Privacy policy
Effective 18 August 2026 · version 1.0
The short version
Section titled “The short version”Your documents are not stored. They exist in memory for the length of the request and are gone when the response is sent.
We keep enough metadata to bill you correctly and to defend a payment dispute, and that metadata does not include what your documents said.
Nothing you send trains anything. Nothing is sold, rented or shared for advertising.
Who is responsible for your data
Section titled “Who is responsible for your data”The controller is Kaho LLC, a Delaware limited liability company, of
19 Beechtree Lane, Bronxville, NY 10708, United States, contactable at
[email protected]. There is no
data protection officer; there is one person, and that address reaches them.
When you send us documents containing other people’s personal data, you are the controller and we act as your processor — the data processing addendum governs that relationship.
What we process, why, and on what legal basis
Section titled “What we process, why, and on what legal basis”| Data | Purpose | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| The PDF you send | Converting it, because that is what you asked for | Performance of a contract, 6(1)(b) | Not stored. In memory for the request only |
| The conversion result | Serving a repeat of the identical request without charging you twice | Performance of a contract, 6(1)(b) | 24 hours, scoped to your account and project. Nothing is written if you send cache: false |
| Request metadata — timestamp, source IP address, endpoint, page counts, SHA-256 of the document bytes | Billing accuracy; investigating abuse; evidence if a payment is disputed | Performance of a contract, 6(1)(b), and our legitimate interest in being paid and not defrauded, 6(1)(f) | 540 days |
| Your email address, from Google sign-in | Identifying you and contacting you about your account | Performance of a contract, 6(1)(b) | Life of the account |
| API key hashes and metadata | Authenticating your requests; revoking a leaked key | Performance of a contract, 6(1)(b) | Life of the account |
| Credit ledger entries and purchase records | Operating the service; keeping financial records | Contract, 6(1)(b), and legal obligation, 6(1)(c) | 7 years |
| Fraud signals — card fingerprint, dispute and chargeback records, 3-D Secure results | Preventing payment fraud and defending disputes | Legal obligation, 6(1)(c), and legitimate interest, 6(1)(f) | 7 years, with the ledger |
Providing this data is a contractual necessity. Without an email address we cannot give you an account, and without request metadata we cannot bill you or defend a chargeback. There is no part of it we collect “just in case”.
The source IP address is the personal data in the request-metadata table. It has no separate lifetime: deleting the record is what deletes it, and a scheduled job does that at 540 days.
What we never do
Section titled “What we never do”- We do not read your documents. Conversion is automatic; no person sees document content in the ordinary course of operating the service.
- We do not use your documents, or anything derived from them, to train models.
- We do not sell, rent or share your data with advertisers or data brokers.
- We do not put document content in URLs or in logs.
- We do not profile you for marketing, and we send no marketing email.
Automated decisions
Section titled “Automated decisions”Some decisions about your account are made automatically, and two of them can affect you significantly:
- A card payment can be refused. Every card purchase is authorised first and captured only if the bank confirms a 3-D Secure liability shift and the payment processor’s risk assessment is acceptable. If it is not, the authorisation is cancelled — no money is taken, and you may see a pending hold that releases.
- An account can be frozen or credits clawed back automatically when a chargeback, a refund or an early fraud warning arrives, and new accounts have a usage cap until a payment has settled.
You can ask a human to look at any of these. Write to [email protected],
say what happened, and we will review it ourselves, explain the decision, and
change it if it was wrong. You may also contest the decision and express your
point of view. This is your right under Article 22 of the GDPR and we would
rather hear from you than lose you to a bank dispute.
Where your data is
Section titled “Where your data is”The service runs in the United States. Conversion runs on Google Cloud Run in
us-central1. Account, key and ledger data are stored on Cloudflare’s network
with primary storage in the United States.
If you are in the EEA, the UK or Switzerland, your data is transferred to the United States. The safeguard is the European Commission’s standard contractual clauses (Decision 2021/914), with the UK International Data Transfer Addendum where the UK GDPR applies. Each sub-processor below is engaged under a data processing agreement that carries the same clauses onward. Some of them also self-certify under the EU–US Data Privacy Framework; we rely on the clauses rather than on that, so the safeguard does not change if a certification lapses. The DPA sets this out in full, and we will send you a copy of the relevant clauses on request.
Sub-processors
Section titled “Sub-processors”These are the third parties that can hold or see customer data. The list is dated, and it changes only with 30 days’ notice.
| Sub-processor | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Edge compute, API routing, account and ledger storage, result cache | United States, global edge |
| Google LLC (Google Cloud) | Document conversion compute; secret storage | us-central1, United States |
| Google LLC (Sign-In) | Authenticating you when you sign in to the console | United States |
| Stripe, Inc. | Payment processing, invoicing, tax calculation | United States |
Card details go to Stripe, not to us. Stripe is a controller in its own right for payment data, and its own privacy policy governs that.
We do not currently use an error-reporting or email delivery provider. If that changes, this table changes first, with notice.
Cookies
Section titled “Cookies”The console sets one cookie, which holds your signed-in session. It is
__Host- prefixed, Secure, HttpOnly and SameSite=Lax, and lasts 14 days.
It exists only so you do not sign in on every page.
We set no analytics cookie, no advertising cookie and no third-party cookie on this site or in the console. Because the only cookie we set is strictly necessary to deliver a service you asked for, no consent banner is required for it.
Your rights
Section titled “Your rights”Under the GDPR and the UK GDPR you have the right to:
- access the personal data we hold about you;
- rectify it if it is wrong;
- erase it, subject to the financial records we are required to keep;
- restrict how we process it while a dispute about it is resolved;
- object to processing based on our legitimate interests, including on grounds relating to your particular situation;
- portability — receive the data you gave us in a machine-readable form;
- not be subject to a solely automated decision with legal or similarly significant effect, as described above;
- withdraw consent, where we rely on it — we currently do not rely on consent for anything described here.
Write to [email protected]. We respond within one month, as the GDPR requires.
Where a request is complex or there are several, we may extend that by up to two
further months and will tell you why within the first month.
There is no charge, unless a request is manifestly unfounded or excessive — in which case the law allows us to charge a reasonable fee or to refuse, and we will explain which and why.
In practice, closing your account deletes your documents (already gone), your keys, your cached results and your personal details. Ledger entries survive, because financial records must; they identify an account, not a person, and they contain no document content.
Complaints
Section titled “Complaints”If you think we have handled your data badly, tell us first — [email protected] —
and we will try to put it right.
You also have the right to complain to a supervisory authority. In the EEA that is the data protection authority of the country where you live, work, or where you think the problem happened; the list is at edpb.europa.eu. In the UK it is the Information Commissioner’s Office.
Security
Section titled “Security”The security page says how to report a vulnerability and what the service does to protect your data. In short: documents are not retained after the request, conversion runs isolated from the network and the filesystem, API keys are held only as peppered hashes, data is encrypted in transit, and card payments are authorised before they are captured, so a refused authorisation does not become a charge.
Breach notification
Section titled “Breach notification”Where a breach of your personal data is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, as Article 34 requires, and we will notify the supervisory authority where Article 33 requires it.
Where we act as your processor rather than as controller, our notification obligation to you is in the DPA.
Children
Section titled “Children”The service is not directed at children and we do not knowingly collect their data. You must be 18 to hold an account.
Changes
Section titled “Changes”We will tell you about material changes before they take effect, by posting the revised policy here and in the console. The effective date and version at the top of this page change with them.