Privacy Policy
Last updated: [DATE — TO BE FILLED AT PUBLICATION]
This Privacy Policy explains how PDF Nativo ("we") handles data in connection with the website and tools available at pdfnativo.com (the "Service"), in accordance with Brazil's General Data Protection Law (Lei nº 13.709/2018 — "LGPD"). PDF Nativo is the trade name under which the Service operates; formal incorporation is in progress — [LEGAL ENTITY NAME / CNPJ — TO BE FILLED once incorporated]. Where relevant to users in other jurisdictions, this policy is drafted to be compatible with general GDPR/CCPA principles, but its primary legal basis is Brazilian law.
If you only want to know one thing: the content of the files you process through the Service never leaves your device. The rest of this document details that and covers the few other data points involved in using the site.
1. The core distinction: file data vs. browsing data
This policy treats two types of data separately, because they are fundamentally different in nature:
- Content of your files (the PDF, JPG, or other file you load into a tool, and the output generated): we never collect, receive, transmit, store, or have access to this content. All processing — compression, merging, conversion, page deletion/extraction/splitting — happens locally in your browser, using WebAssembly/JavaScript, inside an isolated process (Web Worker). No network call is made with the file's content, at any step. This architecture has been verified through independent security testing (penetration testing) and is reinforced by automated technical controls that prevent network calls in the code responsible for processing. Practical consequence: we have no way of knowing what is in your files, we cannot hand them over to third parties, authorities, or advertisers, and any data breach on our side cannot include file content, because that content never reaches us.
- Browsing and infrastructure data: technical data common to any access to a website (IP address, browser type, operating system, page accessed, date/time, referrer), plus any analytics data if you consent to it. These are covered in Sections 2 and 3 below.
2. Browsing data and infrastructure logs
Like any website, the Service depends on a hosting provider to be delivered to your browser. That provider automatically records, as part of the normal operation of the internet, data such as IP address, date and time of access, user-agent (browser/device), and the URL accessed. This happens even if you never use any tool on the Service, and is distinct from any collection related to your files.
- Legal basis: legitimate interest (LGPD art. 7, IX, and art. 10), limited to what is necessary to enable the operation, security, and availability of the Service (e.g., detecting abuse, attacks, error spikes).
- Hosting provider: [HOSTING PROVIDER — TO BE FILLED, e.g., Vercel Pro or self-managed VPS] — [PROVIDER'S LOG RETENTION POLICY — TO BE FILLED: how long access logs are retained and whether processing occurs outside Brazil].
- Retention: infrastructure access logs are retained for the period defined by the hosting provider, typically between 7 and 90 days depending on the provider's policy, unless longer retention is needed to investigate an ongoing security incident.
- International transfer: depending on the hosting provider chosen, this data may be processed outside Brazil. Where applicable, this occurs under the safeguards required by the LGPD (art. 33) and will be detailed here once the final hosting decision is made [TO BE FILLED].
3. Cookies and analytics
Today, in the current version of the Service, no analytics or marketing cookie is loaded. We do not use Google Tag Manager or any generic tag management tool.
Once the consent banner is implemented, the behavior will be as follows:
- Before you give any consent, no Google Analytics (GA4) or Google Ads script is loaded, and no analytics cookie is set. You can use all of the Service's tools normally without ever giving this consent.
- If you choose to accept, we load Google Analytics 4 (via
gtag, loaded directly — never through Google Tag Manager) to understand, in aggregate, which tools are used most and to detect failures. The events collected are limited to product-usage information, such as which tool was used and whether the operation succeeded or failed (by a fixed error code), and the interface language. No event ever sends data derived from your file's content — this includes file name, size, page count, hash, or any excerpt of the content. This rule is treated as a product security requirement, with automated technical verification, not just a stated policy (seedocs/ANALYTICS_POLICY.mdin the project repository for the full technical detail). We also use Google Ads solely to measure the effectiveness of advertising campaigns (aggregate conversions), under the same restrictions. GA4 data retention is configured at the minimum available setting, and Google Signals is turned off. - You can withdraw your consent at any time through the Service's own cookie banner/preferences, accessible at [LOCATION OF PREFERENCE CONTROL — TO BE FILLED ONCE THE BANNER IS IMPLEMENTED, e.g., site footer].
- Legal basis: consent (LGPD art. 7, I), collected in a specific, informed, and prominent manner, before any Google script is loaded.
Outside of analytics consent, the Service may use, at most, strictly necessary technical cookies (e.g., language preference), if any come to exist. [TO CONFIRM: today the project does not identify any first-party technical cookie beyond a possible language preference stored locally in the browser (localStorage), which is not a cookie and is never sent to any server.]
4. No account, no login
The Service does not require registration, login, or providing a name, email, or any personal identifier to use the tools. We do not maintain user profiles, do not store preferences server-side, and do not link data across visits to individually identify the same user (no persistent identifier is used for that purpose).
Satisfaction survey (optional)
At the end of each tool you can rate it from 1 to 5 stars and, if you wish, write a comment. Answering is optional and changes nothing in how the Service works.
- What we receive: the rating, the comment, which tool was used, the page language and the date (day only, no time). Nothing from your file (name, size, pages or content) is sent. We do not store your IP address or browser data with the answer.
- Publishing: we only publish a comment on the site if you tick the permission box. In that case it may appear with the first name you give (or as anonymous), after we review it. You can ask for it to be removed at any time through the contact in section 11.
- Purpose and legal basis: improving the tools, based on legitimate interest (LGPD art. 7, IX); publishing, based on your consent (art. 7, I).
- Retention: at most 12 months, deleted automatically after that; kept on the Service's hosting server, not shared with third parties.
- Please avoid personal data in your comment. If any appears, it is processed only for the purpose above.
- So we don't ask again, your browser stores locally (
localStorage) the date you answered. This is not sent to any server.
5. Who we share data with
- File content: never shared, because it never reaches us (see Section 1).
- Browsing/infrastructure data: shared only with the hosting provider, to the extent necessary to operate the Service (see Section 2).
- Analytics data (after consent): shared with Google, as operator of Google Analytics 4 and Google Ads, limited to the events described in Section 3.
- We do not sell, rent, or trade personal data.
- We do not share data with third parties for third-party advertising purposes outside the scope described above.
6. Your rights as a data subject (LGPD)
Under the LGPD, you have the right to, among others: confirmation of the existence of processing; access to data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary data; portability; deletion of data processed with consent; information about data sharing; and withdrawal of consent.
In practice, given the Service's design:
- There is no account or file data to access, correct, delete, or port, because we never collect it.
- The rights that practically apply are mainly about browsing/ infrastructure data (Section 2) and, when you consent, about analytics data (Section 3) — for example, withdrawing analytics consent at any time, or requesting clarification about access logs retained by the hosting provider.
To exercise any of these rights, contact our Data Protection Officer through the channels below.
7. Data Protection Officer (DPO)
Name: Robson Souza
Email: suporte@pdfnativo.com
8. Security
We adopt technical and organizational measures to protect the data we actually process (infrastructure logs and, where applicable, analytics data), including the use of HTTPS, security headers, and a restrictive Content Security Policy. As for the content of your files, the strongest protection we offer is structural: because that content never leaves your device, it is never exposed to a potential security incident in our infrastructure.
9. Children
The Service is not directed at children and does not intentionally collect data from minors under 18 beyond the browsing/infrastructure data common to any visitor, handled as described in Section 2.
10. Changes to this policy
We may update this Privacy Policy periodically, especially as the consent banner and GA4 are actually implemented, or if hosting/ infrastructure changes. The version in force is always the one published on this page, with the last-updated date at the top. Material changes will be communicated prominently within the Service.
11. Contact
Questions about this Policy may be sent to suporte@pdfnativo.com or directly to the Data Protection Officer (Section 7).