Privacy Policy & Data Protection Charter
PustakEdits Platformoperates under strict ephemeral compute architecture. All uploaded Portable Document Format ("PDF") files, raster images, and document payloads are cryptographically processed in transient volatile RAM / temporary disk partitions and permanently expunged via automated scrubbing daemon within twenty-four (24) hours of creation. We do not inspect, retain, commercialize, or train machine-learning models upon your proprietary document content.
Strict 24h Data Expunction
Automated hard-deletion routines purge all document binaries, temporary artifacts, and extracted font maps precisely within 24 hours of ingest.
Absolute AI Ringfencing
Zero ingestion into artificial intelligence, LLMs, neural networks, or public training sets. Your files are never parsed for third-party intelligence.
Cryptographic Transport
All transport payloads are secured via Transport Layer Security (TLS 1.3 / AES-256) with forward secrecy between client and backend compute nodes.
§ 1.0Legal Preamble, Scope & Binding Effect
This Privacy Policy constitutes a legally binding agreement entered into by and between the individual or legal entity accessing, uploading to, or otherwise utilizing the services ("User", "You", or "Data Subject") and PustakEdits Platform ("Company", "We", "Us", or "Our").
By accessing the website located at pustakedit.vercel.app, invoking API endpoints under /api/tools/* or /api/pdf/*, or transmitting any electronic document to our infrastructure, you unreservedly assent to the practices, collection vectors, and processing protocols detailed herein. If you do not agree to these strict provisions, you must immediately terminate use of the platform and disconnect your browser.
§ 2.0Classification: Data Controller vs. Data Processor
To maintain comprehensive compliance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), UK Data Protection Act 2018, and relevant privacy laws, the legal capacity in which PustakEdits operates is expressly partitioned as follows:
- PustakEdits as Data Controller:PustakEdits acts as the Data Controller solely with respect to account registration credentials (email address, hashed credentials, OAuth token claims) and essential HTTP connection telemetrics necessary to secure the network infrastructure against Denial-of-Service ("DoS") attacks.
- PustakEdits as Data Processor (Operator): With respect to all user-uploaded document payloads, embedded text layers, images, signatures, and file metadata transmitted into our parsing algorithms, the User acts as the sole Data Controller. PustakEdits acts exclusively as an automated technical Data Processor executing commands on behalf of the User.
§ 3.0Explicit Categories of Data Collected and Processed
We adhere to strict data minimization principles under GDPR Article 5(1)(c). We collect only data strictly indispensable to execute technical PDF manipulation:
Binary byte arrays of uploaded PDF, Word, Excel, PowerPoint, and image files. Processed in volatile memory or isolated ephemeral filesystem sandboxes. Deleted permanently within 24 hours.
User email addresses and cryptographic authentication tokens when registering via Supabase Auth or Google OAuth. Passwords are never stored in plaintext and are salted/hashed with industry standards.
IP address hashes, timestamp headers, and quota consumption counters stored in sliding-window rate limiters solely to prevent server exhaustion and unauthorized bot exploitation.
Recent document references and UI preferences stored strictly client-side on the User's physical device via HTML5 LocalStorage. Never synced to remote advertising profiles.
§ 4.0Lawful Basis for Processing (GDPR Article 6)
Processing of data is conducted solely under the following legal bases:
- Performance of Contract (Art. 6(1)(b)): Executing the requested text editing, compression, OCR extraction, conversion, or watermarking requested directly by the User.
- Legitimate Interests (Art. 6(1)(f)): Maintaining server perimeter defense, safeguarding computational nodes from distributed attacks, rate-limiting spam requests, and verifying API health.
- Compliance with Legal Obligations (Art. 6(1)(c)): Retaining records strictly where mandated by statutory legal directives, lawful judicial subpoenas, or valid law enforcement orders.
§ 5.0Absolute Prohibition of Artificial Intelligence Model Training
Under no circumstances does PustakEdits Platform, its operators, affiliates, contractors, or compute suppliers parse, tokenize, index, retain, train upon, or aggregate any portion of user documents into large language models (LLMs), deep neural networks, public corpora, or derivative machine learning models. Document parsing is strictly mechanical and algorithmic via native C/C++ libraries (PyMuPDF, Poppler, Tesseract OCR) executing directly in transient sandboxes.
