Legally Binding Instrument

Privacy Policy & Data Protection Charter

Effective Date: March 18, 2026Last Revised: March 18, 2026
Statutory Legal Notice & Ephemeral Processing Guarantee

PustakEdits Platformoperates under strict ephemeral compute architecture. All uploaded Portable Document Format ("PDF") files, raster images, and document payloads are cryptographically processed in transient volatile RAM / temporary disk partitions and permanently expunged via automated scrubbing daemon within twenty-four (24) hours of creation. We do not inspect, retain, commercialize, or train machine-learning models upon your proprietary document content.

Strict 24h Data Expunction

Automated hard-deletion routines purge all document binaries, temporary artifacts, and extracted font maps precisely within 24 hours of ingest.

Absolute AI Ringfencing

Zero ingestion into artificial intelligence, LLMs, neural networks, or public training sets. Your files are never parsed for third-party intelligence.

Cryptographic Transport

All transport payloads are secured via Transport Layer Security (TLS 1.3 / AES-256) with forward secrecy between client and backend compute nodes.

§ 1.0Legal Preamble, Scope & Binding Effect

This Privacy Policy constitutes a legally binding agreement entered into by and between the individual or legal entity accessing, uploading to, or otherwise utilizing the services ("User", "You", or "Data Subject") and PustakEdits Platform ("Company", "We", "Us", or "Our").

By accessing the website located at pustakedit.vercel.app, invoking API endpoints under /api/tools/* or /api/pdf/*, or transmitting any electronic document to our infrastructure, you unreservedly assent to the practices, collection vectors, and processing protocols detailed herein. If you do not agree to these strict provisions, you must immediately terminate use of the platform and disconnect your browser.

§ 2.0Classification: Data Controller vs. Data Processor

To maintain comprehensive compliance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), UK Data Protection Act 2018, and relevant privacy laws, the legal capacity in which PustakEdits operates is expressly partitioned as follows:

  • PustakEdits as Data Controller:PustakEdits acts as the Data Controller solely with respect to account registration credentials (email address, hashed credentials, OAuth token claims) and essential HTTP connection telemetrics necessary to secure the network infrastructure against Denial-of-Service ("DoS") attacks.
  • PustakEdits as Data Processor (Operator): With respect to all user-uploaded document payloads, embedded text layers, images, signatures, and file metadata transmitted into our parsing algorithms, the User acts as the sole Data Controller. PustakEdits acts exclusively as an automated technical Data Processor executing commands on behalf of the User.

§ 3.0Explicit Categories of Data Collected and Processed

We adhere to strict data minimization principles under GDPR Article 5(1)(c). We collect only data strictly indispensable to execute technical PDF manipulation:

A. Ephemeral Document Data

Binary byte arrays of uploaded PDF, Word, Excel, PowerPoint, and image files. Processed in volatile memory or isolated ephemeral filesystem sandboxes. Deleted permanently within 24 hours.

B. Account & Auth Credentials

User email addresses and cryptographic authentication tokens when registering via Supabase Auth or Google OAuth. Passwords are never stored in plaintext and are salted/hashed with industry standards.

C. Rate-Limiting & Telemetry

IP address hashes, timestamp headers, and quota consumption counters stored in sliding-window rate limiters solely to prevent server exhaustion and unauthorized bot exploitation.

D. Browser Local Storage

Recent document references and UI preferences stored strictly client-side on the User's physical device via HTML5 LocalStorage. Never synced to remote advertising profiles.

§ 5.0Absolute Prohibition of Artificial Intelligence Model Training

CONTRACTUAL GUARANTEE: YOUR PROPRIETARY DOCUMENT CONTENT, VECTOR TEXT SPANS, AND INTELLECTUAL PROPERTY ARE STRICTLY IMMUNE FROM MACHINE LEARNING INGESTION.

Under no circumstances does PustakEdits Platform, its operators, affiliates, contractors, or compute suppliers parse, tokenize, index, retain, train upon, or aggregate any portion of user documents into large language models (LLMs), deep neural networks, public corpora, or derivative machine learning models. Document parsing is strictly mechanical and algorithmic via native C/C++ libraries (PyMuPDF, Poppler, Tesseract OCR) executing directly in transient sandboxes.

§ 6.024-Hour Ephemeral Data Lifecycle & Cryptographic Sanitation

All uploaded files, converted outputs, and intermediary rendering caches follow an uncompromising time-to-live ("TTL") protocol:

0 to 60 Seconds: Processing in volatile memory or isolated execution sandbox.
1 to 24 Hours: Stored exclusively for User download retrieval via cryptographically unguessable UUID.
24th Hour: Automated asynchronous cron sweeps and invokes filesystem unlinks, permanently purging artifacts from storage blocks.

Once purged, documents cannot be recovered by any party, including system administrators or law enforcement, as zero cold archival backups of document bodies are maintained.

§ 7.0Technical & Organizational Security Measures (TOMs)

In compliance with Article 32 of the GDPR, PustakEdits Platform maintains enterprise-grade administrative, physical, and technical safeguards:

  • Encryption in Transit: Mandatory TLS 1.3 encryption across all public network endpoints.
  • Encryption at Rest: Ephemeral server storage encrypted utilizing AES-256 block cipher standards.
  • Network Isolation: Application compute tiers operate inside segregated cloud container network boundaries with zero public database exposure.
  • Vulnerability Management: Automated static code analysis and dependency auditing for rapid patching of Common Vulnerabilities and Exposures (CVEs).

§ 8.0Authorized Infrastructure Sub-processors

We do not sell, license, lease, or distribute data to data brokers or advertising exchanges. We engage strictly authorized infrastructure sub-processors:

Sub-processorFunction / Processing RoleData Categories HandledLocation
Supabase Inc.Identity management & auth token verificationAccount Email, User UUIDUnited States / EU
Vercel Inc.Frontend edge content delivery & static assetsHTTP Headers, Anonymized IPGlobal Edge
Self-Hosted Cloud ComputePyMuPDF / OCR document manipulation engineEphemeral PDF byte streamsSecure Regional Data Centers

§ 9.0European Economic Area (EEA) & UK Data Subject Rights

Qualified residents within the European Economic Area, Switzerland, and the United Kingdom enjoy statutory rights under Chapter III of the GDPR:

  • Right of Access (Art. 15): Right to obtain confirmation of whether your personal data is processed.
  • Right to Rectification (Art. 16): Right to rectify inaccurate account information.
  • Right to Erasure / "Right to Be Forgotten" (Art. 17): Right to request irreversible deletion of user account credentials. (Uploaded document payloads are deleted automatically within 24 hours without requiring a manual request).
  • Right to Restriction & Data Portability (Arts. 18 & 20): Right to demand restriction of processing and receive machine-readable exports of stored credentials.

To exercise any statutory GDPR entitlement, submit an authenticated request to our Data Protection representative at Vishweshshinde26@gmail.com. Responses are provided within thirty (30) days.

§ 10.0California Consumer Privacy Rights (CCPA / CPRA Notice)

Pursuant to the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"):

DO NOT SELL OR SHARE MY PERSONAL INFORMATION

PustakEdits Platform has never sold, shared, monetized, or transferred personal information to third parties for monetary or other valuable consideration, nor do we engage in cross-context behavioral advertising.

California residents possess the Right to Know, Right to Delete, Right to Correct, and the Right to Non-Discrimination for exercising statutory privacy rights.

§ 11.0Health Information & Regulatory Compliance Disclaimers

MANDATORY HEALTHCARE REGULATORY NOTICE

PustakEdits Platform is an automated consumer utility platform and does not maintain Business Associate Agreements ("BAA") by default under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Users are strictly prohibited from uploading unencrypted Protected Health Information ("PHI") subject to HIPAA, or non-public financial records under the Gramm-Leach-Bliley Act ("GLBA"), unless the User has independently verified that their use case complies with applicable state and federal compliance thresholds.

§ 12.0Data Security Incident & Breach Notification Protocol

In the event of a verified security incident resulting in unlawful access, exfiltration, or disclosure of identifiable user data under our control, PustakEdits Platform commits to notifying affected Data Subjects and relevant supervisory authorities without undue delay, and no later than seventy-two (72) hours after becoming aware of the breach, pursuant to GDPR Article 33.

§ 13.0Unilateral Amendments & Revision Notifications

We reserve the absolute right to amend, update, or revise this Privacy Policy at our sole discretion to reflect changes in regulatory directives, technological standards, or platform functionality. The "Last Revised" date at the commencement of this document signifies the effective version. Continued interaction with the platform post-publication constitutes affirmative acceptance of the revised terms.

§ 14.0Designated Data Protection Representative & Formal Inquiries

For questions regarding data processing, requests to exercise statutory rights, or service of legal process, please direct correspondence to the designated representative:

Officer: Vishwesh Shinde
Entity: PustakEdits Platform Compliance Group
Jurisdiction: India and applicable international data protection frameworks