data transfer by Google to jurisdictions outside Singapore is subject to Google’s own transfer mechanisms and compliance with applicable data protection laws.

If you have privacy concerns, you may contact the Personal Data Protection Commission (PDPC) at https://www.pdpc.gov.sg.

19. India DPDP Act

The Digital Personal Data Protection Act, 2023 (“DPDP Act”) is India’s comprehensive data protection legislation. It applies to the processing of digital personal data within India and to the processing of personal data outside India in connection with offering goods or services to individuals in India.

19.1 Key Provisions

Under the DPDP Act, data fiduciaries (entities that determine the purpose and means of processing personal data) must comply with the following obligations:

  • Lawful Processing: Personal data must be processed only with the consent of the data principal (individual) or for certain legitimate uses specified under the Act (such as compliance with law, medical emergencies, employment, and specified government purposes). The App does not process personal data.
  • Notice: Data fiduciaries must provide a clear and concise notice to data principals regarding the personal data being processed and the purposes for which it is processed. This Privacy Policy serves as such notice and clearly states that no personal data is collected.
  • Consent Management: Consent must be free, specific, informed, unconditional, and unambiguous. Where consent is used as the legal basis, it must be easily withdrawable. You may manage consent for analytics through your device settings.
  • Data Principal Rights: Under the DPDP Act, you have the right to:
    • Obtain information about the processing of your personal data (Section 7).
    • Request correction or erasure of your personal data (Section 8).
    • Receive a confirmation of compliance with your requests (Section 8).
    • Nominate another individual to exercise your rights in the event of death or incapacity (Section 9).
    • Lodge a complaint with the Data Protection Board of India (Section 27).
  • Children’s Data: Processing of children’s data requires verifiable parental consent. The App is not intended for children under 13 (see Section 21). Where applicable, we do not knowingly process children’s data.
  • Special Protections: The DPDP Act includes enhanced protections for certain categories of personal data as may be specified by the government. We do not collect any personal data to which such special protections might apply.

If you have questions or wish to exercise your rights under the DPDP Act, please contact us at ronik2599@gmail.com. You may also contact the Data Protection Board of India for grievance redressal.

20. Children’s Privacy

PDF To Image is a general-purpose productivity tool and is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13 years of age.

20.1 COPPA Compliance (United States)

The Children’s Online Privacy Protection Act (“COPPA”) imposes requirements on operators of online services directed to children under 13 or that have actual knowledge that they collect personal information from children under 13. Our compliance position is as follows:

  • We do not knowingly collect personal information from children under the age of 13.
  • The App does not require users to provide any personal information (such as name, email address, or age) at any point.
  • The App does not use any features that would collect personal information from children, including but not limited to: account creation, chat rooms, forums, social networking features, or user profiling.
  • The App does not use any third-party services (beyond Firebase Analytics) that would collect personal information from children.
  • Firebase Analytics, to the extent it operates, does not collect personally identifiable information from any user, including children.

If we become aware that a child under the age of 13 has somehow provided personal information to us (which, given the App’s design, would be highly unlikely), we will take immediate steps to delete such information from our systems (if any exists) and terminate any associated analytics data collection. If you are a parent or guardian and believe that your child under 13 has interacted with the App in a way that may have resulted in the collection of personal information, please contact us immediately at ronik2599@gmail.com.

20.2 International Children’s Privacy

Other jurisdictions have their own children’s privacy requirements, which are addressed within the respective compliance sections of this policy. For example:

  • GDPR / UK GDPR: Requires parental consent for the processing of personal data of children under 16 (or a lower age as determined by member states, typically 13). Since we do not collect personal data, this requirement does not apply to our direct processing activities.
  • DPDP Act (India): Requires verifiable parental consent for processing children’s personal data. We do not knowingly process children’s data.
  • LGPD (Brazil): Requires the best interest of the child as a standard for processing children’s data, generally requiring parental consent for children under 12. We do not collect children’s data.

21. Your Rights

Depending on your jurisdiction, you may have various rights with respect to your personal information. While the App does not collect personal information, we respect your rights and are committed to facilitating their exercise. A comprehensive summary of your rights is provided below:

RightDescriptionHow to Exercise
Access You have the right to know whether personal information about you is being processed and to obtain a copy of such information. Contact us at ronik2599@gmail.com. We will respond within the timeframes required by applicable law.
Correction You have the right to request the correction of inaccurate or incomplete personal information. Contact us at ronik2599@gmail.com. Since we do not maintain personal data records, there is typically nothing to correct.
Deletion / Erasure You have the right to request the deletion of your personal information. Contact us or use device settings to disable analytics. No personal data is stored in our systems.
Restriction of Processing You have the right to request that we limit or restrict the processing of your personal information. Disable Firebase Analytics through your device privacy settings as described in Section 4.4.
Withdrawal of Consent Where processing is based on consent, you may withdraw your consent at any time. Manage consent through your device privacy settings. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
Data Portability You have the right to receive your personal data in a structured, commonly used, machine-readable format. Your PDF files and generated images are already in standard formats (PDF, PNG, JPG, WEBP) stored on your device. No personal data is stored by us.
Object to Processing You have the right to object to processing based on legitimate interests or for direct marketing purposes. Disable Firebase Analytics through your device settings. We do not engage in direct marketing.
Lodge a Complaint You have the right to lodge a complaint with a supervisory authority or data protection regulator in your jurisdiction. See the relevant compliance section (Sections 11–19) for the appropriate authority in your jurisdiction.

To exercise any of these rights, please contact us at ronik2599@gmail.com. We will acknowledge your request within a reasonable timeframe and respond substantively within the period required by the applicable law (typically 30 to 45 days, depending on the jurisdiction). If we are unable to fulfill your request, we will explain the reasons for the refusal and any available avenues for appeal.

22. Advertising

The App does not currently display any advertisements. There are no banner ads, interstitial ads, native ads, rewarded video ads, or any other form of advertising within the App. The App does not integrate any advertising SDKs (Software Development Kits), ad networks, or monetization platforms.

22.1 Future Advertising

We may consider adding advertisements in future versions of the App. If we decide to implement advertising, we will:

  • Update this Privacy Policy before any advertising functionality is deployed, to reflect the new data collection and sharing practices associated with the advertising technology.
  • Provide clear disclosure about the types of ads, the advertising partners involved, and the data practices of those partners.
  • Comply with all applicable privacy laws and platform policies regarding advertising, including obtaining necessary consents where required.
  • Provide users with meaningful choices regarding personalized advertising, including the ability to opt out of interest-based advertising where technically feasible.
  • Ensure that any advertising implementation does not compromise the App’s core offline-first privacy principles for PDF and image processing.
Important: Even if advertising is added in the future, your PDF files and generated images will continue to be processed entirely on your device and will not be shared with or accessible to any advertising network or platform.

23. International Data Transfers

Given the App’s offline-first design, the App itself does not transfer personal data across international borders. All PDF processing and image generation occurs locally on your device. The only potential international data transfer relates to Firebase Analytics data, which is operated by Google and may involve the transfer of anonymous analytics data to servers located in various countries.

23.1 Firebase Analytics Transfers

Google, as the provider of Firebase Analytics, may transfer analytics data outside your country or region of residence as part of its global infrastructure operations. Google addresses such transfers through:

  • Standard Contractual Clauses (SCCs): Google relies on European Commission-approved Standard Contractual Clauses for transfers of personal data from the EEA, UK, and Switzerland to countries not recognized as providing an adequate level of data protection.
  • Data Processing Agreements: Google enters into data processing agreements with its customers that include appropriate security and privacy obligations.
  • UK International Data Transfer Agreement (IDTA): For transfers from the UK, Google has implemented the UK IDTA or its addendum.
  • Adequacy Decisions: Where applicable, Google relies on adequacy decisions by relevant data protection authorities (e.g., the EU-Japan adequacy decision, the EU-UK adequacy decision, etc.).
  • Other Legal Mechanisms: Google may also rely on binding corporate rules, consent, or other legally recognized transfer mechanisms as applicable.

For more information about Google’s international data transfer practices, please review Google’s Privacy Frameworks documentation.

23.2 Limited Scope of Transfers

It is important to emphasize that any international transfer is limited to the anonymous, aggregated analytics data collected by Firebase Analytics. Your PDF files, generated images, and any other personal information are never transferred internationally because they are never collected or transmitted by the App in the first place.

24. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, changes in applicable law, changes in the App’s functionality, or other operational reasons. When we make material changes to this policy, we will take the following steps to notify you:

  • In-App Notification: We may display a notification within the App informing you that the Privacy Policy has been updated and providing a link to the revised version.
  • Store Listing Update: We will update the Privacy Policy link in the App’s listing on the Google Play Store and Apple App Store to point to the most current version.
  • Last Updated Date: The “Last Updated” date at the top of this policy will be revised to reflect the date of the most recent change.

24.1 How to Stay Informed

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information and handle data. You can check the “Last Updated” date at the top of this page to determine when the policy was last revised. Continued use of the App after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

24.2 Version History

DateDescription
30 June 2026 Initial comprehensive Privacy Policy covering all applicable privacy legislation, Firebase Analytics disclosure, offline-first design, and user rights.

If you have questions about a previous version of this Privacy Policy, please contact us at ronik2599@gmail.com.

25. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, the App’s data practices, or your rights under applicable privacy laws, please contact us using the following information:

Developer: Pdfstudio

Email: ronik2599@gmail.com

We will make every effort to respond to your inquiry within a reasonable timeframe, typically within 30 calendar days, and in accordance with the response timelines required by applicable law.