§ 6.024-Hour Ephemeral Data Lifecycle & Cryptographic Sanitation
All uploaded files, converted outputs, and intermediary rendering caches follow an uncompromising time-to-live ("TTL") protocol:
Once purged, documents cannot be recovered by any party, including system administrators or law enforcement, as zero cold archival backups of document bodies are maintained.
§ 7.0Technical & Organizational Security Measures (TOMs)
In compliance with Article 32 of the GDPR, PustakEdits Platform maintains enterprise-grade administrative, physical, and technical safeguards:
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public network endpoints.
- Encryption at Rest: Ephemeral server storage encrypted utilizing AES-256 block cipher standards.
- Network Isolation: Application compute tiers operate inside segregated cloud container network boundaries with zero public database exposure.
- Vulnerability Management: Automated static code analysis and dependency auditing for rapid patching of Common Vulnerabilities and Exposures (CVEs).
§ 8.0Authorized Infrastructure Sub-processors
We do not sell, license, lease, or distribute data to data brokers or advertising exchanges. We engage strictly authorized infrastructure sub-processors:
| Sub-processor | Function / Processing Role | Data Categories Handled | Location |
|---|---|---|---|
| Supabase Inc. | Identity management & auth token verification | Account Email, User UUID | United States / EU |
| Vercel Inc. | Frontend edge content delivery & static assets | HTTP Headers, Anonymized IP | Global Edge |
| Self-Hosted Cloud Compute | PyMuPDF / OCR document manipulation engine | Ephemeral PDF byte streams | Secure Regional Data Centers |
§ 9.0European Economic Area (EEA) & UK Data Subject Rights
Qualified residents within the European Economic Area, Switzerland, and the United Kingdom enjoy statutory rights under Chapter III of the GDPR:
- Right of Access (Art. 15): Right to obtain confirmation of whether your personal data is processed.
- Right to Rectification (Art. 16): Right to rectify inaccurate account information.
- Right to Erasure / "Right to Be Forgotten" (Art. 17): Right to request irreversible deletion of user account credentials. (Uploaded document payloads are deleted automatically within 24 hours without requiring a manual request).
- Right to Restriction & Data Portability (Arts. 18 & 20): Right to demand restriction of processing and receive machine-readable exports of stored credentials.
To exercise any statutory GDPR entitlement, submit an authenticated request to our Data Protection representative at Vishweshshinde26@gmail.com. Responses are provided within thirty (30) days.
§ 10.0California Consumer Privacy Rights (CCPA / CPRA Notice)
Pursuant to the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"):
PustakEdits Platform has never sold, shared, monetized, or transferred personal information to third parties for monetary or other valuable consideration, nor do we engage in cross-context behavioral advertising.
California residents possess the Right to Know, Right to Delete, Right to Correct, and the Right to Non-Discrimination for exercising statutory privacy rights.
§ 11.0Health Information & Regulatory Compliance Disclaimers
PustakEdits Platform is an automated consumer utility platform and does not maintain Business Associate Agreements ("BAA") by default under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Users are strictly prohibited from uploading unencrypted Protected Health Information ("PHI") subject to HIPAA, or non-public financial records under the Gramm-Leach-Bliley Act ("GLBA"), unless the User has independently verified that their use case complies with applicable state and federal compliance thresholds.
§ 12.0Data Security Incident & Breach Notification Protocol
In the event of a verified security incident resulting in unlawful access, exfiltration, or disclosure of identifiable user data under our control, PustakEdits Platform commits to notifying affected Data Subjects and relevant supervisory authorities without undue delay, and no later than seventy-two (72) hours after becoming aware of the breach, pursuant to GDPR Article 33.
§ 13.0Unilateral Amendments & Revision Notifications
We reserve the absolute right to amend, update, or revise this Privacy Policy at our sole discretion to reflect changes in regulatory directives, technological standards, or platform functionality. The "Last Revised" date at the commencement of this document signifies the effective version. Continued interaction with the platform post-publication constitutes affirmative acceptance of the revised terms.
§ 14.0Designated Data Protection Representative & Formal Inquiries
For questions regarding data processing, requests to exercise statutory rights, or service of legal process, please direct correspondence to the designated representative: